Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2020-27199 The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a … Magic Home Pro No fix yet Fix from $1,9502020-12-17 CRITICAL 9.8 CVE-2020-4747 IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper au… Connect\ Mitigation only Fix from $2,3002020-12-15 HIGH 7.5 CVE-2020-0460 In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This cou… Android Patch available Fix from $1,9502020-12-14 HIGH 8.2 CVE-2020-16102 Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid confi… Command Centre 7.90.0 / 8.00.1252+ Fix from $1,9502020-12-14 HIGH 8.8 CVE-2020-25183 Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Pati… Mycarelink Smart Model 25000 Firmware Mitigation only Fix from $1,9502020-12-14 HIGH 8.8 CVE-2020-29669 In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability whi… Wifisd2 2a82 Firmware No fix yet Fix from $1,9502020-12-14 MEDIUM 5.7 CVE-2020-35207 An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The PIN authentication for unl… Lastpass No fix yet Fix from $1,6002020-12-12 MEDIUM 5.7 CVE-2020-35208 An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The password authentication fo… Lastpass No fix yet Fix from $1,6002020-12-12 CRITICAL 9.8 CVE-2020-29563 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unau… My Cloud Os 5 5.07.118+ Fix from $2,3002020-12-12 HIGH 8.2 CVE-2020-7787 This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and re… React Adal Patch available Fix from $1,9502020-12-09 MEDIUM 5.4 CVE-2020-26834 SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possibl… Hana Database Mitigation only Fix from $1,6002020-12-09 HIGH 7.5 CVE-2020-27408 OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker … Opensis after 7.6 Fix from $1,9502020-12-04 CRITICAL 9.8 CVE-2020-7199EPSS 9% A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Softwar… Edgeline Infrastructure Manager 1.21+ Fix from $2,3002020-12-02 CRITICAL 9.8 CVE-2020-28971 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unau… My Cloud Os 5 5.06.115+ Fix from $2,3002020-12-01 CRITICAL 9.8 CVE-2020-28940 On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unau… My Cloud Os 5 5.06.115+ Fix from $2,3002020-12-01 CRITICAL 9.8 CVE-2020-28970 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unau… My Cloud Os 5 5.06.115+ Fix from $2,3002020-12-01 CRITICAL 9.8 CVE-2020-7533 CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sendin… Modicon M340 Bmxp3420302 Firmware 2.10 / 3.3+ Fix from $2,3002020-12-01 CRITICAL 9.8 CVE-2020-29127 An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web b… Eternus Storage Dx200 S4 Firmware after 2020-11-25 Fix from $2,3002020-11-30 HIGH 8.8 CVE-2020-29378 An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4… V1600d Firmware Mitigation only Fix from $1,9502020-11-29 CRITICAL 9.8 CVE-2020-28333 Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not u… Wepresent Wipg 1600w Firmware No fix yet Fix from $2,3002020-11-24 CRITICAL 9.1 CVE-2020-7378 CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to… Opencrx after 4.3.0 Fix from $2,3002020-11-24 MEDIUM 5.3 CVE-2020-28896 Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was inva… Debian Linux 2.0.2 / 2020-11-20+ Fix from $1,6002020-11-23 MEDIUM 5.3 CVE-2020-4771 IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive inform… Spectrum Protect Operations Center after 8.1.10 Fix from $1,6002020-11-23 HIGH 7.5 CVE-2020-26236 In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's account on any site that uses Sc… Scratchverifier Patch available Fix from $1,9502020-11-20 MEDIUM 5.3 CVE-2020-9049 A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated atta… C Cure Web after 5.6 Fix from $1,6002020-11-19 CRITICAL 9.8 CVE-2019-20933EPSS 31% InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may ha… Debian Linux 1.7.6+ Fix from $2,3002020-11-19 MEDIUM 6.5 CVE-2020-27558 Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream. Ge 131 Bt 1837836 Firmware No fix yet Fix from $1,6002020-11-17 HIGH 7.5 CVE-2020-8272 Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8 Sd Wan 10.2.8 / 11.1.2b+ Fix from $1,9502020-11-16 CRITICAL 9.8 CVE-2020-28638 ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be en… Tomb after 2.7 Fix from $2,3002020-11-13 HIGH 7.5 CVE-2020-25165 BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnera… Alaris 8015 Pcu Firmware after 9.33.1 Fix from $1,9502020-11-13