Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Epikur CRITICAL 9.8
CVE-2020-10539

An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted …

Fix: 20.1.1+
Fix from $2,300 2021-02-05
Shiro CRITICAL 9.8
CVE-2020-17523EPSS 86%

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

Fix: 1.7.1+
Fix from $2,300 2021-02-03
Vault HIGH 7.5
CVE-2021-3282

HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication…

Mitigation only
Fix from $1,950 2021-02-01
Mofi4500 4gxelte Firmware CRITICAL 9.8
CVE-2020-15835

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the …

Patch available
Fix from $2,300 2021-02-01
Mofi4500 4gxelte Firmware CRITICAL 9.8
CVE-2020-13859

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - Ope…

Patch available
Fix from $2,300 2021-02-01
4cct Ea6 334126bf Firmware MEDIUM 6.5
CVE-2021-25910

Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in…

Mitigation only
Fix from $1,600 2021-01-29
Activemq HIGH 7.5
CVE-2021-26117EPSS 11%

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior…

Fix: 2.16.0 / 5.15.14+
Fix from $1,950 2021-01-27
Nbg2105 Firmware HIGH 7.8
CVE-2021-3297EPSS 21%

On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.

No fix yet
Fix from $1,950 2021-01-26
Open5gs HIGH 8.8
CVE-2021-25863

Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.

No fix yet
Fix from $1,950 2021-01-26
Projectsend HIGH 7.5
CVE-2020-28874

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not proper…

Patch available
Fix from $1,950 2021-01-26
Spectrum Lsf HIGH 7.8
CVE-2020-4983

IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitr…

Patch available
Fix from $1,950 2021-01-20
Anydana A Firmware MEDIUM 6.5
CVE-2020-27266

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and A…

Fix: 3.0+
Fix from $1,600 2021-01-19
Airwave Glass HIGH 7.5
CVE-2020-24641

In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully ex…

Fix: 1.3.3+
Fix from $1,950 2021-01-15
GitLab MEDIUM 6.5
CVE-2021-22171

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click …

Fix: 13.5.6 / 13.6.4+
Fix from $1,600 2021-01-15
Miniserver Gen 1 Firmware CRITICAL 9.8
CVE-2020-27488

Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the …

Fix: 11.1.9.3+
Fix from $2,300 2021-01-13
Univerge Sv9500 Firmware HIGH 7.5
CVE-2020-5686

Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker …

Mitigation only
Fix from $1,950 2021-01-13
Baseboard Management Controller CRITICAL 9.8
CVE-2020-5633

Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Expr…

Fix: after 1.09
Fix from $2,300 2021-01-13
Bot Framework Software Development Kit MEDIUM 5.5
CVE-2021-1725

Bot Framework SDK Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2021-01-12
Ithemes Security HIGH 7.5
CVE-2020-36176

The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing acco…

Fix: 7.7.0+
Fix from $1,950 2021-01-06
Limit Login Attempts CRITICAL 9.8
CVE-2012-10001

The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attacker…

Fix: 1.7.1+
Fix from $2,300 2021-01-06
Dsl N17u Firmware CRITICAL 9.8
CVE-2020-35219

The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication vi…

Mitigation only
Fix from $2,300 2021-01-04
Msr45 Isherlock Antispam CRITICAL 9.8
CVE-2020-25848

HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

Fix: 4.5-114 / 4.5-122+
Fix from $2,300 2020-12-31
Dgn2200 Firmware HIGH 8.8
CVE-2020-35785

NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-2020-0365).

Fix: 1.0.0.60+
Fix from $1,950 2020-12-30
Cloudengine 12800 Firmware HIGH 7.8
CVE-2020-9207

There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. A…

No fix yet
Fix from $1,950 2020-12-29
Zammad CRITICAL 9.8
CVE-2020-26030

An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configure…

Fix: 3.4.1+
Fix from $2,300 2020-12-28
Symphony \+ Historian CRITICAL 9.8
CVE-2020-24675

In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ H…

Mitigation only
Fix from $2,300 2020-12-22
Dsl2888a Firmware HIGH 8.8
CVE-2020-24579EPSS 10%

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authenticati…

No fix yet
Fix from $1,950 2020-12-22
X Stream Enhanced Xegp Firmware HIGH 7.5
CVE-2020-27254

Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper aut…

Mitigation only
Fix from $1,950 2020-12-21
Linux Pam CRITICAL 9.8
CVE-2020-27780

A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM…

Fix: 1.5.1+
Fix from $2,300 2020-12-18
Interscan Web Security Virtual Appliance CRITICAL 9.8
CVE-2020-8465

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combinat…

No fix yet
Fix from $2,300 2020-12-17