Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ca Automic Sysload CRITICAL 9.8
CVE-2019-19518

CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows…

Fix: after 6.1.2
Fix from $2,300 2020-01-08
Givewp HIGH 7.5
CVE-2019-20360

A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiabl…

Fix: 2.5.5+
Fix from $1,950 2020-01-08
Linksys Ea2700 Firmware CRITICAL 9.8
CVE-2013-5122

Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access

No fix yet
Fix from $2,300 2020-01-07
Clearscada HIGH 7.8
CVE-2019-6854

A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 …

Mitigation only
Fix from $1,950 2020-01-06
Cryptbond Network HIGH 7.5
CVE-2018-19831

The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change t…

Mitigation only
Fix from $1,950 2019-12-31
Newinteltechmedia HIGH 7.5
CVE-2018-19832

The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, allows attackers to change the…

Mitigation only
Fix from $1,950 2019-12-31
Ddq HIGH 7.5
CVE-2018-19833

The owned function of a smart contract implementation for DDQ, an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract…

Mitigation only
Fix from $1,950 2019-12-31
Bombba HIGH 7.5
CVE-2018-19834

The quaker function of a smart contract implementation for BOMBBA (BOMB), an tradable Ethereum ERC20 token, allows attackers to change the owner of t…

Mitigation only
Fix from $1,950 2019-12-31
GitLab MEDIUM 5.3
CVE-2018-20489

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A…

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
Magnolia Cms CRITICAL 9.8
CVE-2013-4621

Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities

Fix: 4.5.9+
Fix from $2,300 2019-12-27
Ds 2cd7153 E Firmware CRITICAL 9.8
CVE-2013-4976EPSS 36%

Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials

No fix yet
Fix from $2,300 2019-12-27
Avn801 Dvr Firmware CRITICAL 9.8
CVE-2013-4982EPSS 13%

AVTECH AVN801 DVR has a security bypass via the administration login captcha

No fix yet
Fix from $2,300 2019-12-27
F5d8236 4 Firmware CRITICAL 9.8
CVE-2013-3085

An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.

No fix yet
Fix from $2,300 2019-12-26
N900 Firmware CRITICAL 9.8
CVE-2013-3088

Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

Mitigation only
Fix from $2,300 2019-12-26
Sssd HIGH 8.8
CVE-2012-3462

A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event tha…

Patch available
Fix from $1,950 2019-12-26
Dir 601 Firmware CRITICAL 9.8
CVE-2019-16327

D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-…

No fix yet
Fix from $2,300 2019-12-26
Email Subscribers \& Newsletters MEDIUM 5.3
CVE-2019-19982

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit …

Fix: 4.2.3+
Fix from $1,600 2019-12-26
Linux Kernel MEDIUM 6.5
CVE-2019-5108EPSS 10%

An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by trig…

Fix: 5.3+
Fix from $1,600 2019-12-23
GitLab HIGH 8.8
CVE-2019-5486

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used…

Fix: 12.1.10 / 12.2.6+
Fix from $1,950 2019-12-18
Ipados MEDIUM 5.7
CVE-2019-8804

An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical prox…

Fix: 13.2+
Fix from $1,600 2019-12-18
Iphone Os MEDIUM 6.8
CVE-2019-8760

This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolle…

Fix: 13.0+
Fix from $1,600 2019-12-18
Iphone Os MEDIUM 5.5
CVE-2019-8704

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user…

Fix: 13 / 13.0+
Fix from $1,600 2019-12-18
Mac Os X HIGH 8.8
CVE-2019-8634

An authentication issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5. A user may be unexpectedly logged …

Fix: 10.12.6 / 10.13.6+
Fix from $1,950 2019-12-18
Mac Os X HIGH 7.8
CVE-2019-8533

A lock handling issue was addressed with improved lock handling. This issue is fixed in macOS Mojave 10.14.4. A Mac may not lock when disconnecting f…

Fix: 10.14.4+
Fix from $1,950 2019-12-18
Debian Linux CRITICAL 9.8
CVE-2014-8650

python-requests-Kerberos through 0.5 does not handle mutual authentication

Fix: after 0.5
Fix from $2,300 2019-12-15
E5572 855 Firmware MEDIUM 5.9
CVE-2019-5253

E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does not perform a sufficient auth…

Fix: 8.0.1.3+
Fix from $1,600 2019-12-13
Suphp HIGH 7.8
CVE-2014-1867

suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution

Fix: 0.7.2+
Fix from $1,950 2019-12-13
Hostapd MEDIUM 6.5
CVE-2019-5061

An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for statio…

Mitigation only
Fix from $1,600 2019-12-12
Sinvr 3 Central Control Server CRITICAL 9.8
CVE-2019-18337

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authenticatio…

Mitigation only
Fix from $2,300 2019-12-12
Sinvr 3 Central Control Server MEDIUM 5.3
CVE-2019-18341

A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Cen…

Mitigation only
Fix from $1,600 2019-12-12