Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2021-21403 In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacte… Kongchuanhujiao 1.3.21+ Fix from $2,3002021-03-26 MEDIUM 6.5 CVE-2021-3153 HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two… Terraform Enterprise after 202102-2 Fix from $1,6002021-03-26 HIGH 7.5 CVE-2021-25368 Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed. Cloud 4.7.0.3+ Fix from $1,9502021-03-25 HIGH 7.5 CVE-2021-22496 Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could caus… Access Manager 4.5.3.3+ Fix from $1,9502021-03-25 HIGH 7.2 CVE-2021-26070 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via… Data Center 8.13.3 / 8.14.1+ Fix from $1,9502021-03-22 CRITICAL 9.8 CVE-2021-24148 A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unaut… Mstore Api 3.2.0+ Fix from $2,3002021-03-18 CRITICAL 9.8 CVE-2021-22860 EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote atta… E Document System Mitigation only Fix from $2,3002021-03-17 HIGH 8.2 CVE-2021-21378 Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT… Envoy Patch available Fix from $1,9502021-03-11 HIGH 8.8 CVE-2020-35231 The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to by… Gs116e Firmware Mitigation only Fix from $1,9502021-03-10 MEDIUM 6.5 CVE-2020-27838EPSS 18% A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like cli… Keycloak 13.0.0+ Fix from $1,6002021-03-08 CRITICAL 9.8 CVE-2021-21335 In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a … Spnego Http Authentication Module 1.1.1+ Fix from $2,3002021-03-08 CRITICAL 9.8 CVE-2021-21329 RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF users with multi factor authentic… Ratcf 2021-02-26+ Fix from $2,3002021-03-08 CRITICAL 9.1 CVE-2020-28050 Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server. Manageengine Desktop Central 10.0.647+ Fix from $2,3002021-03-05 HIGH 8.2 CVE-2020-5148 SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential atta… Directory Services Connector 4.1.19+ Fix from $1,9502021-03-05 MEDIUM 5.3 CVE-2021-25347 Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is execu… Android No fix yet Fix from $1,6002021-03-04 HIGH 7.8 CVE-2021-25315 CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute a… Salt 3002.2+ Fix from $1,9502021-03-03 CRITICAL 9.8 CVE-2021-21513EPSS 6% Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration c… Openmanage Server Administrator 9.4.0.3 / 9.5.0.1+ Fix from $2,3002021-03-02 MEDIUM 5.3 CVE-2021-3332 WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password. Wps Hide Login No fix yet Fix from $1,6002021-03-01 CRITICAL 9.8 CVE-2021-25281EPSS 73% An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attac… Fedora 2015.8.10 / 2015.8.13+ Fix from $2,3002021-02-27 CRITICAL 9.1 CVE-2021-21308 PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an atta… Prestashop 1.7.7.2+ Fix from $2,3002021-02-26 MEDIUM 6.8 CVE-2020-26200 A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component… Endpoint Security 18.0.11.3+ Fix from $1,6002021-02-26 MEDIUM 5.9 CVE-2020-10254 An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview. Owncloud 10.4.0+ Fix from $1,6002021-02-19 HIGH 8.8 CVE-2021-22858 Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obt… Changjia Property Management System Mitigation only Fix from $1,9502021-02-17 MEDIUM 6.5 CVE-2020-27863 This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-2888A rou… Dva 2800 Firmware Mitigation only Fix from $1,6002021-02-12 HIGH 8.8 CVE-2020-27865 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 … Dap 1860 Firmware after 1.04b03 Fix from $1,9502021-02-12 HIGH 8.8 CVE-2020-27866EPSS 9% This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260,… Ac2100 Firmware 1.2.0.76+ Fix from $1,9502021-02-12 MEDIUM 6.5 CVE-2020-13185 Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to sp… Cloud Access Connector 18+ Fix from $1,6002021-02-11 CRITICAL 9.8 CVE-2021-21502 Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRI… Emc Powerscale Onefs Mitigation only Fix from $2,3002021-02-09 MEDIUM 5.5 CVE-2020-10048 A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verificatio… Simatic Pcs 7 7.5+ Fix from $1,6002021-02-09 MEDIUM 6.5 CVE-2021-26905 1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key. Scim Bridge 1.6.2+ Fix from $1,6002021-02-08