Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Nex Forms HIGH 7.5
CVE-2021-34676

Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.

Fix: after 7.8.7
Fix from $1,950 2021-07-19
Orca Hcm CRITICAL 9.8
CVE-2021-35964

The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the ma…

Fix: after 10.0
Fix from $2,300 2021-07-19
Infosphere Data Replication CRITICAL 9.8
CVE-2020-4821

IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypa…

Patch available
Fix from $2,300 2021-07-16
Remotepc CRITICAL 9.8
CVE-2021-34690

iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to conne…

Fix: 7.6.48+
Fix from $2,300 2021-07-15
Cloud Foundation CRITICAL 9.8
CVE-2021-21994

SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on E…

Fix: 3.10.2 / 4.3+
Fix from $2,300 2021-07-13
G 50a Firmware HIGH 7.1
CVE-2021-20593

Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3…

Fix: after 7.09
Fix from $1,950 2021-07-13
Nextcloud Server CRITICAL 9.8
CVE-2021-32726

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted…

Fix: 19.0.13 / 20.0.11+
Fix from $2,300 2021-07-12
Halo MEDIUM 5.3
CVE-2020-19037

Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.

No fix yet
Fix from $1,600 2021-07-12
Fortinet Single Sign On CRITICAL 9.6
CVE-2021-26088

An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall poli…

Fix: 6.4.6 / 7.0.1+
Fix from $2,300 2021-07-12
Edgex Foundry MEDIUM 6.5
CVE-2021-32753

EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edi…

Fix: 2.0.0+
Fix from $1,600 2021-07-09
Knox Cloud Services HIGH 7.5
CVE-2021-25442

Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.

Fix: 1.39+
Fix from $1,950 2021-07-08
At 40cm01sr Firmware CRITICAL 9.8
CVE-2021-20776

Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary comman…

Mitigation only
Fix from $2,300 2021-07-07
Js Stellar Sdk MEDIUM 6.5
CVE-2021-32738

js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar W…

Fix: 8.2.3+
Fix from $1,600 2021-07-02
Usg1900 Firmware CRITICAL 9.8
CVE-2021-35029

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG …

Fix: after 4.64
Fix from $2,300 2021-07-02
Symantec Proxysg CRITICAL 9.8
CVE-2021-30648

The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthen…

Fix: 6.5.10.16 / 6.6.5.19+
Fix from $2,300 2021-06-30
Cryptctl CRITICAL 9.8
CVE-2019-18906

A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with acc…

Fix: 2.4+
Fix from $2,300 2021-06-30
Ie Wl Bl Ap Cl Eu Firmware HIGH 7.2
CVE-2021-33539

In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A s…

Fix: after 1.16.18
Fix from $1,950 2021-06-25
Backbox H4.09 Firmware HIGH 8.1
CVE-2021-33895

ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox U…

Mitigation only
Fix from $1,950 2021-06-25
Carbon Black App Control CRITICAL 9.8
CVE-2021-21998EPSS 11%

VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network acc…

Fix: 8.5.8 / 8.6.2+
Fix from $2,300 2021-06-23
Hospital Management System HIGH 7.5
CVE-2020-22176

PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated user…

No fix yet
Fix from $1,950 2021-06-22
Growi MEDIUM 6.5
CVE-2021-20737

Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privi…

Fix: 4.2.20+
Fix from $1,600 2021-06-22
Symfony HIGH 8.8
CVE-2021-32693

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication …

Fix: 5.3.2+
Fix from $1,950 2021-06-17
Data Connector Rock CRITICAL 9.8
CVE-2021-32691

Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able …

Fix: 2.20.0+
Fix from $2,300 2021-06-16
Sf220 24 Firmware MEDIUM 6.1
CVE-2021-1571EPSS 10%

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…

Fix: 1.2.0.6+
Fix from $1,600 2021-06-16
Sf220 24 Firmware HIGH 7.2
CVE-2021-1541EPSS 9%

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…

Fix: 1.2.0.6+
Fix from $1,950 2021-06-16
Sf220 24 Firmware HIGH 8.1
CVE-2021-1542

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…

Fix: 1.2.0.6+
Fix from $1,950 2021-06-16
Sf220 24 Firmware MEDIUM 6.1
CVE-2021-1543EPSS 9%

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…

Fix: 1.2.0.6+
Fix from $1,600 2021-06-16
Netweaver Abap CRITICAL 9.8
CVE-2021-27610

SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about…

Mitigation only
Fix from $2,300 2021-06-16
The Plus Addons For Elementor MEDIUM 5.3
CVE-2021-24359

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legi…

Fix: 4.1.11+
Fix from $1,600 2021-06-14
Powerlogic Pm5560 Firmware MEDIUM 5.3
CVE-2021-22764

A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see securit…

Fix: 2.7.8 / 10.7.3+
Fix from $1,600 2021-06-11