Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
OpenBSD CRITICAL 9.8
CVE-2020-16088

iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key mat…

Fix: after 6.7
Fix from $2,300 2020-07-28
Fortios CRITICAL 9.8
CVE-2020-12812 KEVEPSS 49%

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succe…

Fix: 6.0.10 / 6.2.4+
Fix from $2,300 2020-07-24
Workspace HIGH 8.8
CVE-2020-8207

Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic upd…

Mitigation only
Fix from $1,950 2020-07-24
Eframework CRITICAL 9.8
CVE-2020-15921EPSS 18%

Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as …

Fix: after 2.9.0
Fix from $2,300 2020-07-24
C More Hmi Ea9 Firmware HIGH 7.5
CVE-2020-10918

This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen pa…

Mitigation only
Fix from $1,950 2020-07-23
Esp Idf MEDIUM 6.8
CVE-2020-12638

An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK dev…

Fix: after 4.2
Fix from $1,600 2020-07-23
Dap 1522 Firmware HIGH 7.5
CVE-2020-15896

An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessi…

Patch available
Fix from $1,950 2020-07-22
R8500g4 Firmware CRITICAL 9.8
CVE-2020-6871

The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server a…

Mitigation only
Fix from $2,300 2020-07-20
Openclinic Ga CRITICAL 9.8
CVE-2020-14485

OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a sessio…

Mitigation only
Fix from $2,300 2020-07-20
Openclinic Ga CRITICAL 9.8
CVE-2020-14494

OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to prot…

Mitigation only
Fix from $2,300 2020-07-20
Honor V30 Firmware MEDIUM 6.5
CVE-2020-9259

Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerability. The system does not su…

Fix: 10.1.0.212+
Fix from $1,600 2020-07-17
Sd Wan Firmware HIGH 7.8
CVE-2020-3388

A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands that are execut…

Fix: 19.2.2 / 20.1.1+
Fix from $1,950 2020-07-16
Meeting Server MEDIUM 5.3
CVE-2020-3197

A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Re…

Mitigation only
Fix from $1,600 2020-07-16
Rv110w Firmware CRITICAL 9.8
CVE-2020-3144

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction …

Fix: 1.0.3.55 / 1.2.2.8+
Fix from $2,300 2020-07-16
Automate CRITICAL 9.8
CVE-2020-15027

ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attem…

Fix: 2019.12+
Fix from $2,300 2020-07-16
Robotware CRITICAL 9.8
CVE-2020-10288

IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can inpu…

Mitigation only
Fix from $2,300 2020-07-15
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8193 KEVEPSS 88%

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW…

Fix: 10.2.7 / 10.5-70.18+
Fix from $1,600 2020-07-10
Mate 30 Pro Firmware MEDIUM 5.5
CVE-2020-1838

HUAWEI Mate 30 Pro with versions earlier than 10.1.0.150(C00E136R5P3) have is an improper authentication vulnerability. The device does not sufficien…

Fix: 10.1.0.150+
Fix from $1,600 2020-07-06
Prestashop CRITICAL 9.8
CVE-2020-4074

In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and e…

Fix: 1.7.6.6+
Fix from $2,300 2020-07-02
Sg250x 24 Firmware CRITICAL 9.8
CVE-2020-3297

A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, …

Fix: 2.5.5.47+
Fix from $2,300 2020-07-02
Mk Auth CRITICAL 9.8
CVE-2020-14070

An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessable credentials to admin/execut…

Mitigation only
Fix from $2,300 2020-06-29
Jira MEDIUM 5.3
CVE-2019-20412

The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following in…

Fix: 7.13.9 / 8.4.2+
Fix from $1,600 2020-06-29
Mattermost Server HIGH 8.1
CVE-2017-18906

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody el…

Fix: 3.9.2 / 3.10.2+
Fix from $1,950 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2017-18908

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-ma…

Fix: 3.9.2 / 3.10.2+
Fix from $2,300 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18919

An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.

Fix: 3.6.3+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.5
CVE-2016-11072

An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.

Fix: 3.0.2+
Fix from $1,600 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2016-11074

An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.

Fix: 3.0.0+
Fix from $2,300 2020-06-19
Mattermost Server HIGH 8.8
CVE-2018-21263

An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a craft…

Fix: 4.5.2 / 4.6.2+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2019-20875

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is…

Fix: 4.10.8 / 5.7.3+
Fix from $1,600 2020-06-19
Mattermost Desktop MEDIUM 6.5
CVE-2020-14455

An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-20…

Fix: 4.4.0+
Fix from $1,600 2020-06-19