Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.1 CVE-2021-34578 This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically construct… 750 890\/040 000 Firmware Mitigation only Fix from $1,9502021-08-31 CRITICAL 9.8 CVE-2021-39177 Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNAPSHOT allow anyone that can c… Geyser 1.4.2+ Fix from $2,3002021-08-30 CRITICAL 9.8 CVE-2021-37417 Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. Manageengine Adselfservice Plus 6.1+ Fix from $2,3002021-08-30 HIGH 7.5 CVE-2021-36370 An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked … Midnight Commander after 4.8.26 Fix from $1,9502021-08-30 CRITICAL 9.8 CVE-2021-32967 Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized… Diaenergie after 1.7.5 Fix from $2,3002021-08-30 HIGH 7.5 CVE-2021-22025 The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unaut… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 MEDIUM 6.5 CVE-2021-39165EPSS 10% Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearc… Cachet 2.3.18+ Fix from $1,6002021-08-26 HIGH 7.4 CVE-2021-29487 octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vuln… October 1.0.472 / 1.1.5+ Fix from $1,9502021-08-26 CRITICAL 9.1 CVE-2021-32648 KEVEPSS 90% octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an accoun… October 1.1.5+ Fix from $2,3002021-08-26 MEDIUM 5.5 CVE-2021-30867 The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access phot… Ipados 12.0.1 / 15.0+ Fix from $1,6002021-08-24 CRITICAL 9.8 CVE-2021-37597 WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation. Wp Cerber 8.9.3+ Fix from $2,3002021-08-19 MEDIUM 6.5 CVE-2021-39138 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup use… Parse Server 4.5.1+ Fix from $1,6002021-08-19 MEDIUM 5.4 CVE-2021-1561 A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow… Secure Email And Web Manager after 14.1 Fix from $1,6002021-08-18 CRITICAL 9.8 CVE-2021-24527EPSS 8% The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin o… Profile Builder 3.4.9+ Fix from $2,3002021-08-16 HIGH 7.1 CVE-2021-36949 Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability Azure Active Directory Connect 1.1.582.0+ Fix from $1,9502021-08-12 HIGH 8.8 CVE-2021-36921 AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An a… Application Insight Manager Mitigation only Fix from $1,9502021-08-12 HIGH 7.8 CVE-2021-27794 A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a us… Fabric Operating System 7.4.2h / 8.2.3a+ Fix from $1,9502021-08-12 MEDIUM 6.5 CVE-2021-3046 An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any o… Pan Os 8.1.19 / 9.0.14+ Fix from $1,6002021-08-11 HIGH 7.5 CVE-2021-37172 A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against con… Simatic S7 1200 Cpu Firmware after 13.0 Fix from $1,9502021-08-10 CRITICAL 9.8 CVE-2021-21564 Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentiall… Openmanage Enterprise 3.6.1+ Fix from $2,3002021-08-09 CRITICAL 9.8 CVE-2014-9320 SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privilege… Businessobjects Edge Patch available Fix from $2,3002021-08-09 MEDIUM 5.3 CVE-2021-20598 Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R0… R08sfcpu Firmware Mitigation only Fix from $1,6002021-08-06 HIGH 7.5 CVE-2021-37545 In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made. Teamcity 2021.1+ Fix from $1,9502021-08-06 HIGH 7.8 CVE-2021-32579 Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (wh… True Image Mitigation only Fix from $1,9502021-08-05 MEDIUM 5.3 CVE-2021-25445 Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Intern… Internet 14.2+ Fix from $1,6002021-08-05 HIGH 7.5 CVE-2020-16839 On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthentic… Dm Nvx Dir 80 Firmware Mitigation only Fix from $1,9502021-07-30 CRITICAL 10.0 CVE-2021-21538 Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated at… Idrac9 Firmware 4.40.10.00+ Fix from $2,3002021-07-29 HIGH 7.5 CVE-2021-32794 ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /… Archisteamfarm 5.1.2.4+ Fix from $1,9502021-07-26 MEDIUM 5.3 CVE-2020-21932 A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially auth… Cx2 Firmware No fix yet Fix from $1,6002021-07-21 HIGH 7.5 CVE-2021-34675 Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports. Nex Forms after 7.8.7 Fix from $1,9502021-07-19