Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Eg Manager CRITICAL 9.8
CVE-2020-8591

eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.

No fix yet
Fix from $2,300 2020-02-03
Phpabook CRITICAL 9.8
CVE-2020-8510

An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang)…

Mitigation only
Fix from $2,300 2020-02-03
Airwave HIGH 7.5
CVE-2016-2032

A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called…

Fix: 4.1.3.0 / 8.2.0.0+
Fix from $1,950 2020-01-31
Lastpass MEDIUM 6.1
CVE-2013-5114

LastPass prior to 2.5.1 allows secure wipe bypass.

Fix: 2.5.1+
Fix from $1,600 2020-01-31
Evernote HIGH 7.1
CVE-2013-5116

Evernote prior to 5.5.1 has insecure password change

Fix: 5.5.1+
Fix from $1,950 2020-01-31
Opencast CRITICAL 10.0
CVE-2020-5206

In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that use…

Fix: 7.6+
Fix from $2,300 2020-01-30
Wnr1000 Firmware CRITICAL 9.8
CVE-2013-3316

Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".

Fix: 1.0.2.60+
Fix from $2,300 2020-01-29
Wnr1000 Firmware CRITICAL 9.8
CVE-2013-3317

Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.

Fix: 1.0.2.60+
Fix from $2,300 2020-01-29
Vtiger Crm CRITICAL 9.8
CVE-2013-3215EPSS 69%

vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

Fix: after 5.4.0
Fix from $2,300 2020-01-29
F3105 Firmware HIGH 7.5
CVE-2013-2569EPSS 31%

A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could…

Fix: after 1.6.03
Fix from $1,950 2020-01-29
Dcs 2102 Firmware MEDIUM 5.3
CVE-2013-1600EPSS 19%

An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_…

No fix yet
Fix from $1,600 2020-01-28
Wndr4700 Firmware CRITICAL 9.8
CVE-2013-3071

NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.

No fix yet
Fix from $2,300 2020-01-28
Veralite Firmware HIGH 8.8
CVE-2013-4863EPSS 12%

The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLu…

No fix yet
Fix from $1,950 2020-01-28
GitLab CRITICAL 9.8
CVE-2019-15585

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML …

Fix: 12.1.12 / 12.2.6+
Fix from $2,300 2020-01-28
A3002ru Firmware CRITICAL 9.8
CVE-2019-19825EPSS 30%

On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin…

Fix: after 4.0.0
Fix from $2,300 2020-01-27
Portable Phpmyadmin CRITICAL 9.1
CVE-2013-4462

WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability

No fix yet
Fix from $2,300 2020-01-27
Django User Sessions HIGH 8.8
CVE-2020-5224

In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used t…

Fix: 1.7.1+
Fix from $1,950 2020-01-24
Pt7135 Firmware MEDIUM 5.3
CVE-2013-1596EPSS 10%

An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554.

No fix yet
Fix from $1,600 2020-01-24
Lnc116 Firmware CRITICAL 9.8
CVE-2012-6451

Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability

Fix: after 030312
Fix from $2,300 2020-01-24
Honor V30 Firmware MEDIUM 5.5
CVE-2020-1788

Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not p…

Fix: 10.0.1.135+
Fix from $1,600 2020-01-21
Mate 20 Firmware MEDIUM 6.0
CVE-2020-1840

HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker wit…

Fix: after 10.0.0.175
Fix from $1,600 2020-01-21
Web Server MEDIUM 5.3
CVE-2020-7222

An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to …

No fix yet
Fix from $1,600 2020-01-18
Serpico MEDIUM 6.5
CVE-2019-19857

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the…

Mitigation only
Fix from $1,600 2020-01-15
Campaign Enterprise HIGH 7.5
CVE-2012-3824

In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.

Fix: 11.0.551+
Fix from $1,950 2020-01-10
Sphider CRITICAL 9.8
CVE-2014-5081EPSS 10%

sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass

Fix: 1.3.6 / 3.2+
Fix from $2,300 2020-01-10
Browserid CRITICAL 9.8
CVE-2012-2714

The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via …

Mitigation only
Fix from $2,300 2020-01-09
Scrutinizer Netflow \& Sflow Analyzer MEDIUM 6.5
CVE-2012-1258

cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow…

Fix: 9.0.1.19899+
Fix from $1,600 2020-01-09
Mate 20 Firmware MEDIUM 6.6
CVE-2020-1787

HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error u…

Fix: 9.1.0.139+
Fix from $1,600 2020-01-09
Openstage 80 Firmware CRITICAL 9.8
CVE-2014-2651

Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface

Mitigation only
Fix from $2,300 2020-01-09
Firefox MEDIUM 6.5
CVE-2019-17023

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS …

Fix: 72.0+
Fix from $1,600 2020-01-08