Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.4 CVE-2022-45724 Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthent… Cf Wr610n Firmware No fix yet Fix from $1,6002023-02-13 HIGH 8.1 CVE-2023-25559 DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata… Datahub 0.8.45+ Fix from $1,9502023-02-11 MEDIUM 5.5 CVE-2023-21437 Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via… Android Mitigation only Fix from $1,6002023-02-09 MEDIUM 5.5 CVE-2023-21425 Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information. Android Mitigation only Fix from $1,6002023-02-09 HIGH 7.5 CVE-2023-21419 An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain co… Android Mitigation only Fix from $1,9502023-02-09 HIGH 7.5 CVE-2022-48294 The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality. Emui No fix yet Fix from $1,9502023-02-09 HIGH 8.1 CVE-2022-42951 An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbas… Couchbase Server 6.6.6 / 7.0.5+ Fix from $1,9502023-02-06 CRITICAL 9.1 CVE-2023-22501EPSS 16% An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user… Jira Service Management 5.3.3 / 5.4.2+ Fix from $2,3002023-02-01 CRITICAL 9.8 CVE-2022-47003 A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. Mura Cms 10.0.580+ Fix from $2,3002023-02-01 HIGH 7.5 CVE-2020-20402 Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation. Portfoliocms No fix yet Fix from $1,9502023-01-31 HIGH 8.8 CVE-2022-4041 Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escal… Storage Plug In Mitigation only Fix from $1,9502023-01-31 HIGH 8.8 CVE-2022-4441 Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escal… Storage Plug In Mitigation only Fix from $1,9502023-01-31 HIGH 7.8 CVE-2022-30421 Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(lo… Storage Security Software No fix yet Fix from $1,9502023-01-31 CRITICAL 9.8 CVE-2022-32514 A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affe… 5500ac2 Firmware 1.11.0+ Fix from $2,3002023-01-30 HIGH 7.5 CVE-2023-24830 Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before… Iotdb 0.13.3+ Fix from $1,9502023-01-30 CRITICAL 9.8 CVE-2022-48066 An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie. A830r Firmware No fix yet Fix from $2,3002023-01-27 HIGH 8.8 CVE-2023-23612 OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained from the Identity Provider (Id… Opensearch 1.3.8 / 2.5.0+ Fix from $1,9502023-01-26 MEDIUM 6.8 CVE-2023-20924 In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege w… Android Mitigation only Fix from $1,6002023-01-26 HIGH 7.5 CVE-2021-43444 ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default U… Server after 7.0.0.49 Fix from $1,9502023-01-23 CRITICAL 9.8 CVE-2021-43445 ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONL… Server after 7.0.0.49 Fix from $2,3002023-01-23 CRITICAL 9.1 CVE-2020-22657 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10… R310 Firmware 3.6.2.0.795+ Fix from $2,3002023-01-20 CRITICAL 9.1 CVE-2023-22964 Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled. Manageengine Servicedesk Plus Msp Mitigation only Fix from $2,3002023-01-20 MEDIUM 5.3 CVE-2023-22334 Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authent… Conprosys Hmi System after 3.4.5 Fix from $1,6002023-01-20 HIGH 8.8 CVE-2022-45922 An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd coo… Opentext Extended Ecm after 22.1 Fix from $1,9502023-01-18 MEDIUM 5.3 CVE-2021-4314 It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happ… Zowe Api Mediation Layer 1.19.0+ Fix from $1,6002023-01-18 HIGH 7.5 CVE-2023-21841 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3… Weblogic Server Patch available Fix from $1,9502023-01-18 MEDIUM 5.3 CVE-2023-22278 m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to bypass auth… M Filter 4.87r04 / 5.70r01+ Fix from $1,6002023-01-17 CRITICAL 9.8 CVE-2023-22303 TP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerability. Under the certain condit… Tl Sg105pe Firmware Mitigation only Fix from $2,3002023-01-17 CRITICAL 9.8 CVE-2023-0311 Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10. Phpmyfaq 3.1.10+ Fix from $2,3002023-01-15 CRITICAL 9.1 CVE-2023-22497 Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an automatically generated MACHI… Netdata 1.37.0+ Fix from $2,3002023-01-14