Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2022-3465 A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of the file /index.asp. The manipu… Mlwr Ac1200r Firmware No fix yet Fix from $2,3002022-10-12 CRITICAL 9.8 CVE-2022-40664 Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. Shiro 1.10.0+ Fix from $2,3002022-10-12 HIGH 7.5 CVE-2022-39289 ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log conten… Zoneminder 1.37.24+ Fix from $1,9502022-10-07 MEDIUM 6.5 CVE-2022-39290EPSS 6% ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by mo… Zoneminder 1.36.27 / 1.37.24+ Fix from $1,6002022-10-07 MEDIUM 6.5 CVE-2022-21936 On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when usin… Metasys Extended Application And Data Server Mitigation only Fix from $1,6002022-10-07 CRITICAL 9.8 CVE-2022-40494 NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp… Nps after 0.26.10 Fix from $2,3002022-10-06 MEDIUM 6.8 CVE-2022-20662 A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass … Duo 2.0.0+ Fix from $1,6002022-09-30 HIGH 7.5 CVE-2022-39252 matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to vers… Matrix Rust Sdk 0.6+ Fix from $1,9502022-09-29 MEDIUM 6.5 CVE-2022-39254 matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from… Matrix Nio 0.20+ Fix from $1,6002022-09-29 HIGH 7.5 CVE-2022-39250 Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating wit… Javascript Sdk 19.7.0+ Fix from $1,9502022-09-29 MEDIUM 6.5 CVE-2021-40693 An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability. Moodle 3.9.10 / 3.10.7+ Fix from $1,6002022-09-29 MEDIUM 5.9 CVE-2022-39264 nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets,… Fedora 0.10.2+ Fix from $1,6002022-09-28 HIGH 7.5 CVE-2022-39257 Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeser… Software Development Kit 0.23.19+ Fix from $1,9502022-09-28 HIGH 8.1 CVE-2022-39263 `@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `ne… Next Auth 3.0.2+ Fix from $1,9502022-09-28 HIGH 7.5 CVE-2022-39255 Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeser… Software Development Kit 0.23.19+ Fix from $1,9502022-09-28 HIGH 7.5 CVE-2022-39249 Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver ca… Javascript Sdk 19.7.0+ Fix from $1,9502022-09-28 HIGH 7.5 CVE-2022-39251 Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver ca… Javascript Sdk 19.7.0+ Fix from $1,9502022-09-28 HIGH 7.5 CVE-2022-39248 matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages… Software Development Kit 1.5.1+ Fix from $1,9502022-09-28 MEDIUM 5.3 CVE-2022-39246 matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages… Software Development Kit 1.5.1+ Fix from $1,6002022-09-28 HIGH 7.5 CVE-2022-22523 An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App whi… Cpy Car Park Server 2.8.3 / 8.5.0.3+ Fix from $1,9502022-09-28 MEDIUM 6.5 CVE-2022-39219 Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vul… Bifrost 1.8.7+ Fix from $1,6002022-09-26 HIGH 7.8 CVE-2022-39245 Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable … Mist 0.9.5+ Fix from $1,9502022-09-26 HIGH 7.5 CVE-2022-3119 The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unau… Oauth Client Single Sign On 3.0.4+ Fix from $1,9502022-09-26 HIGH 8.8 CVE-2022-35248 A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypassed when te… Rocket.chat 4.7.5 / 4.8.2+ Fix from $1,9502022-09-23 MEDIUM 6.8 CVE-2022-30124 An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile dev… Rocket.chat 4.14.1.22788+ Fix from $1,6002022-09-23 MEDIUM 5.9 CVE-2021-45035 Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has acce… Vclient Mitigation only Fix from $1,6002022-09-23 HIGH 8.8 CVE-2022-39238 Arvados is an open source platform for managing and analyzing biomedical big data. In versions prior to 2.4.3, when using Portable Authentication Mod… Arvados 2.4.3+ Fix from $1,9502022-09-23 HIGH 8.1 CVE-2022-40616 IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tas… Maximo Asset Management Mitigation only Fix from $1,9502022-09-21 MEDIUM 6.8 CVE-2021-33076 Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege… Ssd 600p Firmware 002c / 003c+ Fix from $1,6002022-09-20 CRITICAL 9.8 CVE-2022-28321 The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctl… Linux Pam 1.5.2-6.1+ Fix from $2,3002022-09-19