Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Galaxy Watch Active 2 Firmware HIGH 8.8
CVE-2021-25424

Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the us…

Fix: 5.5+
Fix from $1,950 2021-06-11
Android MEDIUM 6.1
CVE-2021-25389

Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.

Mitigation only
Fix from $1,600 2021-06-11
Netsetman MEDIUM 6.8
CVE-2021-34546

An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button …

Fix: 5.0+
Fix from $1,600 2021-06-10
Realsense Id F450 Firmware MEDIUM 6.8
CVE-2020-24514

Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physic…

Mitigation only
Fix from $1,600 2021-06-09
Cpp6 Firmware CRITICAL 9.1
CVE-2021-23847

A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or chang…

Fix: 7.80.0129+
Fix from $2,300 2021-06-09
Silverstripe MEDIUM 6.5
CVE-2020-26136

In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.

Fix: 4.6.0+
Fix from $1,600 2021-06-08
Bf 430 Firmware CRITICAL 9.8
CVE-2021-31251EPSS 36%

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining …

No fix yet
Fix from $2,300 2021-06-04
Openvpn Access Server MEDIUM 5.3
CVE-2020-15077

OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers config…

Fix: after 2.8.7
Fix from $1,600 2021-06-04
Satellite HIGH 7.5
CVE-2020-14380

An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authen…

Mitigation only
Fix from $1,950 2021-06-02
Single Sign On MEDIUM 5.3
CVE-2021-3424

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself…

Mitigation only
Fix from $1,600 2021-06-01
Dav Cogs HIGH 7.3
CVE-2021-32646

Roomer is a discord bot cog (extension) which provides automatic voice channel generation as well as private voice and text channels. A vulnerability…

Fix: 1.0.1+
Fix from $1,950 2021-05-28
Authelia CRITICAL 10.0
CVE-2021-32637

Authelia is a a single sign-on multi-factor portal for web apps. This affects uses who are using nginx ngx_http_auth_request_module with Authelia, it…

Fix: 4.25.1 / 4.29.3+
Fix from $2,300 2021-05-28
Kiali MEDIUM 6.5
CVE-2021-20278

An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is e…

Fix: 1.31.0+
Fix from $1,600 2021-05-28
Cts Web MEDIUM 5.3
CVE-2021-32541

The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows remote unauthenticated attac…

Fix: 2021.3.24+
Fix from $1,600 2021-05-28
Cts Web MEDIUM 5.4
CVE-2021-32543

The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies …

Fix: 2021.3.24+
Fix from $1,600 2021-05-28
Ansible Tower HIGH 7.1
CVE-2020-10709

A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authen…

Fix: 3.5.6 / 3.6.4+
Fix from $1,950 2021-05-27
Versa Director MEDIUM 5.3
CVE-2018-16496

In Versa Director, the un-authentication request found.

Mitigation only
Fix from $1,600 2021-05-26
Fedora MEDIUM 6.8
CVE-2021-31924

Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass…

Fix: 1.1.1+
Fix from $1,600 2021-05-26
Mesh Profile HIGH 7.5
CVE-2020-26557

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisionin…

Mitigation only
Fix from $1,950 2021-05-24
Linux Kernel HIGH 7.5
CVE-2002-2438

TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linu…

Fix: 2.4.20+
Fix from $1,950 2021-05-18
Hirschmann Hios CRITICAL 9.8
CVE-2021-27734

Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of…

Fix: 08.6.00+
Fix from $2,300 2021-05-17
Dxp HIGH 7.5
CVE-2021-29047

The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is…

Fix: 7.3+
Fix from $1,950 2021-05-16
Workspaces Server HIGH 8.8
CVE-2021-22155

An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10…

Fix: after 9.1
Fix from $1,950 2021-05-13
Debian Linux MEDIUM 5.3
CVE-2020-26139EPSS 6%

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet s…

Patch available
Fix from $1,600 2021-05-11
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2021-23008

On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM…

Fix: 11.6.5 / 12.1.5+
Fix from $2,300 2021-05-10
Im Security HIGH 8.1
CVE-2021-31520

A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently l…

Patch available
Fix from $1,950 2021-05-10
Connect Spring Boot HIGH 8.8
CVE-2021-26077

Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Sp…

Fix: 2.1.3 / 2.1.5+
Fix from $1,950 2021-05-10
H8922 Firmware CRITICAL 9.8
CVE-2021-28152EPSS 5%

Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on por…

No fix yet
Fix from $2,300 2021-05-06
Lyra Mini Firmware CRITICAL 9.8
CVE-2021-32030 KEVEPSS 99%

The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass …

Fix: 3.0.0.4.384.46630 / 3.0.0.4.386.42643+
Fix from $2,300 2021-05-06
Openmptcprouter MEDIUM 5.9
CVE-2021-31245

omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent man…

Fix: after 0.57.3
Fix from $1,600 2021-05-06