Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.3 CVE-2022-32928 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network po… Iphone Os 9.0 / 13.0+ Fix from $1,6002022-11-01 CRITICAL 9.8 CVE-2022-2572 In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a dis… Octopus Server 2022.1.3264 / 2022.2.8277+ Fix from $2,3002022-11-01 HIGH 7.5 CVE-2022-39018 Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a know… Hubshare 3.3.11.3+ Fix from $1,9502022-10-31 HIGH 7.5 CVE-2022-39019 Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the a… Hubshare 3.3.11.3+ Fix from $1,9502022-10-31 CRITICAL 9.8 CVE-2022-41648 The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machin… Tnc 640 Programming Station Mitigation only Fix from $2,3002022-10-28 CRITICAL 9.8 CVE-2022-39366 DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not veri… Datahub 0.8.45+ Fix from $2,3002022-10-28 CRITICAL 9.8 CVE-2022-37913 Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to … Aruba Edgeconnect Enterprise Orchestrator 8.10.23.40009 / 9.0.7.40108+ Fix from $2,3002022-10-28 CRITICAL 9.8 CVE-2022-37914 Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to … Aruba Edgeconnect Enterprise Orchestrator 8.10.23.40009 / 9.0.7.40108+ Fix from $2,3002022-10-28 HIGH 7.5 CVE-2022-38744 An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, caus… Factorytalk Alarms And Events Mitigation only Fix from $1,9502022-10-27 MEDIUM 6.1 CVE-2022-40703 CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthentica… Kardia after 5.17.1-754993421 Fix from $1,6002022-10-26 CRITICAL 9.8 CVE-2022-39355 Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabled, an improper authenticatio… Patreon 2022-10-26+ Fix from $2,3002022-10-26 MEDIUM 6.5 CVE-2022-39360 Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) us… Metabase 0.41.9 / 0.42.6+ Fix from $1,6002022-10-26 CRITICAL 9.8 CVE-2022-3674 A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an … Sanitization Management System Mitigation only Fix from $2,3002022-10-26 CRITICAL 9.8 CVE-2022-26870 Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vul… Powerstoreos Patch available Fix from $2,3002022-10-21 CRITICAL 9.8 CVE-2022-43400 A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected… Siveillance Video Mobile Server 22.2a+ Fix from $2,3002022-10-21 CRITICAL 9.8 CVE-2022-42233EPSS 43% Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability. 11n Firmware No fix yet Fix from $2,3002022-10-20 CRITICAL 9.8 CVE-2022-37298 Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safep… Shinken Monitoring Patch available Fix from $2,3002022-10-20 HIGH 8.8 CVE-2022-39267 Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environ… Bifrost after 1.8.6 Fix from $1,9502022-10-19 MEDIUM 5.3 CVE-2022-21618 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affec… Fedora after 11.70.2 Fix from $1,6002022-10-18 CRITICAL 9.8 CVE-2022-40684 KEVEPSS 100% An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiP… Fortiproxy 7.0.7 / 7.2.2+ Fix from $2,3002022-10-18 HIGH 8.1 CVE-2022-31122 Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If… Wire Server 2022-07-12+ Fix from $1,9502022-10-18 MEDIUM 6.5 CVE-2022-22237 An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an imp… Junos Mitigation only Fix from $1,6002022-10-18 HIGH 7.4 CVE-2022-2533 An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all v… GitLab 15.1.6 / 15.2.4+ Fix from $1,9502022-10-17 CRITICAL 9.8 CVE-2022-23769 Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerabilit… Reversewall Mds 3.8_a008+ Fix from $2,3002022-10-17 CRITICAL 9.1 CVE-2022-41436 An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/index1.ht… Tp50 Firmware No fix yet Fix from $2,3002022-10-14 CRITICAL 9.8 CVE-2022-38982 The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked. Harmonyos No fix yet Fix from $2,3002022-10-14 HIGH 7.8 CVE-2022-42488 OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious applicat… Openharmony 3.1.2+ Fix from $1,9502022-10-14 HIGH 8.8 CVE-2022-42463 OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication su… Openharmony after 3.1.2 Fix from $1,9502022-10-14 HIGH 8.8 CVE-2022-35135 Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>. Iot Platform No fix yet Fix from $1,9502022-10-13 HIGH 7.5 CVE-2021-36369 An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH … Debian Linux after 2020.81 Fix from $1,9502022-10-12