Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2020-25165 BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnera… Alaris 8015 Pcu Firmware after 9.33.1 Fix from $1,9502020-11-13 HIGH 8.2 CVE-2020-2050 An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to… Pan Os 8.1.17 / 9.0.11+ Fix from $1,9502020-11-12 CRITICAL 9.8 CVE-2020-26168 The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify p… Hazelcast 4.0.3+ Fix from $2,3002020-11-09 CRITICAL 9.8 CVE-2020-26542 An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjuncti… Percona Server after 2020-10-02 Fix from $2,3002020-11-09 MEDIUM 5.5 CVE-2020-23139 Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized … Microweber Mitigation only Fix from $1,6002020-11-09 CRITICAL 9.8 CVE-2020-26214EPSS 66% In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to … Alerta 7.5.7 / 8.1.0+ Fix from $2,3002020-11-06 CRITICAL 9.8 CVE-2020-25592EPSS 58% In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH. Debian Linux 2015.8.10 / 2015.8.13+ Fix from $2,3002020-11-06 CRITICAL 9.8 CVE-2020-17510EPSS 9% Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. Shiro 1.7.0+ Fix from $2,3002020-11-05 MEDIUM 5.3 CVE-2020-8267 A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token… Unifi Protect Firmware after 1.14.10 Fix from $1,6002020-11-05 CRITICAL 9.8 CVE-2020-12145EPSS 6% Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This m… Unity Orchestrator 8.9.11 / 8.10.11+ Fix from $2,3002020-11-05 HIGH 7.5 CVE-2020-15949 Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover. Immuta No fix yet Fix from $1,9502020-11-05 MEDIUM 6.8 CVE-2020-8236 A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking… Nextcloud Server 19.0.2+ Fix from $1,6002020-11-02 MEDIUM 5.3 CVE-2020-28002 In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login opt… Sonarqube No fix yet Fix from $1,6002020-11-02 HIGH 7.9 CVE-2020-5425 Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user imper… Single Sign On For Tanzu 1.11.3 / 1.12.4+ Fix from $1,9502020-10-31 CRITICAL 9.8 CVE-2020-7197 SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web appl… Storeserv Management Console 3.7.1.1+ Fix from $2,3002020-10-26 HIGH 7.8 CVE-2020-24848 FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local p… Fruitywifi after 2.4 Fix from $1,9502020-10-23 MEDIUM 5.8 CVE-2020-3565 A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t… Secure Firewall Threat Defense 6.4.0.8 / 6.5.0.4+ Fix from $1,6002020-10-21 HIGH 8.1 CVE-2020-3410 A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthentic… Secure Firewall Management Center Mitigation only Fix from $1,9502020-10-21 CRITICAL 9.1 CVE-2020-15240 omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Imp… Omniauth Auth0 2.4.1+ Fix from $2,3002020-10-21 CRITICAL 9.1 CVE-2020-15269 In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in v… Spree 3.7.11 / 4.0.4+ Fix from $2,3002020-10-20 CRITICAL 9.8 CVE-2020-24629 A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC P… Intelligent Management Center 7.3+ Fix from $2,3002020-10-19 MEDIUM 6.5 CVE-2020-14299 A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox Secur… Jboss Enterprise Application Platform 5.0.3+ Fix from $1,6002020-10-16 HIGH 8.8 CVE-2020-7591 A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to i… Siport Mp 3.2.1+ Fix from $1,9502020-10-15 HIGH 8.8 CVE-2020-8350 An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of … Thinkpad Stack Wireless Router Firmware after 1.1.3.4 Fix from $1,9502020-10-14 HIGH 8.1 CVE-2020-4779 A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attac… Curam Social Program Management Mitigation only Fix from $1,9502020-10-12 HIGH 8.8 CVE-2020-26921 Certain NETGEAR devices are affected by authentication bypass. This affects GS110EMX before 1.0.1.7, GS810EMX before 1.7.1.3, XS512EM before 1.0.1.3,… Gs110emx Firmware 1.0.1.3 / 1.0.1.7+ Fix from $1,9502020-10-09 CRITICAL 9.8 CVE-2020-15243 Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 … Smartstore Mitigation only Fix from $2,3002020-10-08 HIGH 7.5 CVE-2020-10816 Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor … Manageengine Applications Manager Mitigation only Fix from $1,9502020-10-08 MEDIUM 5.3 CVE-2020-25867 SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentica… Soplanning 1.47+ Fix from $1,6002020-10-07 CRITICAL 9.8 CVE-2020-12126 Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router s… Wn530h4 Firmware Mitigation only Fix from $2,3002020-10-02