Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2020-10539 An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted … Epikur 20.1.1+ Fix from $2,3002021-02-05 CRITICAL 9.8 CVE-2020-17523EPSS 86% Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. Shiro 1.7.1+ Fix from $2,3002021-02-03 HIGH 7.5 CVE-2021-3282 HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication… Vault Mitigation only Fix from $1,9502021-02-01 CRITICAL 9.8 CVE-2020-15835 An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the … Mofi4500 4gxelte Firmware Patch available Fix from $2,3002021-02-01 CRITICAL 9.8 CVE-2020-13859 An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - Ope… Mofi4500 4gxelte Firmware Patch available Fix from $2,3002021-02-01 MEDIUM 6.5 CVE-2021-25910 Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in… 4cct Ea6 334126bf Firmware Mitigation only Fix from $1,6002021-01-29 HIGH 7.5 CVE-2021-26117EPSS 11% The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior… Activemq 2.16.0 / 5.15.14+ Fix from $1,9502021-01-27 HIGH 7.8 CVE-2021-3297EPSS 21% On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access. Nbg2105 Firmware No fix yet Fix from $1,9502021-01-26 HIGH 8.8 CVE-2021-25863 Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account. Open5gs No fix yet Fix from $1,9502021-01-26 HIGH 7.5 CVE-2020-28874 reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not proper… Projectsend Patch available Fix from $1,9502021-01-26 HIGH 7.8 CVE-2020-4983 IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitr… Spectrum Lsf Patch available Fix from $1,9502021-01-20 MEDIUM 6.5 CVE-2020-27266 In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and A… Anydana A Firmware 3.0+ Fix from $1,6002021-01-19 HIGH 7.5 CVE-2020-24641 In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully ex… Airwave Glass 1.3.3+ Fix from $1,9502021-01-15 MEDIUM 6.5 CVE-2021-22171 Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click … GitLab 13.5.6 / 13.6.4+ Fix from $1,6002021-01-15 CRITICAL 9.8 CVE-2020-27488 Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the … Miniserver Gen 1 Firmware 11.1.9.3+ Fix from $2,3002021-01-13 HIGH 7.5 CVE-2020-5686 Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker … Univerge Sv9500 Firmware Mitigation only Fix from $1,9502021-01-13 CRITICAL 9.8 CVE-2020-5633 Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Expr… Baseboard Management Controller after 1.09 Fix from $2,3002021-01-13 MEDIUM 5.5 CVE-2021-1725 Bot Framework SDK Information Disclosure Vulnerability Bot Framework Software Development Kit No fix yet Fix from $1,6002021-01-12 HIGH 7.5 CVE-2020-36176 The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing acco… Ithemes Security 7.7.0+ Fix from $1,9502021-01-06 CRITICAL 9.8 CVE-2012-10001 The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attacker… Limit Login Attempts 1.7.1+ Fix from $2,3002021-01-06 CRITICAL 9.8 CVE-2020-35219 The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication vi… Dsl N17u Firmware Mitigation only Fix from $2,3002021-01-04 CRITICAL 9.8 CVE-2020-25848 HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism. Msr45 Isherlock Antispam 4.5-114 / 4.5-122+ Fix from $2,3002020-12-31 HIGH 8.8 CVE-2020-35785 NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-2020-0365). Dgn2200 Firmware 1.0.0.60+ Fix from $1,9502020-12-30 HIGH 7.8 CVE-2020-9207 There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. A… Cloudengine 12800 Firmware No fix yet Fix from $1,9502020-12-29 CRITICAL 9.8 CVE-2020-26030 An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configure… Zammad 3.4.1+ Fix from $2,3002020-12-28 CRITICAL 9.8 CVE-2020-24675 In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ H… Symphony \+ Historian Mitigation only Fix from $2,3002020-12-22 HIGH 8.8 CVE-2020-24579EPSS 10% An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authenticati… Dsl2888a Firmware No fix yet Fix from $1,9502020-12-22 HIGH 7.5 CVE-2020-27254 Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper aut… X Stream Enhanced Xegp Firmware Mitigation only Fix from $1,9502020-12-21 CRITICAL 9.8 CVE-2020-27780 A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM… Linux Pam 1.5.1+ Fix from $2,3002020-12-18 CRITICAL 9.8 CVE-2020-8465 A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combinat… Interscan Web Security Virtual Appliance No fix yet Fix from $2,3002020-12-17