Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Portable Phpmyadmin CRITICAL 9.1
CVE-2013-4454

WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities

Mitigation only
Fix from $2,300 2020-02-18
Hege 560 Firmware MEDIUM 6.8
CVE-2020-1842

Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insuf…

Mitigation only
Fix from $1,600 2020-02-18
P30 Firmware HIGH 7.8
CVE-2020-1812

HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability. Due to improperly validation…

Fix: 10.0.0.173+
Fix from $1,950 2020-02-18
Osca 550 Firmware MEDIUM 6.8
CVE-2020-1789

Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentication vulnerability. The soft…

Mitigation only
Fix from $1,600 2020-02-18
Virtual System Administrator CRITICAL 9.8
CVE-2015-6922EPSS 82%

Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly req…

Fix: 7.0.0.33 / 8.0.0.23+
Fix from $2,300 2020-02-17
Husky Rtu 6049 E70 Firmware CRITICAL 9.8
CVE-2019-20046

The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does…

Fix: after 5.0
Fix from $2,300 2020-02-14
Ts S402 Firmware HIGH 7.5
CVE-2013-6360

TRENDnet TS-S402 has a backdoor to enable TELNET.

No fix yet
Fix from $1,950 2020-02-13
Simplisafe Ss3 Firmware MEDIUM 5.5
CVE-2019-3998

Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi …

No fix yet
Fix from $1,600 2020-02-13
Converged Security Management Engine Firmware MEDIUM 6.7
CVE-2019-14598

Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0…

Fix: 12.0.48 / 12.0.56+
Fix from $1,600 2020-02-13
Rbs Bs Client. Retail Client CRITICAL 9.1
CVE-2014-4198

A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID a…

No fix yet
Fix from $2,300 2020-02-13
Openvpn Access Server CRITICAL 9.8
CVE-2020-8953

OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).

Fix: 2.8.1+
Fix from $2,300 2020-02-13
Shaman HIGH 7.8
CVE-2011-4338

Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is r…

No fix yet
Fix from $1,950 2020-02-12
Openshift Service Mesh HIGH 7.3
CVE-2020-8595

Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact…

Fix: after 1.4.3
Fix from $1,950 2020-02-12
Exchange Server HIGH 8.8
CVE-2020-0688 KEVEPSS 100%

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Micros…

Patch available
Fix from $1,950 2020-02-11
Paste Applet HIGH 8.4
CVE-2013-2120

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, …

Fix: 4.10.5+
Fix from $1,950 2020-02-11
Ammyy Admin HIGH 7.8
CVE-2013-5582

Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass …

Fix: after 3.2
Fix from $1,950 2020-02-11
Atutor CRITICAL 9.8
CVE-2014-9753

confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login paramet…

Fix: after 2.2
Fix from $2,300 2020-02-11
Analyzer CRITICAL 9.8
CVE-2013-1359EPSS 89%

An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal M…

No fix yet
Fix from $2,300 2020-02-11
Analyzer CRITICAL 9.8
CVE-2013-1360EPSS 23%

An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal M…

No fix yet
Fix from $2,300 2020-02-11
Filemaker Pro HIGH 7.8
CVE-2014-8347

An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.…

No fix yet
Fix from $1,950 2020-02-11
Yetishare CRITICAL 9.8
CVE-2019-20062

MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).

Fix: after 4.5.4
Fix from $2,300 2020-02-10
Lxc HIGH 8.1
CVE-2017-18641

In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.

Patch available
Fix from $1,950 2020-02-10
Dir865l Firmware MEDIUM 5.9
CVE-2013-3096

D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.

No fix yet
Fix from $1,600 2020-02-07
N300 Firmware CRITICAL 9.8
CVE-2013-3091

An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging…

No fix yet
Fix from $2,300 2020-02-07
Wp Time Capsule CRITICAL 9.8
CVE-2020-8771EPSS 46%

The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be log…

Fix: 1.21.16+
Fix from $2,300 2020-02-06
Linksys E4200 Firmware CRITICAL 9.8
CVE-2013-2681EPSS 10%

Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

No fix yet
Fix from $2,300 2020-02-05
Workflow HIGH 8.1
CVE-2015-0102

IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to captu…

Mitigation only
Fix from $1,950 2020-02-05
Nextcloud MEDIUM 6.1
CVE-2019-15615

A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.

Fix: after 3.9.0
Fix from $1,600 2020-02-04
Nextcloud Server MEDIUM 5.4
CVE-2019-15617

A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.

Fix: 17.0.1+
Fix from $1,600 2020-02-04
Dir 100 Firmware HIGH 8.8
CVE-2013-7051EPSS 16%

D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters

No fix yet
Fix from $1,950 2020-02-04