Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Wordpress \+ Azure Ad \/ Microsoft Office 365 HIGH 7.5
CVE-2020-26511

The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.

Fix: 11.7+
Fix from $1,950 2020-10-02
Jwt Go HIGH 7.5
CVE-2020-26160

jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by …

Fix: after 3.2.0
Fix from $1,950 2020-09-30
Hadoop HIGH 7.5
CVE-2018-11765EPSS 5%

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerbe…

Fix: after 2.9.2
Fix from $1,950 2020-09-30
Apex One HIGH 7.8
CVE-2020-24563

A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), whi…

Mitigation only
Fix from $1,950 2020-09-29
Cpanel CRITICAL 9.8
CVE-2020-26105

In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).

Fix: 88.0.3+
Fix from $2,300 2020-09-25
Cpanel CRITICAL 9.8
CVE-2020-26101

In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).

Fix: 88.0.3+
Fix from $2,300 2020-09-25
Fosite HIGH 8.1
CVE-2020-15222

In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the un…

Fix: 0.31.0+
Fix from $1,950 2020-09-24
Secure Firewall Management Center CRITICAL 9.8
CVE-2019-16028

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to b…

Fix: 6.2.3.16 / 6.3.0.6+
Fix from $2,300 2020-09-23
Sg250x 24 Firmware MEDIUM 5.3
CVE-2019-15993EPSS 10%

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information…

Fix: 2.5.0.92+
Fix from $1,600 2020-09-23
Xenmobile Server HIGH 7.5
CVE-2020-8253

Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before R…

Fix: after 10.8.0
Fix from $1,950 2020-09-18
Storefront Server MEDIUM 6.5
CVE-2020-8200

Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory doma…

Fix: 3.0.8001 / 3.12.5001+
Fix from $1,600 2020-09-18
Web Gateway MEDIUM 5.7
CVE-2020-7297

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard …

Fix: 7.8.2.22 / 8.2.9+
Fix from $1,600 2020-09-16
Web Gateway CRITICAL 9.0
CVE-2020-7293

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change…

Fix: 7.8.2.23 / 8.2.11+
Fix from $2,300 2020-09-15
Web Gateway MEDIUM 5.7
CVE-2020-7296

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configurat…

Fix: 7.8.2.23 / 8.2.11+
Fix from $1,600 2020-09-15
Command Centre CRITICAL 9.8
CVE-2020-16098

It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior…

Fix: 8.00.1228 / 8.10.1211+
Fix from $2,300 2020-09-15
GitLab MEDIUM 6.5
CVE-2020-13303

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized use…

Fix: 13.1.10 / 13.2.8+
Fix from $1,600 2020-09-15
Bluetooth Core Specification MEDIUM 5.9
CVE-2020-15802EPSS 7%

Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specific…

Fix: 5.1+
Fix from $1,600 2020-09-11
Patient Information Center Ix HIGH 8.8
CVE-2020-16222

In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a g…

No fix yet
Fix from $1,950 2020-09-11
Onbase CRITICAL 9.1
CVE-2020-25251

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and …

Fix: after 20.3.10.1000
Fix from $2,300 2020-09-11
Simatic Hmi United Comfort Panels Firmware CRITICAL 9.8
CVE-2020-15787

A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authenticat…

Mitigation only
Fix from $2,300 2020-09-09
Endpoint Security MEDIUM 6.9
CVE-2020-7323

Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical lo…

Fix: 10.7.0+
Fix from $1,600 2020-09-09
Ipq6018 Firmware HIGH 7.8
CVE-2019-10562

u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into se…

Mitigation only
Fix from $1,950 2020-09-08
Ac18 Firmware CRITICAL 9.8
CVE-2020-24987

Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authenticati…

Mitigation only
Fix from $2,300 2020-09-04
Qualiex CRITICAL 9.8
CVE-2020-24029

Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple reque…

Mitigation only
Fix from $2,300 2020-09-02
Magmi CRITICAL 9.8
CVE-2020-5777EPSS 23%

MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database …

Fix: 0.7.24+
Fix from $2,300 2020-09-01
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2020-24786EPSS 13%

An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo…

Fix: after 12.1.2
Fix from $2,300 2020-08-31
Endpoint Security HIGH 7.8
CVE-2020-8097

An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivile…

Fix: 6.6.18.261+
Fix from $1,950 2020-08-30
Scratch Login CRITICAL 10.0
CVE-2020-15164

in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repea…

Fix: 1.1+
Fix from $2,300 2020-08-28
Deep Security Manager HIGH 8.1
CVE-2020-15601

If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated …

Patch available
Fix from $1,950 2020-08-27
Deep Security Manager HIGH 8.1
CVE-2020-15605

If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthe…

Patch available
Fix from $1,950 2020-08-27