Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2022-46316 A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confid… Harmonyos 2.1+ Fix from $2,3002022-12-20 MEDIUM 5.5 CVE-2022-41590 Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation … Harmonyos No fix yet Fix from $1,6002022-12-20 MEDIUM 5.4 CVE-2022-46400 The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in le… Bm78 Firmware No fix yet Fix from $1,6002022-12-19 HIGH 7.5 CVE-2022-3875 A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affect… Passwordstate No fix yet Fix from $1,9502022-12-19 MEDIUM 6.5 CVE-2022-42453 There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in u… Bigfix Platform 9.5.21 / 10.0.8+ Fix from $1,6002022-12-19 HIGH 8.8 CVE-2022-47209 A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and … Rax30 Firmware 1.0.9.90+ Fix from $1,9502022-12-16 HIGH 7.5 CVE-2021-35252 Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an… Serv U 15.3.2+ Fix from $1,9502022-12-16 CRITICAL 9.1 CVE-2022-47408 An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.… Fp Newsletter 1.1.1 / 2.1.2+ Fix from $2,3002022-12-14 MEDIUM 6.5 CVE-2022-23501 TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerabl… TYPO3 8.7.49 / 9.5.38+ Fix from $1,6002022-12-14 CRITICAL 9.1 CVE-2022-2757 Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an attacker viewing and modifying t… Tms300 Cs Firmware Mitigation only Fix from $2,3002022-12-13 HIGH 7.5 CVE-2022-25685 Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,… Apq8009 Firmware Mitigation only Fix from $1,9502022-12-13 HIGH 7.5 CVE-2022-23505 Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker… Passport Wsfed Saml2 after 4.6.2 Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-2752 A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. … Gatemanager after 9.7 Fix from $1,9502022-12-09 HIGH 8.8 CVE-2022-46829 In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented. Jetbrains Gateway 2022.3+ Fix from $1,9502022-12-08 MEDIUM 5.3 CVE-2022-45877 OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authenticati… Openharmony after 3.1.4 Fix from $1,6002022-12-08 MEDIUM 5.5 CVE-2022-45118 OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the p… Openharmony after 3.1.4 Fix from $1,6002022-12-08 MEDIUM 6.5 CVE-2022-39901 Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between U… Exynos Firmware Mitigation only Fix from $1,6002022-12-08 HIGH 8.8 CVE-2022-40966 Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the de… Wcr 300 Firmware after 2.96 Fix from $1,9502022-12-07 CRITICAL 9.8 CVE-2022-42458 Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attack… Bingo\!cms after 1.7.4.1 Fix from $2,3002022-12-07 HIGH 8.8 CVE-2022-44620 Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authentica… Udr Ja1604 Firmware 71x10.1.107114.43a+ Fix from $1,9502022-12-07 CRITICAL 9.8 CVE-2022-35843 An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 thr… Fortiproxy after 7.0.7 Fix from $2,3002022-12-06 HIGH 8.1 CVE-2022-38336 An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentica… Mobaxterm 22.2+ Fix from $1,9502022-12-06 MEDIUM 5.3 CVE-2022-43557 The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical acc… Bodyguard 999 603 Firmware Mitigation only Fix from $1,6002022-12-05 CRITICAL 9.8 CVE-2022-40242 MegaRAC Default Credentials Vulnerability Megarac Sp X Mitigation only Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-40259 MegaRAC Default Credentials Vulnerability Megarac Sp X No fix yet Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-43549 Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms. Veeam Backup For Google Cloud Mitigation only Fix from $2,3002022-12-05 MEDIUM 5.3 CVE-2022-43504 Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of th… WordPress 3.7.40 / 3.8.40+ Fix from $1,6002022-12-05 HIGH 8.8 CVE-2022-46411 An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after insta… Access Appliance after 8.0.100 Fix from $1,9502022-12-04 CRITICAL 9.8 CVE-2022-46145 authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential a… Authentik 2022.10.2 / 2022.11.2+ Fix from $2,3002022-12-02 MEDIUM 6.5 CVE-2022-43900 IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbo… Websphere Automation For Ibm Cloud Pak For Watson Aiops 1.4.3+ Fix from $1,6002022-12-01