Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-3632
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered…
Keycloak
7.4.9 / 15.1.0+
MEDIUM 6.5
CVE-2021-3979
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algo…
Ceph Storage
Patch available
HIGH 8.8
CVE-2022-2031
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them t…
Samba
4.14.14 / 4.15.9+
MEDIUM 5.5
CVE-2021-4142
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (sim…
Candlepin
after 4.1.8-1
CRITICAL 9.8
CVE-2022-35726
Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.
Video Gallery
1.3.5+
MEDIUM 6.8
CVE-2021-3827
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an at…
Keycloak
18.0.0+
HIGH 7.2
CVE-2022-35203
An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.
Tv Ip572pi Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-34919
The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted …
Contensis
15.2.1.79+
HIGH 8.8
CVE-2022-32282
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' passw…
Avideo
No fix yet
CRITICAL 9.8
CVE-2022-34149
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
Wp Oauth Server
after 3.0.4
CRITICAL 9.8
CVE-2022-22730
Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially e…
Edge Insights For Industrial
2.6.1+
HIGH 7.5
CVE-2022-35198
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
Contract Managment System
No fix yet
CRITICAL 9.8
CVE-2022-2336
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and passwor…
Edgeaggregator
Mitigation only
CRITICAL 9.8
CVE-2022-2662
Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access t…
Portbloque S Firmware
Mitigation only
HIGH 8.8
CVE-2022-38368
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an aut…
Gateway
6.6.5712 / 6.7.1376+
HIGH 7.5
CVE-2022-36524
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
Go Rt Ac750 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-37397
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or una…
Yugabytedb
Mitigation only
MEDIUM 6.7
CVE-2022-2503
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trus…
Linux Kernel
5.19+
MEDIUM 6.5
CVE-2022-38180
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
Ktor
2.1.0+
CRITICAL 9.8
CVE-2022-2765
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown f…
Company Website Cms
No fix yet
CRITICAL 9.8
CVE-2022-32429EPSS 76%
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 al…
Msnswitch Firmware
No fix yet
MEDIUM 6.8
CVE-2022-29083
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could poten…
Chengming 3980 Firmware
1.7.0 / 1.11.0+
HIGH 7.1
CVE-2022-33732
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unpro…
Android
Mitigation only
MEDIUM 5.3
CVE-2022-36296
Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.
Activedemand
after 0.2.27
CRITICAL 9.8
CVE-2022-2664
A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/a…
Private Cloud Management Platform
Mitigation only
HIGH 7.5
CVE-2022-35142
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.
Raneto
0.17.1+
CRITICAL 9.8
CVE-2022-35925
BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brut…
Bookwyrm
0.4.5+
MEDIUM 5.4
CVE-2022-35629
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own cl…
Velociraptor
0.6.5-2+
HIGH 7.5
CVE-2016-0796
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security …
Mb.miniaudioplayer
after 1.7.6
MEDIUM 6.5
CVE-2022-2553
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes …
Debian Linux
after 1.0