Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.5 CVE-2023-0105 A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker … Keycloak Mitigation only Fix from $1,6002023-01-13 HIGH 7.5 CVE-2022-25027 The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages… Trufusion Enterprise 7.9.5.1+ Fix from $1,9502023-01-12 CRITICAL 9.8 CVE-2022-39184 EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass. Bv 10 Firmware Mitigation only Fix from $2,3002023-01-12 HIGH 7.5 CVE-2022-4874EPSS 11% Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static … Nf20 Firmware No fix yet Fix from $1,9502023-01-11 HIGH 8.1 CVE-2022-35401EPSS 21% An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-craft… Rt Ax82u Firmware No fix yet Fix from $1,9502023-01-10 HIGH 7.8 CVE-2023-0035 softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows a… Openharmony after 3.0.5 Fix from $1,9502023-01-09 HIGH 7.8 CVE-2023-0036 platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA … Openharmony after 3.0.5 Fix from $1,9502023-01-09 CRITICAL 9.8 CVE-2022-1101 A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown proces… Event Management System Mitigation only Fix from $2,3002023-01-07 CRITICAL 9.8 CVE-2014-125060 A vulnerability, which was classified as critical, was found in holdennb CollabCal. Affected is the function handleGet of the file calenderServer.cpp… Collabcal 2014-12-09+ Fix from $2,3002023-01-07 MEDIUM 6.5 CVE-2022-47974 The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the Bluetooth pro… Emui 2.0+ Fix from $1,6002023-01-06 HIGH 7.5 CVE-2022-47976 The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerab… Emui 2.0+ Fix from $1,9502023-01-06 CRITICAL 9.8 CVE-2021-40342 In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensi… Foxman Un Mitigation only Fix from $2,3002023-01-05 MEDIUM 6.5 CVE-2022-43528 Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code… Aruba Edgeconnect Enterprise Orchestrator after 9.2.1.40179 Fix from $1,6002023-01-05 CRITICAL 9.8 CVE-2022-39042 aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication … A\+hrd Mitigation only Fix from $2,3002023-01-03 CRITICAL 9.8 CVE-2022-48195 An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises suppor… Sasl Mitigation only Fix from $2,3002022-12-31 MEDIUM 5.4 CVE-2022-23554 Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the r… Alpine 1.10.4+ Fix from $1,6002022-12-28 MEDIUM 6.5 CVE-2022-41579 There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect… Hota Fara B19 Firmware Mitigation only Fix from $1,6002022-12-28 MEDIUM 6.4 CVE-2022-46172 authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticate… Authentik 2022.10.4 / 2022.11.4+ Fix from $1,6002022-12-28 HIGH 8.8 CVE-2022-23555 authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Imp… Authentik 2022.10.4 / 2022.11.4+ Fix from $1,9502022-12-28 CRITICAL 9.1 CVE-2020-36569 Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063… Golang Nanoauth after 2020-01-31 Fix from $2,3002022-12-27 HIGH 7.8 CVE-2022-3156 A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on ce… Studio 5000 Logix Emulate 34.00+ Fix from $1,9502022-12-27 HIGH 7.2 CVE-2022-4722 Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5. Rdiffweb 2.5.5+ Fix from $1,9502022-12-27 CRITICAL 9.8 CVE-2020-11101 Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with a… Airlink Mobility Manager 2.17+ Fix from $2,3002022-12-26 HIGH 8.1 CVE-2022-47633 An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to … Kyverno Patch available Fix from $1,9502022-12-23 MEDIUM 6.5 CVE-2022-46875 The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This… Firefox 102.6 / 108.0+ Fix from $1,6002022-12-22 MEDIUM 5.3 CVE-2022-35646 IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's acc… Security Verify Governance Patch available Fix from $1,6002022-12-22 CRITICAL 9.8 CVE-2022-46170 CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin page… Codeigniter 4.2.11+ Fix from $2,3002022-12-22 HIGH 7.6 CVE-2022-23540 In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass … Jsonwebtoken after 8.5.1 Fix from $1,9502022-12-22 MEDIUM 6.3 CVE-2022-23541 jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly imp… Jsonwebtoken after 8.5.1 Fix from $1,6002022-12-22 MEDIUM 5.3 CVE-2022-46313 The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartpho… Harmonyos 3.0.0+ Fix from $1,6002022-12-20