Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Interscan Web Security Virtual Appliance CRITICAL 9.8
CVE-2020-8465

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combinat…

No fix yet
Fix from $2,300 2020-12-17
Magic Home Pro HIGH 7.5
CVE-2020-27199

The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a …

No fix yet
Fix from $1,950 2020-12-17
Connect\ CRITICAL 9.8
CVE-2020-4747

IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper au…

Mitigation only
Fix from $2,300 2020-12-15
Android HIGH 7.5
CVE-2020-0460

In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This cou…

Patch available
Fix from $1,950 2020-12-14
Command Centre HIGH 8.2
CVE-2020-16102

Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid confi…

Fix: 7.90.0 / 8.00.1252+
Fix from $1,950 2020-12-14
Mycarelink Smart Model 25000 Firmware HIGH 8.8
CVE-2020-25183

Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Pati…

Mitigation only
Fix from $1,950 2020-12-14
Wifisd2 2a82 Firmware HIGH 8.8
CVE-2020-29669

In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability whi…

No fix yet
Fix from $1,950 2020-12-14
Lastpass MEDIUM 5.7
CVE-2020-35207

An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The PIN authentication for unl…

No fix yet
Fix from $1,600 2020-12-12
Lastpass MEDIUM 5.7
CVE-2020-35208

An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The password authentication fo…

No fix yet
Fix from $1,600 2020-12-12
My Cloud Os 5 CRITICAL 9.8
CVE-2020-29563

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unau…

Fix: 5.07.118+
Fix from $2,300 2020-12-12
React Adal HIGH 8.2
CVE-2020-7787

This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and re…

Patch available
Fix from $1,950 2020-12-09
Hana Database MEDIUM 5.4
CVE-2020-26834

SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possibl…

Mitigation only
Fix from $1,600 2020-12-09
Opensis HIGH 7.5
CVE-2020-27408

OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker …

Fix: after 7.6
Fix from $1,950 2020-12-04
Edgeline Infrastructure Manager CRITICAL 9.8
CVE-2020-7199EPSS 9%

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Softwar…

Fix: 1.21+
Fix from $2,300 2020-12-02
My Cloud Os 5 CRITICAL 9.8
CVE-2020-28971

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unau…

Fix: 5.06.115+
Fix from $2,300 2020-12-01
My Cloud Os 5 CRITICAL 9.8
CVE-2020-28940

On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unau…

Fix: 5.06.115+
Fix from $2,300 2020-12-01
My Cloud Os 5 CRITICAL 9.8
CVE-2020-28970

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unau…

Fix: 5.06.115+
Fix from $2,300 2020-12-01
Modicon M340 Bmxp3420302 Firmware CRITICAL 9.8
CVE-2020-7533

CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sendin…

Fix: 2.10 / 3.3+
Fix from $2,300 2020-12-01
Eternus Storage Dx200 S4 Firmware CRITICAL 9.8
CVE-2020-29127

An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web b…

Fix: after 2020-11-25
Fix from $2,300 2020-11-30
V1600d Firmware HIGH 8.8
CVE-2020-29378

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4…

Mitigation only
Fix from $1,950 2020-11-29
Wepresent Wipg 1600w Firmware CRITICAL 9.8
CVE-2020-28333

Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not u…

No fix yet
Fix from $2,300 2020-11-24
Opencrx CRITICAL 9.1
CVE-2020-7378

CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to…

Fix: after 4.3.0
Fix from $2,300 2020-11-24
Debian Linux MEDIUM 5.3
CVE-2020-28896

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was inva…

Fix: 2.0.2 / 2020-11-20+
Fix from $1,600 2020-11-23
Spectrum Protect Operations Center MEDIUM 5.3
CVE-2020-4771

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive inform…

Fix: after 8.1.10
Fix from $1,600 2020-11-23
Scratchverifier HIGH 7.5
CVE-2020-26236

In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's account on any site that uses Sc…

Patch available
Fix from $1,950 2020-11-20
C Cure Web MEDIUM 5.3
CVE-2020-9049

A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated atta…

Fix: after 5.6
Fix from $1,600 2020-11-19
Debian Linux CRITICAL 9.8
CVE-2019-20933EPSS 31%

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may ha…

Fix: 1.7.6+
Fix from $2,300 2020-11-19
Ge 131 Bt 1837836 Firmware MEDIUM 6.5
CVE-2020-27558

Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream.

No fix yet
Fix from $1,600 2020-11-17
Sd Wan HIGH 7.5
CVE-2020-8272

Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

Fix: 10.2.8 / 11.1.2b+
Fix from $1,950 2020-11-16
Tomb CRITICAL 9.8
CVE-2020-28638

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be en…

Fix: after 2.7
Fix from $2,300 2020-11-13