Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Wac505 Firmware HIGH 8.8
CVE-2018-21128

Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

Fix: 5.0.0.17+
Fix from $1,950 2020-04-22
Gs810emx Firmware HIGH 8.8
CVE-2018-21121

Certain NETGEAR devices are affected by authentication bypass. This affects GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and XS724EM before 1.0.0…

Fix: 1.0.0.5 / 1.0.0.6+
Fix from $1,950 2020-04-22
Wac510 Firmware HIGH 8.8
CVE-2018-21125

NETGEAR WAC510 devices before 5.0.0.17 are affected by authentication bypass.

Fix: 5.0.0.17+
Fix from $1,950 2020-04-22
Xr500 Firmware HIGH 8.8
CVE-2018-21118

NETGEAR XR500 devices before 2.3.2.32 are affected by authentication bypass.

Fix: 2.3.2.32+
Fix from $1,950 2020-04-22
Tg\/s3.2 Firmware CRITICAL 9.8
CVE-2019-19104

The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application wit…

Mitigation only
Fix from $2,300 2020-04-22
D6100 Firmware HIGH 8.4
CVE-2017-18776

Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, J…

Fix: 1.0.0.55 / 1.0.0.108+
Fix from $1,950 2020-04-22
Ex3700 Firmware HIGH 8.8
CVE-2017-18772

Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, E…

Fix: 1.0.0.16 / 1.0.0.32+
Fix from $1,950 2020-04-22
Space CRITICAL 9.8
CVE-2020-11796

In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.

Fix: after 2020-04-22
Fix from $2,300 2020-04-22
Saml2 HIGH 7.3
CVE-2020-5268

In Saml2 Authentication Services for ASP.NET versions before 1.0.2, and between 2.0.0 and 2.6.0, there is a vulnerability in how tokens are validated…

Fix: 1.0.2 / 2.7.0+
Fix from $1,950 2020-04-21
Iqrouter Firmware HIGH 7.5
CVE-2020-11964

In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note:…

Fix: after 3.3.1
Fix from $1,950 2020-04-21
Iqrouter Firmware CRITICAL 9.8
CVE-2020-11965

In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claim…

Fix: after 3.3.1
Fix from $2,300 2020-04-21
Dsl 2640b Firmware CRITICAL 9.8
CVE-2020-9277

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perfor…

No fix yet
Fix from $2,300 2020-04-20
Honor V20 Firmware MEDIUM 5.3
CVE-2020-1803

Huawei smartphones Honor V20 with versions earlier than 10.0.0.179(C636E3R4P3),versions earlier than 10.0.0.180(C185E3R3P3),versions earlier than 10.…

Fix: 10.0.0.179 / 10.0.0.180+
Fix from $1,600 2020-04-20
Taurus Al00b Firmware MEDIUM 5.5
CVE-2020-9070

Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulnerability. The software insuff…

Fix: 10.0.0.205+
Fix from $1,600 2020-04-20
D6220 Firmware HIGH 8.4
CVE-2017-18850

Certain NETGEAR devices are affected by authentication bypass. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R625…

Fix: 1.0.0.26 / 1.0.0.56+
Fix from $1,950 2020-04-20
Dtls CRITICAL 9.8
CVE-2019-20786

handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject ar…

Fix: 1.5.2+
Fix from $2,300 2020-04-19
Endpoint Security MEDIUM 6.7
CVE-2020-7276

Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administ…

Mitigation only
Fix from $1,600 2020-04-15
Cloud Key Gen2 MEDIUM 5.3
CVE-2020-8148

UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostname by sending a malicious API …

Fix: after 1.1.6
Fix from $1,600 2020-04-13
Mate 30 Pro Firmware MEDIUM 5.5
CVE-2020-1801

There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does not sufficiently validate the…

Fix: 10.0.0.205+
Fix from $1,600 2020-04-10
Junos MEDIUM 6.5
CVE-2020-1637

A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are …

Mitigation only
Fix from $1,600 2020-04-08
Argo Cd HIGH 8.8
CVE-2020-8828

As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be a…

Fix: 1.5.0+
Fix from $1,950 2020-04-08
Junos MEDIUM 6.8
CVE-2020-1618

On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without…

Mitigation only
Fix from $1,600 2020-04-08
Android CRITICAL 9.8
CVE-2018-21038

An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsu…

Mitigation only
Fix from $2,300 2020-04-08
Android HIGH 7.5
CVE-2017-18654

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthenticated attacker can register a new security certi…

Mitigation only
Fix from $1,950 2020-04-07
Android HIGH 7.5
CVE-2016-11042

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The Samsung ID is SVE-2016-5381 (J…

No fix yet
Fix from $1,950 2020-04-07
Infinias Eidc32 Firmware CRITICAL 9.8
CVE-2020-11542

3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's…

No fix yet
Fix from $2,300 2020-04-04
Moodle CRITICAL 9.1
CVE-2019-14880

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify us…

Fix: 3.5.9 / 3.6.7+
Fix from $2,300 2020-03-31
Big Iq Centralized Management HIGH 8.1
CVE-2020-5860

On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in …

Fix: after 15.1.0
Fix from $1,950 2020-03-27
Oxfordp An10b Firmware HIGH 7.8
CVE-2020-9066

Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vulnerability. The Application do…

Fix: 10.0.1.169+
Fix from $1,950 2020-03-26
Pcoip Management Console HIGH 8.1
CVE-2020-10965

Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default ad…

Patch available
Fix from $1,950 2020-03-25