Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Dcs 932l Firmware HIGH 8.0
CVE-2021-41503

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command int…

Fix: after 2.17
Fix from $1,950 2021-09-24
Enterprise Server CRITICAL 9.8
CVE-2021-22869

An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not ha…

Fix: 3.0.16 / 3.1.8+
Fix from $2,300 2021-09-24
Data Grid CRITICAL 9.8
CVE-2021-31917

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat…

Fix: 11.0.12 / 12.1.4+
Fix from $2,300 2021-09-21
Portserver Ts 16 Firmware CRITICAL 9.8
CVE-2021-38412

Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require auth…

Mitigation only
Fix from $2,300 2021-09-17
Xss Hunter Express CRITICAL 9.8
CVE-2021-41317

XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.

Fix: 2021-09-17+
Fix from $2,300 2021-09-17
Shiro CRITICAL 9.8
CVE-2021-41303EPSS 77%

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul…

Fix: 1.8.0+
Fix from $2,300 2021-09-17
Ipc Hum7xxx Firmware CRITICAL 9.8
CVE-2021-33044 KEVEPSS 100%

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authenti…

Fix: 2.800.0000000.29.r.210630 / 2.812.0000007.0.r.210706+
Fix from $2,300 2021-09-15
Ipc Hum7xxx Firmware CRITICAL 9.8
CVE-2021-33045 KEVEPSS 100%

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authenti…

Fix: 2.800.0000000.29.r.210630 / 2.820.0000000.5.r.210705+
Fix from $2,300 2021-09-15
Business One HIGH 7.8
CVE-2021-33700

SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim wit…

Patch available
Fix from $1,950 2021-09-15
Jitsi Meet HIGH 7.5
CVE-2021-39215

Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms…

Patch available
Fix from $1,950 2021-09-15
Identity Vault MEDIUM 6.7
CVE-2021-3145

In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.

Fix: 5.0+
Fix from $1,600 2021-09-10
Manageengine Desktop Central HIGH 7.5
CVE-2021-37414EPSS 5%

Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.

Fix: 10.0.709+
Fix from $1,950 2021-09-10
Internet MEDIUM 5.9
CVE-2021-25466

Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Sa…

Fix: 15.0.2.47+
Fix from $1,600 2021-09-09
Openbmc CRITICAL 10.0
CVE-2021-39296

In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.

Mitigation only
Fix from $2,300 2021-09-09
Metamako Operating System HIGH 8.8
CVE-2021-28494

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypasse…

Fix: after 0.34.0
Fix from $1,950 2021-09-09
Metamako Operating System CRITICAL 9.8
CVE-2021-28495

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can b…

Fix: 0.32.0+
Fix from $2,300 2021-09-09
Metamako Operating System HIGH 7.8
CVE-2021-28493

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to exe…

Fix: after 0.32.0
Fix from $1,950 2021-09-09
Broadworks Commpilot Application Software HIGH 7.2
CVE-2021-34785

Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user ac…

Fix: 22.0.2021.09 / 23.0.2021.09+
Fix from $1,950 2021-09-09
Chrome Os Readiness Tool HIGH 7.8
CVE-2021-30605

Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing …

Fix: 1.0.2.0+
Fix from $1,950 2021-09-08
Ipados MEDIUM 5.4
CVE-2021-30667

A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in WiFi range may be able to force…

Fix: 14.6+
Fix from $1,600 2021-09-08
Iphone Os MEDIUM 5.5
CVE-2021-30769

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitr…

Fix: 7.6 / 14.7+
Fix from $1,600 2021-09-08
Iphone Os MEDIUM 5.5
CVE-2021-30770

A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved …

Fix: 7.6 / 14.7+
Fix from $1,600 2021-09-08
Safari MEDIUM 5.4
CVE-2021-30720

A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4…

Fix: 7.5 / 11.4+
Fix from $1,600 2021-09-08
Apq8053 Firmware CRITICAL 9.8
CVE-2020-11264EPSS 13%

Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Aut…

Patch available
Fix from $2,300 2021-09-08
Apq8009 Firmware HIGH 7.5
CVE-2020-11301EPSS 11%

Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdra…

Patch available
Fix from $1,950 2021-09-08
Pcapture MEDIUM 6.5
CVE-2021-39196

pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to u…

Fix: 3.12+
Fix from $1,600 2021-09-07
Enterprise Nfv Infrastructure Software CRITICAL 9.8
CVE-2021-34746EPSS 18%

A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) cou…

Fix: 4.6.1+
Fix from $2,300 2021-09-02
Dwu850 Gs Firmware CRITICAL 9.8
CVE-2021-40350

webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafted query containing an unspeci…

No fix yet
Fix from $2,300 2021-09-01
Identity Manager CRITICAL 9.8
CVE-2021-22002

VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a …

Patch available
Fix from $2,300 2021-08-31
Unifi Protect CRITICAL 9.6
CVE-2021-22943

A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subseq…

Fix: 1.19.0+
Fix from $2,300 2021-08-31