Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.5 CVE-2022-0996 A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. 389 Directory Server No fix yet Fix from $1,6002022-03-23 MEDIUM 5.3 CVE-2022-0862 A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow… Epolicy Orchestrator 5.10.0+ Fix from $1,6002022-03-23 HIGH 8.1 CVE-2021-44759 Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This… Traffic Server after 8.1.0 Fix from $1,9502022-03-23 MEDIUM 6.8 CVE-2021-46390 An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and cause a Denial of Service (Do… F35 Firmware No fix yet Fix from $1,6002022-03-21 CRITICAL 9.8 CVE-2022-0547 OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of def… Openvpn 2.4.12 / 2.5.6+ Fix from $2,3002022-03-18 HIGH 8.8 CVE-2022-26504 Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (… Veeam Backup \& Replication 10.0.1.4854 / 11.0.1.1261+ Fix from $1,9502022-03-17 CRITICAL 9.8 CVE-2021-45786 In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges. Maccms No fix yet Fix from $2,3002022-03-16 HIGH 7.5 CVE-2022-24740 Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-alpha.0, a user could have thei… Volto after 14.10.0 Fix from $1,9502022-03-14 HIGH 8.8 CVE-2022-22729 CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be by… Centum Cs 3000 Firmware Mitigation only Fix from $1,9502022-03-11 MEDIUM 5.5 CVE-2022-25825 Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in. Account 13.1.0.1+ Fix from $1,6002022-03-10 HIGH 7.8 CVE-2022-24286 Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process comm… Quickaccess 2.01.3030 / 3.00.3038+ Fix from $1,9502022-03-10 HIGH 7.8 CVE-2022-24285 Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process communicates with a service of syst… Care Center 4.00.3042+ Fix from $1,9502022-03-10 CRITICAL 9.1 CVE-2022-23383 YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessar… Yzmcms Mitigation only Fix from $2,3002022-03-10 HIGH 7.8 CVE-2021-40376 otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A re… Update Manager No fix yet Fix from $1,9502022-03-10 HIGH 7.5 CVE-2022-24748 Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possibl… Shopware 6.4.8.2+ Fix from $1,9502022-03-09 CRITICAL 9.1 CVE-2022-0715EPSS 6% A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leak… Smt Series 1015 Ups Firmware after 04.5 Fix from $2,3002022-03-09 HIGH 7.4 CVE-2022-24738 Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are able to drain unclaimed fund… Evmos 2.0.1+ Fix from $1,9502022-03-07 HIGH 7.8 CVE-2022-23729 When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010. Android 11.0+ Fix from $1,9502022-03-04 CRITICAL 9.8 CVE-2022-0730 Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. Debian Linux No fix yet Fix from $2,3002022-03-03 HIGH 7.8 CVE-2022-0492 KEVEPSS 6% A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circum… Linux Kernel 4.9.301 / 4.14.266+ Fix from $1,9502022-03-03 MEDIUM 5.3 CVE-2020-14504 The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can sen… 1734 Aentr Point I\/o Dual Port Network Adaptor Series B Firmware after 5.017 Fix from $1,6002022-02-24 HIGH 7.5 CVE-2022-23635 Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a re… Istio 1.11.7 / 1.12.4+ Fix from $1,9502022-02-22 HIGH 8.8 CVE-2022-23652 capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a prope… Capsule Proxy 0.2.1+ Fix from $1,9502022-02-22 MEDIUM 6.5 CVE-2022-23654 Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page o… Wiki.js 2.5.276+ Fix from $1,6002022-02-22 CRITICAL 9.8 CVE-2022-24047 This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not re… Track It\! Mitigation only Fix from $2,3002022-02-18 CRITICAL 9.8 CVE-2022-21196 MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does… Mimosa Management Platform 1.0.3 / 2.5.4.1+ Fix from $2,3002022-02-18 MEDIUM 5.9 CVE-2016-2124 A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the w… Debian Linux Patch available Fix from $1,6002022-02-18 HIGH 7.2 CVE-2020-25719 A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could b… Debian Linux Patch available Fix from $1,9502022-02-18 HIGH 7.5 CVE-2022-23317 CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by spec… Cobalt Strike 4.5+ Fix from $1,9502022-02-15 CRITICAL 9.8 CVE-2021-4201 Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s… Access Management Patch available Fix from $2,3002022-02-14