Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ac1750 Firmware CRITICAL 9.8
CVE-2020-10888

This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 router…

Mitigation only
Fix from $2,300 2020-03-25
Android HIGH 7.5
CVE-2019-20618

An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allows unauthenticated unpinning of an app. The Samsun…

Mitigation only
Fix from $1,950 2020-03-24
Android HIGH 7.5
CVE-2019-20620

An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application allows unauthenticated changes. The Samsung IDs are …

Mitigation only
Fix from $1,950 2020-03-24
Android HIGH 7.5
CVE-2019-20565

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can change the USB configuration without authentication.…

Mitigation only
Fix from $1,950 2020-03-24
Android MEDIUM 5.5
CVE-2020-10846

An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devi…

Mitigation only
Fix from $1,600 2020-03-24
Android MEDIUM 6.8
CVE-2020-10847

An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SV…

Mitigation only
Fix from $1,600 2020-03-24
Dir 878 Firmware HIGH 8.8
CVE-2020-8863EPSS 77%

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 route…

Fix: after 1.20b03
Fix from $1,950 2020-03-23
Secospace Antiddos8000 Firmware HIGH 8.1
CVE-2020-1864

Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain some information and forge the p…

Mitigation only
Fix from $1,950 2020-03-20
Oxfords An00a Firmware MEDIUM 5.5
CVE-2020-1878

Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper a…

Fix: 10.0.1.152d / 10.0.1.160+
Fix from $1,600 2020-03-20
Oce Colorwave 500 Firmware HIGH 7.5
CVE-2020-10669

The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthent…

No fix yet
Fix from $1,950 2020-03-19
Datapower Gateway MEDIUM 6.3
CVE-2020-4205

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the ser…

Fix: after 2018.4.1.8
Fix from $1,600 2020-03-19
Micrologix 1400 A Firmware HIGH 7.5
CVE-2020-6988

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…

Fix: after 21.001
Fix from $1,950 2020-03-16
Easy\!appointments MEDIUM 6.5
CVE-2018-13060

Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.

Fix: 1.2.1+
Fix from $1,600 2020-03-16
Django Rest Framework Json Web Tokens CRITICAL 9.1
CVE-2020-10594

An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working t…

Fix: 1.15.1+
Fix from $2,300 2020-03-15
Honor V30 Firmware MEDIUM 5.5
CVE-2020-9064

Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentication vulnerability. Authentic…

Mitigation only
Fix from $1,600 2020-03-12
Mdz 25 Dt Firmware MEDIUM 6.8
CVE-2020-8994

An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then th…

No fix yet
Fix from $1,600 2020-03-05
Envoy MEDIUM 5.3
CVE-2020-8664

CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) acros…

Fix: after 1.13.0
Fix from $1,600 2020-03-04
Openblocks Iot Vx2 Firmware HIGH 8.8
CVE-2020-5536

OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentication and to initialize the de…

Fix: 4.0.0+
Fix from $1,950 2020-03-04
Easyio 30p Firmware HIGH 7.5
CVE-2018-15819

EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.

Fix: 2.0.5.27+
Fix from $1,950 2020-03-02
Wnr1000 Firmware CRITICAL 9.8
CVE-2019-20489

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other proble…

Mitigation only
Fix from $2,300 2020-03-02
Tat 77104g1 Firmware CRITICAL 9.8
CVE-2020-3923

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET, contain misconfigured authentication mechanism. Attackers can crack the def…

Fix: after 20181221_76216g3
Fix from $2,300 2020-02-27
Awk 3131a Firmware HIGH 7.2
CVE-2019-5165

An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configu…

No fix yet
Fix from $1,950 2020-02-25
5n2 Firmware CRITICAL 9.8
CVE-2018-14705

In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing th…

Mitigation only
Fix from $2,300 2020-02-24
Xgw 3000 Zigbee Gateway Firmware CRITICAL 9.8
CVE-2019-20481

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in …

Fix: 2.4.0+
Fix from $2,300 2020-02-24
Centreon Web HIGH 8.8
CVE-2019-15299

An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the…

Fix: after 19.04.3
Fix from $1,950 2020-02-24
Dap 1330 Firmware HIGH 8.8
CVE-2020-8861EPSS 7%

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range e…

Fix: 1.10b01+
Fix from $1,950 2020-02-22
Dap 2610 Firmware HIGH 8.8
CVE-2020-8862EPSS 13%

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 router…

Fix: after 2.01rc067
Fix from $1,950 2020-02-22
Vrealize Operations HIGH 8.6
CVE-2020-3944

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authenti…

Fix: 6.6.1 / 6.7.1+
Fix from $1,950 2020-02-19
Asa 5500 Firmware HIGH 7.5
CVE-2011-2054

A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Seconda…

Mitigation only
Fix from $1,950 2020-02-19
FreeBSD CRITICAL 9.8
CVE-2014-3879

OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, whi…

Fix: after 9.2
Fix from $2,300 2020-02-18