Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2022-40144 A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by… Apex One Patch available Fix from $2,3002022-09-19 CRITICAL 9.8 CVE-2022-3218EPSS 73% Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which… Wifi Mouse Server Patch available Fix from $2,3002022-09-19 CRITICAL 9.8 CVE-2022-39009 The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WL… Emui No fix yet Fix from $2,3002022-09-16 CRITICAL 9.8 CVE-2021-42949EPSS 6% The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to by… Hoteldruid Mitigation only Fix from $2,3002022-09-16 HIGH 7.8 CVE-2022-25652 Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking Csr8811 Firmware Mitigation only Fix from $1,9502022-09-16 CRITICAL 9.8 CVE-2022-36436 OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability tha… Twisted Vnc Authentication Proxy 1.2.0+ Fix from $2,3002022-09-14 HIGH 8.8 CVE-2022-40622 The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens.… Wn531g3 Firmware No fix yet Fix from $1,9502022-09-13 CRITICAL 9.8 CVE-2022-39205 Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a On… Onedev 7.3.0+ Fix from $2,3002022-09-13 MEDIUM 5.4 CVE-2022-36106 TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the expiration time of a pass… TYPO3 after 11.5.15 Fix from $1,6002022-09-13 HIGH 7.5 CVE-2022-39801 SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefi… Access Control Mitigation only Fix from $1,9502022-09-13 MEDIUM 5.5 CVE-2022-38081 OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take adv… Openharmony after 3.1.2 Fix from $1,6002022-09-09 HIGH 8.8 CVE-2022-38700 OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera s… Openharmony Mitigation only Fix from $1,9502022-09-09 MEDIUM 5.5 CVE-2022-38064 OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive informa… Openharmony after 3.1.2 Fix from $1,6002022-09-09 HIGH 7.5 CVE-2022-36092 XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.4, all rights checks that wou… Xwiki 13.10.4 / 14.2+ Fix from $1,9502022-09-08 HIGH 7.1 CVE-2022-36093 XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart… Xwiki 13.10.5 / 14.3+ Fix from $1,9502022-09-08 CRITICAL 9.8 CVE-2022-37163 Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via bru… Ihatetobudget Mitigation only Fix from $2,3002022-09-08 CRITICAL 9.8 CVE-2022-37164 Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force a… Ontrack Mitigation only Fix from $2,3002022-09-08 CRITICAL 9.8 CVE-2022-20923 A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an… Rv110w Firmware Mitigation only Fix from $2,3002022-09-08 MEDIUM 6.8 CVE-2022-38399 Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an a… Cs Qr20 Firmware Mitigation only Fix from $1,6002022-09-08 HIGH 8.8 CVE-2022-36073 RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org acco… Rubygems 2022-08-31+ Fix from $1,9502022-09-07 HIGH 8.8 CVE-2022-3152 Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20. Phpfusion 9.10.20+ Fix from $1,9502022-09-07 HIGH 7.8 CVE-2022-26858 Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerabil… Alienware M15 R6 Firmware 1.8.0 / 1.8.2+ Fix from $1,9502022-09-06 HIGH 8.8 CVE-2022-31020 Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` re… Indy Node after 1.12.4 Fix from $1,9502022-09-06 HIGH 8.1 CVE-2022-36071 SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based… Sftpgo 2.3.4+ Fix from $1,9502022-09-02 CRITICAL 9.1 CVE-2022-34372 Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may pote… Powerprotect Cyber Recovery 19.11.0.2+ Fix from $2,3002022-09-01 CRITICAL 9.8 CVE-2022-34379 Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active d… Cloudlink 7.1.3+ Fix from $2,3002022-09-01 HIGH 8.2 CVE-2022-34380 Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged lo… Cloudlink 7.1.4+ Fix from $1,9502022-09-01 CRITICAL 9.8 CVE-2022-38556 Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh. Tew733gr Firmware No fix yet Fix from $2,3002022-08-28 CRITICAL 9.8 CVE-2022-38557 D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh. Dir 845l Firmware after 1.0.3 Fix from $2,3002022-08-28 CRITICAL 9.8 CVE-2022-36755 D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php. Dir 845l Firmware after 1.0.3 Fix from $2,3002022-08-28