Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Catalyst Sd Wan Manager CRITICAL 9.8
CVE-2021-1468

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 20.3.3 / 20.4.1+
Fix from $2,300 2021-05-06
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19111

Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication…

No fix yet
Fix from $2,300 2021-05-06
Wsr 2533dhpl2 Bk Firmware HIGH 7.5
CVE-2021-20092EPSS 8%

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sen…

Fix: after 1.24
Fix from $1,950 2021-04-29
Infinity CRITICAL 9.8
CVE-2021-27651EPSS 54%

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication chec…

Fix: after 8.5.2
Fix from $2,300 2021-04-29
Airwave HIGH 8.1
CVE-2021-25147

A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has …

Fix: 8.2.12.1+
Fix from $1,950 2021-04-28
Dominaplus CRITICAL 9.8
CVE-2020-21991

AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET para…

Fix: after 1.10.77
Fix from $2,300 2021-04-28
Tyk Identity Broker CRITICAL 9.1
CVE-2021-23365

The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause…

Fix: 1.1.1+
Fix from $2,300 2021-04-26
Connect Secure CRITICAL 10.0
CVE-2021-22893 KEVEPSS 47%

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul…

Mitigation only
Fix from $2,300 2021-04-23
Got2000 Gt27 Firmware HIGH 7.5
CVE-2021-20590

Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 series GT25 model VNC server vers…

Fix: after 01.40.000
Fix from $1,950 2021-04-22
Secvest Wireless Alarm System Fuaa50000 Firmware HIGH 7.5
CVE-2020-28973

The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can…

Mitigation only
Fix from $1,950 2021-04-21
Helpcom CRITICAL 9.8
CVE-2020-7856

A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient authen…

Fix: 11.2020+
Fix from $2,300 2021-04-20
Connect Express HIGH 7.7
CVE-2021-26073

Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for …

Fix: 6.6.0+
Fix from $1,950 2021-04-16
Connect Spring Boot MEDIUM 6.5
CVE-2021-26074

Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring…

Fix: 2.1.3+
Fix from $1,600 2021-04-16
Ceph Storage HIGH 7.2
CVE-2021-20288

An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitiz…

Fix: 14.2.21+
Fix from $1,950 2021-04-15
Appspace HIGH 7.5
CVE-2021-27990

Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is…

No fix yet
Fix from $1,950 2021-04-14
Ampache HIGH 7.5
CVE-2021-21399

Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the …

Fix: 4.4.1+
Fix from $1,950 2021-04-13
Netiq Advanced Authentication HIGH 7.2
CVE-2021-22497

Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.

Fix: 6.3+
Fix from $1,950 2021-04-12
Global Management System CRITICAL 9.8
CVE-2021-20020

A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.

Mitigation only
Fix from $2,300 2021-04-10
Experience Service HIGH 7.8
CVE-2021-25377

Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to …

Fix: after 10.8.0.4
Fix from $1,950 2021-04-09
Operations Bridge Manager CRITICAL 9.8
CVE-2021-22507

Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerabilit…

Mitigation only
Fix from $2,300 2021-04-08
Learnsite HIGH 8.8
CVE-2021-27522

Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the in…

No fix yet
Fix from $1,950 2021-04-08
Smart Stock Selection MEDIUM 6.5
CVE-2021-28174

Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in the URL, remote attackers can g…

Fix: after 2020-06-23
Fix from $1,600 2021-04-08
Rv160 Firmware CRITICAL 9.8
CVE-2021-1472EPSS 72%

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbit…

Fix: 1.0.01.03 / 1.0.03.21+
Fix from $2,300 2021-04-08
Debian Linux MEDIUM 5.3
CVE-2021-30158

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. Thi…

Fix: 1.31.12 / 1.35.2+
Fix from $1,600 2021-04-06
The Plus Addons For Elementor CRITICAL 9.8
CVE-2021-24175EPSS 14%

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication…

Fix: 4.1.7+
Fix from $2,300 2021-04-05
Smart Hd Wifi Security Camera Ean 2 950004 595317 Firmware HIGH 7.5
CVE-2019-20464

An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over …

No fix yet
Fix from $1,950 2021-04-02
Dma Radius Manager CRITICAL 9.8
CVE-2021-29012

DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is inva…

No fix yet
Fix from $2,300 2021-04-02
Devolutions Server HIGH 8.1
CVE-2021-23923

An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.

Fix: 2020.3+
Fix from $1,950 2021-04-01
Carbon Black Cloud Workload CRITICAL 9.1
CVE-2021-21982

VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network …

Fix: after 1.0.1
Fix from $2,300 2021-04-01
Instant MEDIUM 6.8
CVE-2019-5317

A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.…

Fix: 6.5.4.16 / 8.3.0.12+
Fix from $1,600 2021-03-29