Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Security Guardium Insights MEDIUM 6.5
CVE-2020-4167

IBM Security Guardium Insights 2.0.1 could allow an attacker to obtain sensitive information or perform unauthorized actions due to improper authenci…

Patch available
Fix from $1,600 2020-08-27
Connected Mobile Experiences MEDIUM 6.7
CVE-2020-3151

A vulnerability in the CLI of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials t…

Mitigation only
Fix from $1,600 2020-08-26
M1000 Multipara Patient Monitor Firmware HIGH 7.8
CVE-2020-15482

An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank passwo…

Mitigation only
Fix from $1,950 2020-08-26
Vault HIGH 8.2
CVE-2020-16251

HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypa…

Fix: 1.2.5 / 1.3.8+
Fix from $1,950 2020-08-26
Dbhcms MEDIUM 5.9
CVE-2020-19888

DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation.…

No fix yet
Fix from $1,600 2020-08-24
Aptra Xfs MEDIUM 5.3
CVE-2020-10123

The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests fro…

Fix: after 05.01.00
Fix from $1,600 2020-08-21
Nodebb CRITICAL 9.9
CVE-2020-15149

NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user…

Fix: 1.14.3+
Fix from $2,300 2020-08-20
Catalyst Center HIGH 7.5
CVE-2020-3411

A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. Th…

Fix: 1.3.1.4+
Fix from $1,950 2020-08-17
Fusioncompute CRITICAL 9.1
CVE-2020-9233

FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to delete some files and cause some …

Mitigation only
Fix from $2,300 2020-08-17
Event Streams HIGH 8.8
CVE-2020-4662

IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 18…

Patch available
Fix from $1,950 2020-08-14
Server Board S2600wt Firmware HIGH 8.8
CVE-2020-8708

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to …

Fix: 1.59+
Fix from $1,950 2020-08-13
Server Board S2600wt Firmware HIGH 8.8
CVE-2020-8709

Improper authentication in socket services for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow an unaut…

Fix: 2.45+
Fix from $1,950 2020-08-13
Server Board S2600wt Firmware HIGH 8.8
CVE-2020-8713

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to …

Fix: 1.59+
Fix from $1,950 2020-08-13
Server Board S2600wt Firmware HIGH 7.8
CVE-2020-8714

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to po…

Fix: 1.59+
Fix from $1,950 2020-08-13
GitLab HIGH 7.2
CVE-2020-13290

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page

Fix: 13.0.12 / 13.1.6+
Fix from $1,950 2020-08-12
GitLab CRITICAL 9.6
CVE-2020-13292

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

Fix: 13.0.12 / 13.1.6+
Fix from $2,300 2020-08-10
42633 Firmware HIGH 8.8
CVE-2020-15059

Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administ…

Mitigation only
Fix from $1,950 2020-08-07
Da 70254 Firmware HIGH 8.8
CVE-2020-15063

DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administ…

Mitigation only
Fix from $1,950 2020-08-07
Tl Ps310u Firmware HIGH 8.8
CVE-2020-15055

TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass authentication via a web-administ…

Fix: 2.079.000.t0210+
Fix from $1,950 2020-08-07
Robox Os CRITICAL 9.8
CVE-2020-16169

Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gai…

Fix: after 119.24
Fix from $2,300 2020-08-07
Etcd MEDIUM 6.5
CVE-2020-15136

In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gatew…

Fix: 3.3.23 / 3.4.10+
Fix from $1,600 2020-08-06
Nas326 Firmware HIGH 8.8
CVE-2020-13365

Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can …

Mitigation only
Fix from $1,950 2020-08-06
Centum Cs 3000 Firmware CRITICAL 9.8
CVE-2020-5608

CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B…

Mitigation only
Fix from $2,300 2020-08-05
Calendar01 CRITICAL 9.8
CVE-2020-5616

[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0…

Fix: after 1.0.3
Fix from $2,300 2020-08-04
Endpoint Security HIGH 8.8
CVE-2020-8108

Improper Authentication vulnerability in Bitdefender Endpoint Security for Mac allows an unprivileged process to restart the main service and potenti…

Fix: 4.12.80+
Fix from $1,950 2020-08-03
Multifactor Authentication Agent HIGH 8.4
CVE-2020-5384

Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability. A local unauthenticated …

Mitigation only
Fix from $1,950 2020-07-31
Secvest Hybrid Fumo50110 Firmware CRITICAL 9.1
CVE-2020-14158

The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that are exchan…

No fix yet
Fix from $2,300 2020-07-30
Connect Secure HIGH 8.1
CVE-2020-8206

An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the…

Fix: after 9.0
Fix from $1,950 2020-07-30
Sv8100 Firmware CRITICAL 9.8
CVE-2019-20027

Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly…

Mitigation only
Fix from $2,300 2020-07-29
Sv8100 Firmware CRITICAL 9.8
CVE-2019-20033

On Aspire-derived NEC PBXes, including all versions of SV8100 devices, a set of documented, static login credentials may be used to access the DIM in…

Mitigation only
Fix from $2,300 2020-07-29