Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
750 890\/040 000 Firmware HIGH 8.1
CVE-2021-34578

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically construct…

Mitigation only
Fix from $1,950 2021-08-31
Geyser CRITICAL 9.8
CVE-2021-39177

Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNAPSHOT allow anyone that can c…

Fix: 1.4.2+
Fix from $2,300 2021-08-30
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-37417

Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.

Fix: 6.1+
Fix from $2,300 2021-08-30
Midnight Commander HIGH 7.5
CVE-2021-36370

An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked …

Fix: after 4.8.26
Fix from $1,950 2021-08-30
Diaenergie CRITICAL 9.8
CVE-2021-32967

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized…

Fix: after 1.7.5
Fix from $2,300 2021-08-30
Cloud Foundation HIGH 7.5
CVE-2021-22025

The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unaut…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Cachet MEDIUM 6.5
CVE-2021-39165EPSS 10%

Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearc…

Fix: 2.3.18+
Fix from $1,600 2021-08-26
October HIGH 7.4
CVE-2021-29487

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vuln…

Fix: 1.0.472 / 1.1.5+
Fix from $1,950 2021-08-26
October CRITICAL 9.1
CVE-2021-32648 KEVEPSS 90%

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an accoun…

Fix: 1.1.5+
Fix from $2,300 2021-08-26
Ipados MEDIUM 5.5
CVE-2021-30867

The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access phot…

Fix: 12.0.1 / 15.0+
Fix from $1,600 2021-08-24
Wp Cerber CRITICAL 9.8
CVE-2021-37597

WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.

Fix: 8.9.3+
Fix from $2,300 2021-08-19
Parse Server MEDIUM 6.5
CVE-2021-39138

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup use…

Fix: 4.5.1+
Fix from $1,600 2021-08-19
Secure Email And Web Manager MEDIUM 5.4
CVE-2021-1561

A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow…

Fix: after 14.1
Fix from $1,600 2021-08-18
Profile Builder CRITICAL 9.8
CVE-2021-24527EPSS 8%

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin o…

Fix: 3.4.9+
Fix from $2,300 2021-08-16
Azure Active Directory Connect HIGH 7.1
CVE-2021-36949

Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability

Fix: 1.1.582.0+
Fix from $1,950 2021-08-12
Application Insight Manager HIGH 8.8
CVE-2021-36921

AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An a…

Mitigation only
Fix from $1,950 2021-08-12
Fabric Operating System HIGH 7.8
CVE-2021-27794

A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a us…

Fix: 7.4.2h / 8.2.3a+
Fix from $1,950 2021-08-12
Pan Os MEDIUM 6.5
CVE-2021-3046

An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any o…

Fix: 8.1.19 / 9.0.14+
Fix from $1,600 2021-08-11
Simatic S7 1200 Cpu Firmware HIGH 7.5
CVE-2021-37172

A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against con…

Fix: after 13.0
Fix from $1,950 2021-08-10
Openmanage Enterprise CRITICAL 9.8
CVE-2021-21564

Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentiall…

Fix: 3.6.1+
Fix from $2,300 2021-08-09
Businessobjects Edge CRITICAL 9.8
CVE-2014-9320

SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privilege…

Patch available
Fix from $2,300 2021-08-09
R08sfcpu Firmware MEDIUM 5.3
CVE-2021-20598

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R0…

Mitigation only
Fix from $1,600 2021-08-06
Teamcity HIGH 7.5
CVE-2021-37545

In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.

Fix: 2021.1+
Fix from $1,950 2021-08-06
True Image HIGH 7.8
CVE-2021-32579

Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (wh…

Mitigation only
Fix from $1,950 2021-08-05
Internet MEDIUM 5.3
CVE-2021-25445

Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Intern…

Fix: 14.2+
Fix from $1,600 2021-08-05
Dm Nvx Dir 80 Firmware HIGH 7.5
CVE-2020-16839

On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthentic…

Mitigation only
Fix from $1,950 2021-07-30
Idrac9 Firmware CRITICAL 10.0
CVE-2021-21538

Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated at…

Fix: 4.40.10.00+
Fix from $2,300 2021-07-29
Archisteamfarm HIGH 7.5
CVE-2021-32794

ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /…

Fix: 5.1.2.4+
Fix from $1,950 2021-07-26
Cx2 Firmware MEDIUM 5.3
CVE-2020-21932

A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially auth…

No fix yet
Fix from $1,600 2021-07-21
Nex Forms HIGH 7.5
CVE-2021-34675

Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.

Fix: after 7.8.7
Fix from $1,950 2021-07-19