Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2013-10004 A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the functi… Samwin Agent No fix yet Fix from $2,3002022-05-24 HIGH 7.5 CVE-2021-4230 A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup ha… Airfield Online Mitigation only Fix from $1,9502022-05-24 MEDIUM 5.4 CVE-2022-29237 Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10.14 and 11.7, users could pass… Opencast 10.14 / 11.7+ Fix from $1,6002022-05-24 MEDIUM 6.5 CVE-2022-0910 A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions… Vpn100 Firmware after 5.21 Fix from $1,6002022-05-24 CRITICAL 10.0 CVE-2022-29165 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with versi… Argo Cd 2.1.15 / 2.2.9+ Fix from $2,3002022-05-20 HIGH 7.2 CVE-2021-30028 SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service,… Sooteway Wi Fi Range Extender No fix yet Fix from $1,9502022-05-20 MEDIUM 5.3 CVE-2022-29883 A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the… 7kg8500 0aa00 0aa0 Firmware 3.00+ Fix from $1,6002022-05-20 CRITICAL 9.8 CVE-2022-28106 Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POST request. Online Sports Complex Booking System No fix yet Fix from $2,3002022-05-20 MEDIUM 6.8 CVE-2021-42849 A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to… A1 Firmware 5.3.6.t1 / 5.3.6.a1+ Fix from $1,6002022-05-18 HIGH 7.5 CVE-2022-28955EPSS 40% An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php. Dir 816l Firmware No fix yet Fix from $1,9502022-05-18 CRITICAL 9.8 CVE-2022-22796 Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, t… Sysaid 21.1.30 / 21.4.45+ Fix from $2,3002022-05-12 HIGH 7.2 CVE-2021-0193 Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escala… In Band Manageability 2.13.0+ Fix from $1,9502022-05-12 HIGH 7.2 CVE-2022-1681 Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions Wiki.js 2.5.281+ Fix from $1,9502022-05-12 CRITICAL 9.8 CVE-2019-12254 In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsibl… Smartbox 4 Lan Firmware Mitigation only Fix from $2,3002022-05-06 HIGH 8.1 CVE-2021-26253 A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions be… Splunk 8.1.6+ Fix from $1,9502022-05-06 HIGH 8.8 CVE-2022-21934 Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server … Metasys Application And Data Server 10.1.5 / 11.0.2+ Fix from $1,9502022-05-06 CRITICAL 9.8 CVE-2021-44056 An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attac… Video Station 5.1.8 / 5.3.13+ Fix from $2,3002022-05-05 CRITICAL 9.8 CVE-2021-44057 An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attac… Photo Station 5.4.13 / 5.7.16+ Fix from $2,3002022-05-05 HIGH 7.5 CVE-2022-24901 Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making th… Parse Server 4.10.10 / 5.2.1+ Fix from $1,9502022-05-04 HIGH 8.8 CVE-2022-0916 An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF at… Options 9.60.87+ Fix from $1,9502022-05-03 MEDIUM 6.5 CVE-2022-23722 When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS aut… Pingfederate 9.3.3 / 10.0.12+ Fix from $1,6002022-05-02 HIGH 7.7 CVE-2022-23723 An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication … Pingone Mfa Integration Kit Mitigation only Fix from $1,9502022-05-02 MEDIUM 5.6 CVE-2021-41992 A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass. Pingid Integration For Windows Login 2.7+ Fix from $1,6002022-04-30 HIGH 7.5 CVE-2022-24882 FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not prop… Fedora 2.7.0+ Fix from $1,9502022-04-26 CRITICAL 9.8 CVE-2022-24883 FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might … Fedora 2.7.0+ Fix from $2,3002022-04-26 HIGH 7.8 CVE-2021-36460 VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication w… Veryfitpro after 3.3.7 Fix from $1,9502022-04-25 HIGH 8.1 CVE-2021-45841EPSS 8% In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the us… Tos No fix yet Fix from $1,9502022-04-25 HIGH 7.5 CVE-2022-29534 An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: appli… Misp 2.4.158+ Fix from $1,9502022-04-20 CRITICAL 9.8 CVE-2022-0540EPSS 88% A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This a… Jira Data Center 4.13.8 / 4.13.18+ Fix from $2,3002022-04-20 HIGH 7.5 CVE-2021-26627 Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attac… Qcp200w Firmware Mitigation only Fix from $1,9502022-04-19