Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Hurd HIGH 7.0
CVE-2021-43414

An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middl…

Fix: 0.9.20210404-9+
Fix from $1,950 2021-11-07
Data Catalog CRITICAL 9.8
CVE-2021-42837

An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the nati…

Fix: 7.3-20210930+
Fix from $2,300 2021-11-05
Samsung Pass HIGH 7.8
CVE-2021-25505

Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.

Fix: 3.0.02.4+
Fix from $1,950 2021-11-05
Health MEDIUM 5.5
CVE-2021-25506

Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.

Fix: 6.19.1.0001+
Fix from $1,600 2021-11-05
Traffic Server HIGH 8.1
CVE-2021-38161

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Ap…

Fix: after 8.0.8
Fix from $1,950 2021-11-03
Data Center HIGH 7.5
CVE-2021-41312

Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to e…

Fix: 8.19.1+
Fix from $1,950 2021-11-03
Emui MEDIUM 5.3
CVE-2021-22490

There is a Permission verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect the device performance.

Mitigation only
Fix from $1,600 2021-10-28
Emui HIGH 7.5
CVE-2021-22473

There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2021-10-28
Webaccess\/nms MEDIUM 5.3
CVE-2021-32951

WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources…

Fix: after 3.0.3
Fix from $1,600 2021-10-27
Freeswitch MEDIUM 5.3
CVE-2021-41157

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.10.6+
Fix from $1,600 2021-10-26
Freeswitch HIGH 7.5
CVE-2021-37624

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.10.7+
Fix from $1,950 2021-10-25
Aqt1000 Firmware HIGH 7.5
CVE-2021-30302

Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, Snapdragon Conne…

Mitigation only
Fix from $1,950 2021-10-20
Apq8053 Firmware HIGH 7.5
CVE-2021-30312

Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdrago…

Patch available
Fix from $1,950 2021-10-20
128 Technology Session Smart Router Firmware CRITICAL 9.8
CVE-2021-31349

The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change se…

Fix: 4.5.11+
Fix from $2,300 2021-10-19
Cluster Glue MEDIUM 5.5
CVE-2010-2496

stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwor…

Fix: 1.0.6 / 1.1.3+
Fix from $1,600 2021-10-18
Hero Ct060 Firmware CRITICAL 9.8
CVE-2021-37123

There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain o…

Fix: 1.0.0.200+
Fix from $2,300 2021-10-11
Panel HIGH 8.1
CVE-2021-41129

Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati…

Fix: 1.6.2+
Fix from $1,950 2021-10-06
October HIGH 7.2
CVE-2021-41126

October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts whi…

Fix: 2.1.12+
Fix from $1,950 2021-10-06
Android MEDIUM 6.0
CVE-2021-25490

A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.

Mitigation only
Fix from $1,600 2021-10-06
Android HIGH 7.8
CVE-2021-0595

In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. Thi…

Patch available
Fix from $1,950 2021-10-06
Grafana HIGH 7.3
CVE-2021-39226 KEVEPSS 100%

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit…

Fix: 7.5.11 / 8.1.6+
Fix from $1,950 2021-10-05
Multicash HIGH 7.8
CVE-2021-41286

Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the application, the validity of the p…

Mitigation only
Fix from $1,950 2021-10-05
GitLab MEDIUM 6.5
CVE-2021-39872

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLa…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
Rexroth Indramotion Mlc L20 Firmware CRITICAL 9.8
CVE-2021-23857

Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combin…

Fix: after 12
Fix from $2,300 2021-10-04
Hg150 Ub Firmware CRITICAL 9.8
CVE-2021-35296

An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie val…

No fix yet
Fix from $2,300 2021-10-04
Cloud Pak For Security CRITICAL 9.8
CVE-2021-20578

IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m…

Patch available
Fix from $2,300 2021-09-30
Ecs Router Controller Ecs Firmware CRITICAL 9.1
CVE-2021-41292

ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass aut…

Mitigation only
Fix from $2,300 2021-09-30
Couchbase Server CRITICAL 9.8
CVE-2021-35943

Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password,…

Fix: 6.6.3+
Fix from $2,300 2021-09-29
Openvpn Monitor HIGH 7.5
CVE-2021-31606

furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.

Fix: after 1.1.3
Fix from $1,950 2021-09-27
Webauthn Framwork CRITICAL 9.8
CVE-2021-38299

Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable servic…

Fix: 3.2.9 / 3.3.4+
Fix from $2,300 2021-09-27