Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2022-0996
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
389 Directory Server
No fix yet
MEDIUM 5.3
CVE-2022-0862
A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow…
Epolicy Orchestrator
5.10.0+
HIGH 8.1
CVE-2021-44759
Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This…
Traffic Server
after 8.1.0
MEDIUM 6.8
CVE-2021-46390
An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and cause a Denial of Service (Do…
F35 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-0547
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of def…
Openvpn
2.4.12 / 2.5.6+
HIGH 8.8
CVE-2022-26504
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (…
Veeam Backup \& Replication
10.0.1.4854 / 11.0.1.1261+
CRITICAL 9.8
CVE-2021-45786
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
Maccms
No fix yet
HIGH 7.5
CVE-2022-24740
Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-alpha.0, a user could have thei…
Volto
after 14.10.0
HIGH 8.8
CVE-2022-22729
CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be by…
Centum Cs 3000 Firmware
Mitigation only
MEDIUM 5.5
CVE-2022-25825
Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.
Account
13.1.0.1+
HIGH 7.8
CVE-2022-24286
Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process comm…
Quickaccess
2.01.3030 / 3.00.3038+
HIGH 7.8
CVE-2022-24285
Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process communicates with a service of syst…
Care Center
4.00.3042+
CRITICAL 9.1
CVE-2022-23383
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessar…
Yzmcms
Mitigation only
HIGH 7.8
CVE-2021-40376
otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A re…
Update Manager
No fix yet
HIGH 7.5
CVE-2022-24748
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possibl…
Shopware
6.4.8.2+
CRITICAL 9.1
CVE-2022-0715EPSS 6%
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leak…
Smt Series 1015 Ups Firmware
after 04.5
HIGH 7.4
CVE-2022-24738
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are able to drain unclaimed fund…
Evmos
2.0.1+
HIGH 7.8
CVE-2022-23729
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.
Android
11.0+
CRITICAL 9.8
CVE-2022-0730
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
Debian Linux
No fix yet
HIGH 7.8
CVE-2022-0492 KEVEPSS 6%
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circum…
Linux Kernel
4.9.301 / 4.14.266+
MEDIUM 5.3
CVE-2020-14504
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can sen…
1734 Aentr Point I\/o Dual Port Network Adaptor Series B Firmware
after 5.017
HIGH 7.5
CVE-2022-23635
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a re…
Istio
1.11.7 / 1.12.4+
HIGH 8.8
CVE-2022-23652
capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a prope…
Capsule Proxy
0.2.1+
MEDIUM 6.5
CVE-2022-23654
Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page o…
Wiki.js
2.5.276+
CRITICAL 9.8
CVE-2022-24047
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not re…
Track It\!
Mitigation only
CRITICAL 9.8
CVE-2022-21196
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does…
Mimosa Management Platform
1.0.3 / 2.5.4.1+
MEDIUM 5.9
CVE-2016-2124
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the w…
Debian Linux
Patch available
HIGH 7.2
CVE-2020-25719
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could b…
Debian Linux
Patch available
HIGH 7.5
CVE-2022-23317
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by spec…
Cobalt Strike
4.5+
CRITICAL 9.8
CVE-2021-4201
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s…
Access Management
Patch available