Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.8 CVE-2021-25424 Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the us… Galaxy Watch Active 2 Firmware 5.5+ Fix from $1,9502021-06-11 MEDIUM 6.1 CVE-2021-25389 Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication. Android Mitigation only Fix from $1,6002021-06-11 MEDIUM 6.8 CVE-2021-34546 An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button … Netsetman 5.0+ Fix from $1,6002021-06-10 MEDIUM 6.8 CVE-2020-24514 Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physic… Realsense Id F450 Firmware Mitigation only Fix from $1,6002021-06-09 CRITICAL 9.1 CVE-2021-23847 A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or chang… Cpp6 Firmware 7.80.0129+ Fix from $2,3002021-06-09 MEDIUM 6.5 CVE-2020-26136 In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication. Silverstripe 4.6.0+ Fix from $1,6002021-06-08 CRITICAL 9.8 CVE-2021-31251EPSS 36% An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining … Bf 430 Firmware No fix yet Fix from $2,3002021-06-04 MEDIUM 5.3 CVE-2020-15077 OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers config… Openvpn Access Server after 2.8.7 Fix from $1,6002021-06-04 HIGH 7.5 CVE-2020-14380 An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authen… Satellite Mitigation only Fix from $1,9502021-06-02 MEDIUM 5.3 CVE-2021-3424 A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself… Single Sign On Mitigation only Fix from $1,6002021-06-01 HIGH 7.3 CVE-2021-32646 Roomer is a discord bot cog (extension) which provides automatic voice channel generation as well as private voice and text channels. A vulnerability… Dav Cogs 1.0.1+ Fix from $1,9502021-05-28 CRITICAL 10.0 CVE-2021-32637 Authelia is a a single sign-on multi-factor portal for web apps. This affects uses who are using nginx ngx_http_auth_request_module with Authelia, it… Authelia 4.25.1 / 4.29.3+ Fix from $2,3002021-05-28 MEDIUM 6.5 CVE-2021-20278 An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is e… Kiali 1.31.0+ Fix from $1,6002021-05-28 MEDIUM 5.3 CVE-2021-32541 The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows remote unauthenticated attac… Cts Web 2021.3.24+ Fix from $1,6002021-05-28 MEDIUM 5.4 CVE-2021-32543 The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies … Cts Web 2021.3.24+ Fix from $1,6002021-05-28 HIGH 7.1 CVE-2020-10709 A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authen… Ansible Tower 3.5.6 / 3.6.4+ Fix from $1,9502021-05-27 MEDIUM 5.3 CVE-2018-16496 In Versa Director, the un-authentication request found. Versa Director Mitigation only Fix from $1,6002021-05-26 MEDIUM 6.8 CVE-2021-31924 Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass… Fedora 1.1.1+ Fix from $1,6002021-05-26 HIGH 7.5 CVE-2020-26557 Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisionin… Mesh Profile Mitigation only Fix from $1,9502021-05-24 HIGH 7.5 CVE-2002-2438 TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linu… Linux Kernel 2.4.20+ Fix from $1,9502021-05-18 CRITICAL 9.8 CVE-2021-27734 Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of… Hirschmann Hios 08.6.00+ Fix from $2,3002021-05-17 HIGH 7.5 CVE-2021-29047 The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is… Dxp 7.3+ Fix from $1,9502021-05-16 HIGH 8.8 CVE-2021-22155 An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10… Workspaces Server after 9.1 Fix from $1,9502021-05-13 MEDIUM 5.3 CVE-2020-26139EPSS 6% An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet s… Debian Linux Patch available Fix from $1,6002021-05-11 CRITICAL 9.8 CVE-2021-23008 On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM… Big Ip Access Policy Manager 11.6.5 / 12.1.5+ Fix from $2,3002021-05-10 HIGH 8.1 CVE-2021-31520 A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently l… Im Security Patch available Fix from $1,9502021-05-10 HIGH 8.8 CVE-2021-26077 Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Sp… Connect Spring Boot 2.1.3 / 2.1.5+ Fix from $1,9502021-05-10 CRITICAL 9.8 CVE-2021-28152EPSS 5% Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on por… H8922 Firmware No fix yet Fix from $2,3002021-05-06 CRITICAL 9.8 CVE-2021-32030 KEVEPSS 99% The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass … Lyra Mini Firmware 3.0.0.4.384.46630 / 3.0.0.4.386.42643+ Fix from $2,3002021-05-06 MEDIUM 5.9 CVE-2021-31245 omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent man… Openmptcprouter after 0.57.3 Fix from $1,6002021-05-06