Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2021-3632 A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered… Keycloak 7.4.9 / 15.1.0+ Fix from $1,9502022-08-26 MEDIUM 6.5 CVE-2021-3979 A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algo… Ceph Storage Patch available Fix from $1,6002022-08-25 HIGH 8.8 CVE-2022-2031 A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them t… Samba 4.14.14 / 4.15.9+ Fix from $1,9502022-08-25 MEDIUM 5.5 CVE-2021-4142 The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (sim… Candlepin after 4.1.8-1 Fix from $1,6002022-08-24 CRITICAL 9.8 CVE-2022-35726 Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress. Video Gallery 1.3.5+ Fix from $2,3002022-08-23 MEDIUM 6.8 CVE-2021-3827 A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an at… Keycloak 18.0.0+ Fix from $1,6002022-08-23 HIGH 7.2 CVE-2022-35203 An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information. Tv Ip572pi Firmware Mitigation only Fix from $1,9502022-08-23 CRITICAL 9.8 CVE-2022-34919 The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted … Contensis 15.2.1.79+ Fix from $2,3002022-08-23 HIGH 8.8 CVE-2022-32282 An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' passw… Avideo No fix yet Fix from $1,9502022-08-22 CRITICAL 9.8 CVE-2022-34149 Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress. Wp Oauth Server after 3.0.4 Fix from $2,3002022-08-22 CRITICAL 9.8 CVE-2022-22730 Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially e… Edge Insights For Industrial 2.6.1+ Fix from $2,3002022-08-18 HIGH 7.5 CVE-2022-35198 Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information. Contract Managment System No fix yet Fix from $1,9502022-08-18 CRITICAL 9.8 CVE-2022-2336 Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and passwor… Edgeaggregator Mitigation only Fix from $2,3002022-08-17 CRITICAL 9.8 CVE-2022-2662 Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access t… Portbloque S Firmware Mitigation only Fix from $2,3002022-08-16 HIGH 8.8 CVE-2022-38368 An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an aut… Gateway 6.6.5712 / 6.7.1376+ Fix from $1,9502022-08-15 HIGH 7.5 CVE-2022-36524 D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh. Go Rt Ac750 Firmware Mitigation only Fix from $1,9502022-08-15 CRITICAL 9.8 CVE-2022-37397 An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or una… Yugabytedb Mitigation only Fix from $2,3002022-08-12 MEDIUM 6.7 CVE-2022-2503 Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trus… Linux Kernel 5.19+ Fix from $1,6002022-08-12 MEDIUM 6.5 CVE-2022-38180 In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases Ktor 2.1.0+ Fix from $1,6002022-08-12 CRITICAL 9.8 CVE-2022-2765 A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown f… Company Website Cms No fix yet Fix from $2,3002022-08-11 CRITICAL 9.8 CVE-2022-32429EPSS 76% An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 al… Msnswitch Firmware No fix yet Fix from $2,3002022-08-10 MEDIUM 6.8 CVE-2022-29083 Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could poten… Chengming 3980 Firmware 1.7.0 / 1.11.0+ Fix from $1,6002022-08-09 HIGH 7.1 CVE-2022-33732 Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unpro… Android Mitigation only Fix from $1,9502022-08-05 MEDIUM 5.3 CVE-2022-36296 Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete. Activedemand after 0.2.27 Fix from $1,6002022-08-05 CRITICAL 9.8 CVE-2022-2664 A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/a… Private Cloud Management Platform Mitigation only Fix from $2,3002022-08-05 HIGH 7.5 CVE-2022-35142 An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter. Raneto 0.17.1+ Fix from $1,9502022-08-04 CRITICAL 9.8 CVE-2022-35925 BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brut… Bookwyrm 0.4.5+ Fix from $2,3002022-08-02 MEDIUM 5.4 CVE-2022-35629 Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own cl… Velociraptor 0.6.5-2+ Fix from $1,6002022-07-29 HIGH 7.5 CVE-2016-0796 WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security … Mb.miniaudioplayer after 1.7.6 Fix from $1,9502022-07-28 MEDIUM 6.5 CVE-2022-2553 The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes … Debian Linux after 1.0 Fix from $1,6002022-07-28