Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Flask Appbuilder HIGH 8.8
CVE-2021-41265

Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the RES…

Fix: 3.3.4+
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 7.5
CVE-2021-20145

Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which e…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Eufy Homebase 2 Firmware HIGH 7.5
CVE-2021-21955

An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1…

No fix yet
Fix from $1,950 2021-12-09
Fortiauthenticator HIGH 8.1
CVE-2021-43068

A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login p…

Patch available
Fix from $1,950 2021-12-09
Eharmonynew MEDIUM 6.5
CVE-2021-36718

SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sens…

Fix: 11.0+
Fix from $1,600 2021-12-08
Harmonyos HIGH 7.5
CVE-2021-37054

There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect s…

Fix: 2.0+
Fix from $1,950 2021-12-08
Jira Software Data Center MEDIUM 5.3
CVE-2021-41309

Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs…

Fix: 8.19.1+
Fix from $1,600 2021-12-08
Jira Software Data Center HIGH 7.5
CVE-2021-41311

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to…

Fix: 8.19.1+
Fix from $1,950 2021-12-08
Mahavitaran CRITICAL 9.8
CVE-2021-41716

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulner…

Fix: after 7.50
Fix from $2,300 2021-12-07
Goautodial HIGH 7.5
CVE-2021-43175

The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes…

No fix yet
Fix from $1,950 2021-12-07
Harmonyos HIGH 7.5
CVE-2021-37100

There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authenticatio…

Fix: 2.0+
Fix from $1,950 2021-12-07
Emui HIGH 7.5
CVE-2021-37043

There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious applica…

Fix: 2.0+
Fix from $1,950 2021-12-07
GitLab CRITICAL 9.8
CVE-2021-39890

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

Fix: 14.1.7 / 14.2.5+
Fix from $2,300 2021-12-06
Webhmi Firmware CRITICAL 9.8
CVE-2021-43931

The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that i…

Fix: 4.1+
Fix from $2,300 2021-12-06
Nodebb HIGH 7.5
CVE-2021-43786

Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally al…

Fix: after 1.18.4
Fix from $1,950 2021-11-29
Qvr HIGH 8.8
CVE-2021-38686

An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows attackers to compr…

Fix: 5.1.6+
Fix from $1,950 2021-11-26
Nbg6818 Firmware HIGH 7.8
CVE-2021-35033

A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could…

Fix: 1.00 / 2.20+
Fix from $1,950 2021-11-23
Ox App Suite MEDIUM 5.3
CVE-2021-38376

OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Networking Os10 CRITICAL 9.8
CVE-2021-36306

Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerability. A remote unauthenticated …

Fix: 10.4.3.8 / 10.5.0.10+
Fix from $2,300 2021-11-20
Networking Os10 CRITICAL 9.8
CVE-2021-36308

Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vulnerability. A remote unauthe…

Fix: 10.4.3.8 / 10.5.0.10+
Fix from $2,300 2021-11-20
Gcb Doctor CRITICAL 9.8
CVE-2021-42338EPSS 6%

4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code in…

Fix: after 20210708
Fix from $2,300 2021-11-19
Nuc7i3dn Firmware HIGH 7.8
CVE-2021-0096

Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN, NUC7i7DN before version 1.78…

Fix: 1.78.1.1+
Fix from $1,950 2021-11-17
Nuc M15 Laptop Kit Management Engine Driver Pack MEDIUM 5.5
CVE-2021-33087

Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an a…

Fix: 15.0.10.1508+
Fix from $1,600 2021-11-17
Shenyu CRITICAL 9.8
CVE-2021-37580EPSS 40%

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff…

Mitigation only
Fix from $2,300 2021-11-16
Halo\+ Camera Firmware MEDIUM 6.8
CVE-2021-3788

An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthoriz…

Fix: 03.40.00 / 03.40.02+
Fix from $1,600 2021-11-12
Ideacentre C5 14mb05 Firmware MEDIUM 6.8
CVE-2021-3519

A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Dev…

Mitigation only
Fix from $1,600 2021-11-12
Ktor HIGH 7.5
CVE-2021-43203

In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.

Fix: 1.6.4+
Fix from $1,950 2021-11-09
Pie Register HIGH 8.1
CVE-2021-24647EPSS 10%

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a…

Fix: 3.7.1.6+
Fix from $1,950 2021-11-08
Vantara Pentaho HIGH 7.5
CVE-2021-31602EPSS 52%

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different…

Fix: after 9.1.0.0
Fix from $1,950 2021-11-08
Fedora HIGH 8.8
CVE-2021-42072

An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify …

Fix: 2.4.0+
Fix from $1,950 2021-11-08