Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.0 CVE-2021-43414 An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middl… Hurd 0.9.20210404-9+ Fix from $1,9502021-11-07 CRITICAL 9.8 CVE-2021-42837 An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the nati… Data Catalog 7.3-20210930+ Fix from $2,3002021-11-05 HIGH 7.8 CVE-2021-25505 Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked. Samsung Pass 3.0.02.4+ Fix from $1,9502021-11-05 MEDIUM 5.5 CVE-2021-25506 Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service. Health 6.19.1.0001+ Fix from $1,6002021-11-05 HIGH 8.1 CVE-2021-38161 Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Ap… Traffic Server after 8.0.8 Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-41312 Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to e… Data Center 8.19.1+ Fix from $1,9502021-11-03 MEDIUM 5.3 CVE-2021-22490 There is a Permission verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect the device performance. Emui Mitigation only Fix from $1,6002021-10-28 HIGH 7.5 CVE-2021-22473 There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,9502021-10-28 MEDIUM 5.3 CVE-2021-32951 WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources… Webaccess\/nms after 3.0.3 Fix from $1,6002021-10-27 MEDIUM 5.3 CVE-2021-41157 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.10.6+ Fix from $1,6002021-10-26 HIGH 7.5 CVE-2021-37624 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.10.7+ Fix from $1,9502021-10-25 HIGH 7.5 CVE-2021-30302 Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, Snapdragon Conne… Aqt1000 Firmware Mitigation only Fix from $1,9502021-10-20 HIGH 7.5 CVE-2021-30312 Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdrago… Apq8053 Firmware Patch available Fix from $1,9502021-10-20 CRITICAL 9.8 CVE-2021-31349 The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change se… 128 Technology Session Smart Router Firmware 4.5.11+ Fix from $2,3002021-10-19 MEDIUM 5.5 CVE-2010-2496 stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwor… Cluster Glue 1.0.6 / 1.1.3+ Fix from $1,6002021-10-18 CRITICAL 9.8 CVE-2021-37123 There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain o… Hero Ct060 Firmware 1.0.0.200+ Fix from $2,3002021-10-11 HIGH 8.1 CVE-2021-41129 Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati… Panel 1.6.2+ Fix from $1,9502021-10-06 HIGH 7.2 CVE-2021-41126 October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts whi… October 2.1.12+ Fix from $1,9502021-10-06 MEDIUM 6.0 CVE-2021-25490 A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process. Android Mitigation only Fix from $1,6002021-10-06 HIGH 7.8 CVE-2021-0595 In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. Thi… Android Patch available Fix from $1,9502021-10-06 HIGH 7.3 CVE-2021-39226 KEVEPSS 100% Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit… Grafana 7.5.11 / 8.1.6+ Fix from $1,9502021-10-05 HIGH 7.8 CVE-2021-41286 Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the application, the validity of the p… Multicash Mitigation only Fix from $1,9502021-10-05 MEDIUM 6.5 CVE-2021-39872 In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLa… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-10-05 CRITICAL 9.8 CVE-2021-23857 Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combin… Rexroth Indramotion Mlc L20 Firmware after 12 Fix from $2,3002021-10-04 CRITICAL 9.8 CVE-2021-35296 An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie val… Hg150 Ub Firmware No fix yet Fix from $2,3002021-10-04 CRITICAL 9.8 CVE-2021-20578 IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m… Cloud Pak For Security Patch available Fix from $2,3002021-09-30 CRITICAL 9.1 CVE-2021-41292 ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass aut… Ecs Router Controller Ecs Firmware Mitigation only Fix from $2,3002021-09-30 CRITICAL 9.8 CVE-2021-35943 Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password,… Couchbase Server 6.6.3+ Fix from $2,3002021-09-29 HIGH 7.5 CVE-2021-31606 furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients. Openvpn Monitor after 1.1.3 Fix from $1,9502021-09-27 CRITICAL 9.8 CVE-2021-38299 Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable servic… Webauthn Framwork 3.2.9 / 3.3.4+ Fix from $2,3002021-09-27