Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-29775EPSS 61%
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
Ispy
No fix yet
CRITICAL 9.8
CVE-2022-33139
A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.1…
Cerberus Dms
Mitigation only
HIGH 7.5
CVE-2022-1801
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fiel…
Very Simple Contact Form
11.6+
HIGH 7.5
CVE-2022-31083
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the cert…
Parse Server
4.10.11 / 5.2.2+
HIGH 7.5
CVE-2022-32276
Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vu…
Grafana
No fix yet
HIGH 8.8
CVE-2018-25043
A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads t…
Utorrent
No fix yet
HIGH 7.8
CVE-2020-36548
A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The mani…
Voluson S8 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-33750
CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentia…
Ca Automic Automation
Mitigation only
HIGH 7.5
CVE-2018-18907
An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireles…
Dir 850l Firmare
1.21b07+
HIGH 7.5
CVE-2022-29865
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.
Ua .net Standard Stack
1.4.368.58+
HIGH 7.5
CVE-2022-30150
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
Windows 10
Patch available
HIGH 7.5
CVE-2022-21935
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password cha…
Metasys Application And Data Server
10.1.5+
CRITICAL 9.8
CVE-2022-20733
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentia…
Identity Services Engine
No fix yet
CRITICAL 9.8
CVE-2022-20798
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appli…
Email Security Appliance
13.0.0-277 / 13.6.2-090+
HIGH 7.2
CVE-2022-30229
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated acce…
Sicam Gridedge Essential
2.6.6+
HIGH 7.8
CVE-2021-35094
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon…
Aqt1000 Firmware
Mitigation only
MEDIUM 6.8
CVE-2022-22259
There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a contr…
Flmg 10 Firmware
Mitigation only
HIGH 7.8
CVE-2022-30749
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login act…
Smartthings
1.7.85.25+
MEDIUM 6.5
CVE-2020-36528
A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken acce…
Platinum Mobile
No fix yet
CRITICAL 9.8
CVE-2020-36533
A vulnerability was found in Klapp App and classified as problematic. This issue affects some unknown processing of the JSON Web Token Handler. The m…
App
No fix yet
HIGH 8.8
CVE-2022-30238
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a sessio…
Wiser Smart Eer21000 Firmware
after 4.5
HIGH 7.1
CVE-2022-31463
Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is used.
Meeting Owl Pro Firmware
5.4.2.3+
HIGH 8.6
CVE-2022-30034
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker coul…
Flower
1.2.0+
HIGH 7.5
CVE-2022-26975
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.
Control Room Management Suite
3.14.1+
CRITICAL 9.8
CVE-2022-31013
Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the acc…
Chat Server
2.6.0+
HIGH 7.8
CVE-2022-31011
TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an at…
Tidb
Mitigation only
MEDIUM 5.5
CVE-2022-26724
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Pho…
Tvos
15.5+
HIGH 8.1
CVE-2022-22576
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections witho…
Curl
7.83.0+
CRITICAL 9.8
CVE-2022-24422EPSS 58%
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacke…
Idrac9
5.10.10.00+
MEDIUM 6.8
CVE-2022-26865
Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical acces…
Supportassist Os Recovery
Mitigation only