Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Webex Meetings CRITICAL 9.8
CVE-2020-3361

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access t…

Fix: 4.0+
Fix from $2,300 2020-06-18
Caddy CRITICAL 9.8
CVE-2018-21246

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching m…

Fix: 0.10.3+
Fix from $2,300 2020-06-15
P30 Firmware MEDIUM 6.8
CVE-2020-9076

HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), …

Fix: 10.1.0.135 / 10.1.0.137+
Fix from $1,600 2020-06-15
Spectrum Protect Client HIGH 7.5
CVE-2020-4494

IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8…

Fix: after 8.1.9.1
Fix from $1,950 2020-06-15
Ips Module Firmware CRITICAL 9.8
CVE-2020-9099

Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of…

Mitigation only
Fix from $2,300 2020-06-08
Cells MEDIUM 5.4
CVE-2020-12848

In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is created in …

No fix yet
Fix from $1,600 2020-06-05
Phantompdf HIGH 7.5
CVE-2019-20833

An issue was discovered in Foxit PhantomPDF before 8.3.10. It has mishandling of cloud credentials, as demonstrated by Google Drive.

Fix: 8.3.10+
Fix from $1,950 2020-06-04
E Mail Advertising System HIGH 7.5
CVE-2018-21235

An issue was discovered in Foxit E-mail advertising system before September 2018. It allows authentication bypass and information disclosure, related…

Fix: 09-2018+
Fix from $1,950 2020-06-04
Ios Xe Sd Wan MEDIUM 6.8
CVE-2020-3216

A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted acce…

Mitigation only
Fix from $1,600 2020-06-03
Interscan Web Security Virtual Appliance CRITICAL 9.8
CVE-2020-8606EPSS 73%

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installat…

Patch available
Fix from $2,300 2020-05-27
Eb 1470ui Firmware CRITICAL 9.1
CVE-2020-6091

An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MAIN2: 8X7…

Mitigation only
Fix from $2,300 2020-05-22
Rbs50y Firmware HIGH 8.8
CVE-2020-11551

An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and…

Patch available
Fix from $1,950 2020-05-18
Aptare CRITICAL 9.8
CVE-2020-12874

Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to …

Fix: 10.4+
Fix from $2,300 2020-05-14
Pan Os CRITICAL 9.0
CVE-2020-2018

An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management in…

Fix: 7.1.26 / 8.1.12+
Fix from $2,300 2020-05-13
Jboss Fuse HIGH 8.8
CVE-2020-1718

A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the …

Fix: 8.0.0+
Fix from $1,950 2020-05-12
Tl Wa855re Firmware HIGH 8.0
CVE-2020-10916

This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 855rev4-up-…

Mitigation only
Fix from $1,950 2020-05-07
Data Risk Manager CRITICAL 9.8
CVE-2020-4427 KEVEPSS 70%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with…

Fix: after 2.0.6.1
Fix from $2,300 2020-05-07
Asa 5505 Firmware CRITICAL 9.8
CVE-2020-3125

A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote att…

Mitigation only
Fix from $2,300 2020-05-06
Faye CRITICAL 9.8
CVE-2020-11020

Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension syste…

Fix: 1.0.4 / 1.1.3+
Fix from $2,300 2020-04-29
Jnr1010 Firmware HIGH 7.5
CVE-2016-11057

Certain NETGEAR devices are affected by mishandling of repeated URL calls. This affects JNR1010v2 before 2017-01-06, WNR614 before 2017-01-06, WNR618…

Fix: 2017-01-06+
Fix from $1,950 2020-04-28
Jgs516pe Firmware MEDIUM 6.5
CVE-2017-18862

Certain NETGEAR devices are affected by authentication bypass. This affects JGS516PE before 2017-05-11, JGS524Ev2 before 2017-05-11, JGS524PE before …

Fix: 2017-05-11+
Fix from $1,600 2020-04-28
Garoon MEDIUM 5.3
CVE-2020-5563

Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in the affected product via the API.

Fix: after 4.10.3
Fix from $1,600 2020-04-28
Garoon HIGH 7.5
CVE-2020-5567

Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in Application Menu.

Fix: after 4.10.3
Fix from $1,950 2020-04-28
Fortimail CRITICAL 9.8
CVE-2020-9294EPSS 78%

An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote un…

Fix: after 6.2.2
Fix from $2,300 2020-04-27
Ar3200 Firmware CRITICAL 9.8
CVE-2020-9068

Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an imprope…

Mitigation only
Fix from $2,300 2020-04-27
Fedora CRITICAL 9.8
CVE-2019-18823

HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authent…

Fix: after 8.9.4
Fix from $2,300 2020-04-27
D6200 Firmware HIGH 8.8
CVE-2017-18720

Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, a…

Fix: 1.1.00.24 / 1.1.0.42+
Fix from $1,950 2020-04-24
R6300 Firmware HIGH 8.8
CVE-2017-18732

Certain NETGEAR devices are affected by authentication bypass. This affects R6300v2 before 1.0.4.8, PLW1000v2 before 1.0.0.14, and PLW1010v2 before 1…

Fix: 1.0.0.14 / 1.0.4.8+
Fix from $1,950 2020-04-23
D6220 Firmware HIGH 8.8
CVE-2017-18733

Certain NETGEAR devices are affected by authentication bypass. This affects D6220 before 1.0.0.28, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R625…

Fix: 1.0.0.28 / 1.0.0.32+
Fix from $1,950 2020-04-23
R6300 Firmware HIGH 8.8
CVE-2017-18743

Certain NETGEAR devices are affected by authentication bypass. This affects R6300v2 before 1.0.4.8, R6400 before 1.0.1.20, R6700 before 1.0.1.20, R69…

Fix: 1.0.0.32 / 1.0.0.52+
Fix from $1,950 2020-04-23