Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.0 CVE-2021-41503 DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command int… Dcs 932l Firmware after 2.17 Fix from $1,9502021-09-24 CRITICAL 9.8 CVE-2021-22869 An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not ha… Enterprise Server 3.0.16 / 3.1.8+ Fix from $2,3002021-09-24 CRITICAL 9.8 CVE-2021-31917 A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat… Data Grid 11.0.12 / 12.1.4+ Fix from $2,3002021-09-21 CRITICAL 9.8 CVE-2021-38412 Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require auth… Portserver Ts 16 Firmware Mitigation only Fix from $2,3002021-09-17 CRITICAL 9.8 CVE-2021-41317 XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths. Xss Hunter Express 2021-09-17+ Fix from $2,3002021-09-17 CRITICAL 9.8 CVE-2021-41303EPSS 77% Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul… Shiro 1.8.0+ Fix from $2,3002021-09-17 CRITICAL 9.8 CVE-2021-33044 KEVEPSS 100% The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authenti… Ipc Hum7xxx Firmware 2.800.0000000.29.r.210630 / 2.812.0000007.0.r.210706+ Fix from $2,3002021-09-15 CRITICAL 9.8 CVE-2021-33045 KEVEPSS 100% The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authenti… Ipc Hum7xxx Firmware 2.800.0000000.29.r.210630 / 2.820.0000000.5.r.210705+ Fix from $2,3002021-09-15 HIGH 7.8 CVE-2021-33700 SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim wit… Business One Patch available Fix from $1,9502021-09-15 HIGH 7.5 CVE-2021-39215 Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms… Jitsi Meet Patch available Fix from $1,9502021-09-15 MEDIUM 6.7 CVE-2021-3145 In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication. Identity Vault 5.0+ Fix from $1,6002021-09-10 HIGH 7.5 CVE-2021-37414EPSS 5% Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication. Manageengine Desktop Central 10.0.709+ Fix from $1,9502021-09-10 MEDIUM 5.9 CVE-2021-25466 Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Sa… Internet 15.0.2.47+ Fix from $1,6002021-09-09 CRITICAL 10.0 CVE-2021-39296 In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. Openbmc Mitigation only Fix from $2,3002021-09-09 HIGH 8.8 CVE-2021-28494 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypasse… Metamako Operating System after 0.34.0 Fix from $1,9502021-09-09 CRITICAL 9.8 CVE-2021-28495 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can b… Metamako Operating System 0.32.0+ Fix from $2,3002021-09-09 HIGH 7.8 CVE-2021-28493 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to exe… Metamako Operating System after 0.32.0 Fix from $1,9502021-09-09 HIGH 7.2 CVE-2021-34785 Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user ac… Broadworks Commpilot Application Software 22.0.2021.09 / 23.0.2021.09+ Fix from $1,9502021-09-09 HIGH 7.8 CVE-2021-30605 Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing … Chrome Os Readiness Tool 1.0.2.0+ Fix from $1,9502021-09-08 MEDIUM 5.4 CVE-2021-30667 A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in WiFi range may be able to force… Ipados 14.6+ Fix from $1,6002021-09-08 MEDIUM 5.5 CVE-2021-30769 A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitr… Iphone Os 7.6 / 14.7+ Fix from $1,6002021-09-08 MEDIUM 5.5 CVE-2021-30770 A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved … Iphone Os 7.6 / 14.7+ Fix from $1,6002021-09-08 MEDIUM 5.4 CVE-2021-30720 A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4… Safari 7.5 / 11.4+ Fix from $1,6002021-09-08 CRITICAL 9.8 CVE-2020-11264EPSS 13% Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Aut… Apq8053 Firmware Patch available Fix from $2,3002021-09-08 HIGH 7.5 CVE-2020-11301EPSS 11% Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdra… Apq8009 Firmware Patch available Fix from $1,9502021-09-08 MEDIUM 6.5 CVE-2021-39196 pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to u… Pcapture 3.12+ Fix from $1,6002021-09-07 CRITICAL 9.8 CVE-2021-34746EPSS 18% A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) cou… Enterprise Nfv Infrastructure Software 4.6.1+ Fix from $2,3002021-09-02 CRITICAL 9.8 CVE-2021-40350 webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafted query containing an unspeci… Dwu850 Gs Firmware No fix yet Fix from $2,3002021-09-01 CRITICAL 9.8 CVE-2021-22002 VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a … Identity Manager Patch available Fix from $2,3002021-08-31 CRITICAL 9.6 CVE-2021-22943 A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subseq… Unifi Protect 1.19.0+ Fix from $2,3002021-08-31