Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-46316
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confid…
Harmonyos
2.1+
MEDIUM 5.5
CVE-2022-41590
Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation …
Harmonyos
No fix yet
MEDIUM 5.4
CVE-2022-46400
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in le…
Bm78 Firmware
No fix yet
HIGH 7.5
CVE-2022-3875
A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affect…
Passwordstate
No fix yet
MEDIUM 6.5
CVE-2022-42453
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in u…
Bigfix Platform
9.5.21 / 10.0.8+
HIGH 8.8
CVE-2022-47209
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and …
Rax30 Firmware
1.0.9.90+
HIGH 7.5
CVE-2021-35252
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an…
Serv U
15.3.2+
CRITICAL 9.1
CVE-2022-47408
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.…
Fp Newsletter
1.1.1 / 2.1.2+
MEDIUM 6.5
CVE-2022-23501
TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerabl…
TYPO3
8.7.49 / 9.5.38+
CRITICAL 9.1
CVE-2022-2757
Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an attacker viewing and modifying t…
Tms300 Cs Firmware
Mitigation only
HIGH 7.5
CVE-2022-25685
Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,…
Apq8009 Firmware
Mitigation only
HIGH 7.5
CVE-2022-23505
Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker…
Passport Wsfed Saml2
after 4.6.2
HIGH 7.8
CVE-2022-2752
A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions.
…
Gatemanager
after 9.7
HIGH 8.8
CVE-2022-46829
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
Jetbrains Gateway
2022.3+
MEDIUM 5.3
CVE-2022-45877
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authenticati…
Openharmony
after 3.1.4
MEDIUM 5.5
CVE-2022-45118
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the p…
Openharmony
after 3.1.4
MEDIUM 6.5
CVE-2022-39901
Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between U…
Exynos Firmware
Mitigation only
HIGH 8.8
CVE-2022-40966
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the de…
Wcr 300 Firmware
after 2.96
CRITICAL 9.8
CVE-2022-42458
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attack…
Bingo\!cms
after 1.7.4.1
HIGH 8.8
CVE-2022-44620
Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authentica…
Udr Ja1604 Firmware
71x10.1.107114.43a+
CRITICAL 9.8
CVE-2022-35843
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 thr…
Fortiproxy
after 7.0.7
HIGH 8.1
CVE-2022-38336
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentica…
Mobaxterm
22.2+
MEDIUM 5.3
CVE-2022-43557
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical acc…
Bodyguard 999 603 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-40242
MegaRAC Default Credentials Vulnerability
Megarac Sp X
Mitigation only
CRITICAL 9.8
CVE-2022-40259
MegaRAC Default Credentials Vulnerability
Megarac Sp X
No fix yet
CRITICAL 9.8
CVE-2022-43549
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
Veeam Backup For Google Cloud
Mitigation only
MEDIUM 5.3
CVE-2022-43504
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of th…
WordPress
3.7.40 / 3.8.40+
HIGH 8.8
CVE-2022-46411
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after insta…
Access Appliance
after 8.0.100
CRITICAL 9.8
CVE-2022-46145
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential a…
Authentik
2022.10.2 / 2022.11.2+
MEDIUM 6.5
CVE-2022-43900
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbo…
Websphere Automation For Ibm Cloud Pak For Watson Aiops
1.4.3+