Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.8 CVE-2021-41265 Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the RES… Flask Appbuilder 3.3.4+ Fix from $1,9502021-12-09 HIGH 7.5 CVE-2021-20145 Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which e… Gryphon Tower Firmware after 04.0004.12 Fix from $1,9502021-12-09 HIGH 7.5 CVE-2021-21955 An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1… Eufy Homebase 2 Firmware No fix yet Fix from $1,9502021-12-09 HIGH 8.1 CVE-2021-43068 A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login p… Fortiauthenticator Patch available Fix from $1,9502021-12-09 MEDIUM 6.5 CVE-2021-36718 SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sens… Eharmonynew 11.0+ Fix from $1,6002021-12-08 HIGH 7.5 CVE-2021-37054 There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect s… Harmonyos 2.0+ Fix from $1,9502021-12-08 MEDIUM 5.3 CVE-2021-41309 Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs… Jira Software Data Center 8.19.1+ Fix from $1,6002021-12-08 HIGH 7.5 CVE-2021-41311 Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to… Jira Software Data Center 8.19.1+ Fix from $1,9502021-12-08 CRITICAL 9.8 CVE-2021-41716 Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulner… Mahavitaran after 7.50 Fix from $2,3002021-12-07 HIGH 7.5 CVE-2021-43175 The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes… Goautodial No fix yet Fix from $1,9502021-12-07 HIGH 7.5 CVE-2021-37100 There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authenticatio… Harmonyos 2.0+ Fix from $1,9502021-12-07 HIGH 7.5 CVE-2021-37043 There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious applica… Emui 2.0+ Fix from $1,9502021-12-07 CRITICAL 9.8 CVE-2021-39890 It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above. GitLab 14.1.7 / 14.2.5+ Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-43931 The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that i… Webhmi Firmware 4.1+ Fix from $2,3002021-12-06 HIGH 7.5 CVE-2021-43786 Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally al… Nodebb after 1.18.4 Fix from $1,9502021-11-29 HIGH 8.8 CVE-2021-38686 An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows attackers to compr… Qvr 5.1.6+ Fix from $1,9502021-11-26 HIGH 7.8 CVE-2021-35033 A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could… Nbg6818 Firmware 1.00 / 2.20+ Fix from $1,9502021-11-23 MEDIUM 5.3 CVE-2021-38376 OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call. Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 CRITICAL 9.8 CVE-2021-36306 Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerability. A remote unauthenticated … Networking Os10 10.4.3.8 / 10.5.0.10+ Fix from $2,3002021-11-20 CRITICAL 9.8 CVE-2021-36308 Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vulnerability. A remote unauthe… Networking Os10 10.4.3.8 / 10.5.0.10+ Fix from $2,3002021-11-20 CRITICAL 9.8 CVE-2021-42338EPSS 6% 4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code in… Gcb Doctor after 20210708 Fix from $2,3002021-11-19 HIGH 7.8 CVE-2021-0096 Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN, NUC7i7DN before version 1.78… Nuc7i3dn Firmware 1.78.1.1+ Fix from $1,9502021-11-17 MEDIUM 5.5 CVE-2021-33087 Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an a… Nuc M15 Laptop Kit Management Engine Driver Pack 15.0.10.1508+ Fix from $1,6002021-11-17 CRITICAL 9.8 CVE-2021-37580EPSS 40% A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff… Shenyu Mitigation only Fix from $2,3002021-11-16 MEDIUM 6.8 CVE-2021-3788 An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthoriz… Halo\+ Camera Firmware 03.40.00 / 03.40.02+ Fix from $1,6002021-11-12 MEDIUM 6.8 CVE-2021-3519 A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Dev… Ideacentre C5 14mb05 Firmware Mitigation only Fix from $1,6002021-11-12 HIGH 7.5 CVE-2021-43203 In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly. Ktor 1.6.4+ Fix from $1,9502021-11-09 HIGH 8.1 CVE-2021-24647EPSS 10% The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a… Pie Register 3.7.1.6+ Fix from $1,9502021-11-08 HIGH 7.5 CVE-2021-31602EPSS 52% An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different… Vantara Pentaho after 9.1.0.0 Fix from $1,9502021-11-08 HIGH 8.8 CVE-2021-42072 An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify … Fedora 2.4.0+ Fix from $1,9502021-11-08