Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2021-45347 An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the coo… Zzcms No fix yet Fix from $1,9502022-02-14 CRITICAL 9.1 CVE-2022-24976 Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point… Atheme 7.2.12+ Fix from $2,3002022-02-14 HIGH 7.8 CVE-2021-22796 A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C… C Gate Server after 2.11.7 Fix from $1,9502022-02-11 CRITICAL 9.8 CVE-2021-38679 An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers… Kazoo Server 4.11.22+ Fix from $2,3002022-02-11 HIGH 7.8 CVE-2021-30317 Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdrag… Aqt1000 Firmware Mitigation only Fix from $1,9502022-02-11 CRITICAL 9.8 CVE-2021-45331 An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for… Gitea 1.5.0+ Fix from $2,3002022-02-09 HIGH 7.5 CVE-2022-23320 XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrat… Xmpie Ustore No fix yet Fix from $1,9502022-02-07 HIGH 8.8 CVE-2022-24551 A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could re… Nas 0.2+ Fix from $1,9502022-02-06 CRITICAL 9.8 CVE-2022-22831EPSS 11% An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header. Tessa No fix yet Fix from $2,3002022-02-06 MEDIUM 6.5 CVE-2022-23600 fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missi… Fleet 4.9.1+ Fix from $1,6002022-02-04 CRITICAL 9.8 CVE-2021-28503 The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, whi… Eos after 4.26.2 Fix from $2,3002022-02-04 CRITICAL 9.3 CVE-2021-21965 A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Speciall… Seaconnect 370w Firmware No fix yet Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2022-24259 An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted re… Voipmonitor 24.96+ Fix from $2,3002022-02-04 MEDIUM 6.5 CVE-2021-40404 An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted H… Rlc 410w Firmware No fix yet Fix from $1,6002022-01-28 MEDIUM 5.3 CVE-2021-36346 Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this… Integrated Dell Remote Access Controller 8 Firmware 2.82.82.82+ Fix from $1,6002022-01-25 HIGH 8.8 CVE-2021-34865 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication i… Ac2100 Firmware 1.0.1.80 / 1.1.0.84+ Fix from $1,9502022-01-25 CRITICAL 9.1 CVE-2021-3850 Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21. Debian Linux after 5.20.21 Fix from $2,3002022-01-25 CRITICAL 9.8 CVE-2021-43394 Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm.… Messaging Integration Services Mitigation only Fix from $2,3002022-01-24 CRITICAL 9.8 CVE-2022-23126 TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and in… Teslamate 1.25.1+ Fix from $2,3002022-01-24 CRITICAL 9.8 CVE-2021-43355 Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authenticat… Agilia Partner Maintenance Software 3.0+ Fix from $2,3002022-01-21 CRITICAL 9.8 CVE-2021-23196 The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does n… Agilia Connect Firmware 3.0+ Fix from $2,3002022-01-21 CRITICAL 9.8 CVE-2020-4879 IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth… Cognos Controller Mitigation only Fix from $2,3002022-01-21 CRITICAL 9.8 CVE-2021-44736 The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature. Mc3224i Firmware Mitigation only Fix from $2,3002022-01-20 MEDIUM 5.3 CVE-2022-21695 OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In … Onionshare 2.5+ Fix from $1,6002022-01-18 HIGH 8.8 CVE-2021-25036 The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the … All In One Seo 4.1.5.3+ Fix from $1,9502022-01-17 CRITICAL 9.8 CVE-2022-23178EPSS 76% An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthen… Hd Md4x2 4k E Firmware No fix yet Fix from $2,3002022-01-15 HIGH 8.8 CVE-2021-34977 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers.… R7000 Firmware Mitigation only Fix from $1,9502022-01-13 CRITICAL 9.8 CVE-2021-34993EPSS 5% This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not r… Commcell Mitigation only Fix from $2,3002022-01-13 HIGH 8.8 CVE-2022-21684 Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` all… Discourse 2.7.13+ Fix from $1,9502022-01-13 HIGH 8.8 CVE-2022-22990 A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on… My Cloud Os 5.19.117+ Fix from $1,9502022-01-13