Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Alaris 8015 Pcu Firmware HIGH 7.5
CVE-2020-25165

BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnera…

Fix: after 9.33.1
Fix from $1,950 2020-11-13
Pan Os HIGH 8.2
CVE-2020-2050

An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to…

Fix: 8.1.17 / 9.0.11+
Fix from $1,950 2020-11-12
Hazelcast CRITICAL 9.8
CVE-2020-26168

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify p…

Fix: 4.0.3+
Fix from $2,300 2020-11-09
Percona Server CRITICAL 9.8
CVE-2020-26542

An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjuncti…

Fix: after 2020-10-02
Fix from $2,300 2020-11-09
Microweber MEDIUM 5.5
CVE-2020-23139

Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized …

Mitigation only
Fix from $1,600 2020-11-09
Alerta CRITICAL 9.8
CVE-2020-26214EPSS 66%

In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to …

Fix: 7.5.7 / 8.1.0+
Fix from $2,300 2020-11-06
Debian Linux CRITICAL 9.8
CVE-2020-25592EPSS 58%

In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Shiro CRITICAL 9.8
CVE-2020-17510EPSS 9%

Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

Fix: 1.7.0+
Fix from $2,300 2020-11-05
Unifi Protect Firmware MEDIUM 5.3
CVE-2020-8267

A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token…

Fix: after 1.14.10
Fix from $1,600 2020-11-05
Unity Orchestrator CRITICAL 9.8
CVE-2020-12145EPSS 6%

Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This m…

Fix: 8.9.11 / 8.10.11+
Fix from $2,300 2020-11-05
Immuta HIGH 7.5
CVE-2020-15949

Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.

No fix yet
Fix from $1,950 2020-11-05
Nextcloud Server MEDIUM 6.8
CVE-2020-8236

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking…

Fix: 19.0.2+
Fix from $1,600 2020-11-02
Sonarqube MEDIUM 5.3
CVE-2020-28002

In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login opt…

No fix yet
Fix from $1,600 2020-11-02
Single Sign On For Tanzu HIGH 7.9
CVE-2020-5425

Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user imper…

Fix: 1.11.3 / 1.12.4+
Fix from $1,950 2020-10-31
Storeserv Management Console CRITICAL 9.8
CVE-2020-7197

SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web appl…

Fix: 3.7.1.1+
Fix from $2,300 2020-10-26
Fruitywifi HIGH 7.8
CVE-2020-24848

FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local p…

Fix: after 2.4
Fix from $1,950 2020-10-23
Secure Firewall Threat Defense MEDIUM 5.8
CVE-2020-3565

A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t…

Fix: 6.4.0.8 / 6.5.0.4+
Fix from $1,600 2020-10-21
Secure Firewall Management Center HIGH 8.1
CVE-2020-3410

A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthentic…

Mitigation only
Fix from $1,950 2020-10-21
Omniauth Auth0 CRITICAL 9.1
CVE-2020-15240

omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Imp…

Fix: 2.4.1+
Fix from $2,300 2020-10-21
Spree CRITICAL 9.1
CVE-2020-15269

In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in v…

Fix: 3.7.11 / 4.0.4+
Fix from $2,300 2020-10-20
Intelligent Management Center CRITICAL 9.8
CVE-2020-24629

A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC P…

Fix: 7.3+
Fix from $2,300 2020-10-19
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2020-14299

A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox Secur…

Fix: 5.0.3+
Fix from $1,600 2020-10-16
Siport Mp HIGH 8.8
CVE-2020-7591

A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to i…

Fix: 3.2.1+
Fix from $1,950 2020-10-15
Thinkpad Stack Wireless Router Firmware HIGH 8.8
CVE-2020-8350

An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of …

Fix: after 1.1.3.4
Fix from $1,950 2020-10-14
Curam Social Program Management HIGH 8.1
CVE-2020-4779

A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attac…

Mitigation only
Fix from $1,950 2020-10-12
Gs110emx Firmware HIGH 8.8
CVE-2020-26921

Certain NETGEAR devices are affected by authentication bypass. This affects GS110EMX before 1.0.1.7, GS810EMX before 1.7.1.3, XS512EM before 1.0.1.3,…

Fix: 1.0.1.3 / 1.0.1.7+
Fix from $1,950 2020-10-09
Smartstore CRITICAL 9.8
CVE-2020-15243

Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 …

Mitigation only
Fix from $2,300 2020-10-08
Manageengine Applications Manager HIGH 7.5
CVE-2020-10816

Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor …

Mitigation only
Fix from $1,950 2020-10-08
Soplanning MEDIUM 5.3
CVE-2020-25867

SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentica…

Fix: 1.47+
Fix from $1,600 2020-10-07
Wn530h4 Firmware CRITICAL 9.8
CVE-2020-12126

Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router s…

Mitigation only
Fix from $2,300 2020-10-02