Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Kongchuanhujiao CRITICAL 9.8
CVE-2021-21403

In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacte…

Fix: 1.3.21+
Fix from $2,300 2021-03-26
Terraform Enterprise MEDIUM 6.5
CVE-2021-3153

HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two…

Fix: after 202102-2
Fix from $1,600 2021-03-26
Cloud HIGH 7.5
CVE-2021-25368

Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.

Fix: 4.7.0.3+
Fix from $1,950 2021-03-25
Access Manager HIGH 7.5
CVE-2021-22496

Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could caus…

Fix: 4.5.3.3+
Fix from $1,950 2021-03-25
Data Center HIGH 7.2
CVE-2021-26070

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via…

Fix: 8.13.3 / 8.14.1+
Fix from $1,950 2021-03-22
Mstore Api CRITICAL 9.8
CVE-2021-24148

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unaut…

Fix: 3.2.0+
Fix from $2,300 2021-03-18
E Document System CRITICAL 9.8
CVE-2021-22860

EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote atta…

Mitigation only
Fix from $2,300 2021-03-17
Envoy HIGH 8.2
CVE-2021-21378

Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT…

Patch available
Fix from $1,950 2021-03-11
Gs116e Firmware HIGH 8.8
CVE-2020-35231

The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to by…

Mitigation only
Fix from $1,950 2021-03-10
Keycloak MEDIUM 6.5
CVE-2020-27838EPSS 18%

A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like cli…

Fix: 13.0.0+
Fix from $1,600 2021-03-08
Spnego Http Authentication Module CRITICAL 9.8
CVE-2021-21335

In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a …

Fix: 1.1.1+
Fix from $2,300 2021-03-08
Ratcf CRITICAL 9.8
CVE-2021-21329

RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF users with multi factor authentic…

Fix: 2021-02-26+
Fix from $2,300 2021-03-08
Manageengine Desktop Central CRITICAL 9.1
CVE-2020-28050

Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.

Fix: 10.0.647+
Fix from $2,300 2021-03-05
Directory Services Connector HIGH 8.2
CVE-2020-5148

SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential atta…

Fix: 4.1.19+
Fix from $1,950 2021-03-05
Android MEDIUM 5.3
CVE-2021-25347

Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is execu…

No fix yet
Fix from $1,600 2021-03-04
Salt HIGH 7.8
CVE-2021-25315

CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute a…

Fix: 3002.2+
Fix from $1,950 2021-03-03
Openmanage Server Administrator CRITICAL 9.8
CVE-2021-21513EPSS 6%

Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration c…

Fix: 9.4.0.3 / 9.5.0.1+
Fix from $2,300 2021-03-02
Wps Hide Login MEDIUM 5.3
CVE-2021-3332

WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.

No fix yet
Fix from $1,600 2021-03-01
Fedora CRITICAL 9.8
CVE-2021-25281EPSS 73%

An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attac…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Prestashop CRITICAL 9.1
CVE-2021-21308

PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an atta…

Fix: 1.7.7.2+
Fix from $2,300 2021-02-26
Endpoint Security MEDIUM 6.8
CVE-2020-26200

A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component…

Fix: 18.0.11.3+
Fix from $1,600 2021-02-26
Owncloud MEDIUM 5.9
CVE-2020-10254

An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.

Fix: 10.4.0+
Fix from $1,600 2021-02-19
Changjia Property Management System HIGH 8.8
CVE-2021-22858

Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obt…

Mitigation only
Fix from $1,950 2021-02-17
Dva 2800 Firmware MEDIUM 6.5
CVE-2020-27863

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-2888A rou…

Mitigation only
Fix from $1,600 2021-02-12
Dap 1860 Firmware HIGH 8.8
CVE-2020-27865

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 …

Fix: after 1.04b03
Fix from $1,950 2021-02-12
Ac2100 Firmware HIGH 8.8
CVE-2020-27866EPSS 9%

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260,…

Fix: 1.2.0.76+
Fix from $1,950 2021-02-12
Cloud Access Connector MEDIUM 6.5
CVE-2020-13185

Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to sp…

Fix: 18+
Fix from $1,600 2021-02-11
Emc Powerscale Onefs CRITICAL 9.8
CVE-2021-21502

Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRI…

Mitigation only
Fix from $2,300 2021-02-09
Simatic Pcs 7 MEDIUM 5.5
CVE-2020-10048

A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verificatio…

Fix: 7.5+
Fix from $1,600 2021-02-09
Scim Bridge MEDIUM 6.5
CVE-2021-26905

1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key.

Fix: 1.6.2+
Fix from $1,600 2021-02-08