Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2022-30270 The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote ma… Ace1000 Firmware Mitigation only Fix from $2,3002022-07-26 CRITICAL 9.8 CVE-2022-36412EPSS 5% In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe… Manageengine Supportcenter Plus Mitigation only Fix from $2,3002022-07-26 MEDIUM 5.7 CVE-2022-34575 An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via acc… Wifi Repeater Firmware No fix yet Fix from $1,6002022-07-25 CRITICAL 9.8 CVE-2022-34839 Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress. Wp Oauth2 Server after 1.0.1 Fix from $2,3002022-07-22 HIGH 7.5 CVE-2022-31164 Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including p… Tovy 0.7.51+ Fix from $1,9502022-07-22 MEDIUM 5.3 CVE-2022-28666 Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-togg… Custom Product Tabs For Woocommerce after 1.7.7 Fix from $1,6002022-07-21 CRITICAL 9.8 CVE-2022-26136EPSS 5% A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps… Bamboo 4.3.8 / 4.4.2+ Fix from $2,3002022-07-20 CRITICAL 9.8 CVE-2022-2141 SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication. Mv720 Firmware Mitigation only Fix from $2,3002022-07-20 HIGH 7.5 CVE-2022-34535 Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files. Megapix Firmware Mitigation only Fix from $1,9502022-07-19 CRITICAL 9.8 CVE-2022-30623 The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true… P5e Gnss Firmware No fix yet Fix from $2,3002022-07-18 HIGH 7.5 CVE-2022-30624 Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password. P5e Gnss Firmware Mitigation only Fix from $1,9502022-07-18 CRITICAL 9.8 CVE-2021-40874 An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (… Debian Linux Patch available Fix from $2,3002022-07-18 HIGH 8.8 CVE-2022-30550 An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver … Debian Linux 2.4.0+ Fix from $1,9502022-07-17 MEDIUM 5.3 CVE-2022-2133 The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to l… Oauth Single Sign On 6.22.6+ Fix from $1,6002022-07-17 CRITICAL 9.8 CVE-2017-20133 A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The ma… Job Portal Script Mitigation only Fix from $2,3002022-07-16 HIGH 7.8 CVE-2022-30755 Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the… Android Mitigation only Fix from $1,9502022-07-12 HIGH 7.5 CVE-2022-33736 A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624), Opcenter Quality V13.2 (All versions < V13.2.20220624)… Opcenter Quality 13.1.20220624 / 13.2.20220624+ Fix from $1,9502022-07-12 CRITICAL 9.8 CVE-2022-2302 Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a… C520 Firmware 01.08.01.3021+ Fix from $2,3002022-07-11 MEDIUM 6.5 CVE-2015-5298 The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are suppo… Google Login Mitigation only Fix from $1,6002022-07-07 CRITICAL 9.8 CVE-2022-31125EPSS 20% Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unaut… Roxy Wi 6.1.1.0+ Fix from $2,3002022-07-06 HIGH 8.8 CVE-2021-43116EPSS 7% An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and t… Nacos after 2.0.3 Fix from $1,9502022-07-05 MEDIUM 5.3 CVE-2022-28713 Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Informat… Garoon after 5.5.1 Fix from $1,6002022-07-04 HIGH 7.5 CVE-2021-41995 A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass. Pingid Integration For Mac Login 1.1+ Fix from $1,9502022-06-30 CRITICAL 9.8 CVE-2022-2197 By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and p… Rme1 Firmware after 2.1.6 Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2021-41506 Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.N… Ahb7008t Mh V2 Firmware No fix yet Fix from $2,3002022-06-30 HIGH 8.1 CVE-2022-33202 Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allow… L2blocker 4.8.6+ Fix from $1,9502022-06-27 MEDIUM 5.3 CVE-2022-29578 Meridian Cooperative Utility Software versions 22.02 and 22.03 allows remote attackers to obtain sensitive information such as name, address, and dai… Meridian Mitigation only Fix from $1,6002022-06-24 HIGH 7.5 CVE-2021-41638 The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by usi… Ftp Server No fix yet Fix from $1,9502022-06-24 CRITICAL 9.8 CVE-2021-26637 There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized… Sihas Sgw 300 Firmware Mitigation only Fix from $2,3002022-06-23 CRITICAL 9.8 CVE-2021-26638 Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attack… S\&d Smarthome after 3.2.48 Fix from $2,3002022-06-23