Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2021-33046 Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deploy… Ipc Hx1xxx Firmware after 2021-7 Fix from $2,3002022-01-13 MEDIUM 5.3 CVE-2022-23134 KEVEPSS 85% After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. M… Fedora after 5.4.8 Fix from $1,6002022-01-13 HIGH 8.8 CVE-2021-43999 Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo… Guacamole Mitigation only Fix from $1,9502022-01-11 CRITICAL 9.6 CVE-2021-44458 Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connectio… Lens after 5.2.6 Fix from $2,3002022-01-10 MEDIUM 5.3 CVE-2022-22289 Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information. S Assistant 7.5+ Fix from $1,6002022-01-10 MEDIUM 5.5 CVE-2022-22284 Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication Internet 16.0.2.19+ Fix from $1,6002022-01-10 CRITICAL 9.8 CVE-2021-45389 A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus co… Command Center Mitigation only Fix from $2,3002022-01-04 CRITICAL 9.0 CVE-2021-45917 The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated attacker of an agent computer… Network Computer Terminal Protection System Firmware 7.20.0401+ Fix from $2,3002022-01-03 MEDIUM 6.8 CVE-2021-20161 Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to… Tew 827dru Firmware Mitigation only Fix from $1,6002021-12-30 MEDIUM 6.8 CVE-2021-20168 Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is ab… Rax43 Firmware Mitigation only Fix from $1,6002021-12-30 MEDIUM 6.8 CVE-2021-23147 Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the de… R6700 Firmware Mitigation only Fix from $1,6002021-12-30 HIGH 8.8 CVE-2021-45379 Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its p… Glewlwyd 2.6.1+ Fix from $1,9502021-12-30 HIGH 7.5 CVE-2021-38688 An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromi… Qfile 3.0.0.1105+ Fix from $1,9502021-12-29 CRITICAL 9.8 CVE-2021-45890 basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier. Authguard 0.9.0+ Fix from $2,3002021-12-27 CRITICAL 9.8 CVE-2021-21952 An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase … Eufy Homebase 2 Firmware No fix yet Fix from $2,3002021-12-22 HIGH 8.1 CVE-2021-21902 An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A proper… Ic Module Cma No fix yet Fix from $1,9502021-12-22 CRITICAL 9.8 CVE-2021-27451 Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to t… Amegaview after 3.0 Fix from $2,3002021-12-21 HIGH 7.5 CVE-2021-36350 Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors. A remote un… Powerscale Onefs 9.3.1.0+ Fix from $1,9502021-12-21 CRITICAL 9.8 CVE-2021-44525 Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti… Manageengine Pam360 Mitigation only Fix from $2,3002021-12-20 CRITICAL 9.8 CVE-2021-44675EPSS 6% Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which… Manageengine Servicedesk Plus Msp after 10.5 Fix from $2,3002021-12-20 CRITICAL 9.8 CVE-2021-44676 Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects o… Manageengine Access Manager Plus Mitigation only Fix from $2,3002021-12-20 HIGH 7.5 CVE-2021-40851 TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulner… Gim Mitigation only Fix from $1,9502021-12-17 HIGH 8.8 CVE-2021-43833 eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated … Elabftw 4.2.0+ Fix from $1,9502021-12-16 CRITICAL 9.8 CVE-2021-43834 eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to aut… Elabftw 4.2.0+ Fix from $2,3002021-12-16 CRITICAL 9.8 CVE-2021-43935 The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the applicatio… Welch Allyn Connex Cardio after 7.0.0 Fix from $2,3002021-12-15 HIGH 8.1 CVE-2021-4073EPSS 7% The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew … Registrationmagic after 5.0.1.7 Fix from $1,9502021-12-14 MEDIUM 5.3 CVE-2021-44937 glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox … Glfusion No fix yet Fix from $1,6002021-12-14 CRITICAL 9.8 CVE-2021-44524 A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All v… Sipass Integrated after 1.6.284.0 Fix from $2,3002021-12-14 HIGH 7.5 CVE-2021-39064 IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the S… Spectrum Copy Data Management after 2.2.13 Fix from $1,9502021-12-13 CRITICAL 9.8 CVE-2021-44514EPSS 5% OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories. Manageengine Opmanager Mitigation only Fix from $2,3002021-12-09