Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2020-26511 The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass. Wordpress \+ Azure Ad \/ Microsoft Office 365 11.7+ Fix from $1,9502020-10-02 HIGH 7.5 CVE-2020-26160 jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by … Jwt Go after 3.2.0 Fix from $1,9502020-09-30 HIGH 7.5 CVE-2018-11765EPSS 5% In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerbe… Hadoop after 2.9.2 Fix from $1,9502020-09-30 HIGH 7.8 CVE-2020-24563 A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), whi… Apex One Mitigation only Fix from $1,9502020-09-29 CRITICAL 9.8 CVE-2020-26105 In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554). Cpanel 88.0.3+ Fix from $2,3002020-09-25 CRITICAL 9.8 CVE-2020-26101 In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549). Cpanel 88.0.3+ Fix from $2,3002020-09-25 HIGH 8.1 CVE-2020-15222 In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the un… Fosite 0.31.0+ Fix from $1,9502020-09-24 CRITICAL 9.8 CVE-2019-16028 A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to b… Secure Firewall Management Center 6.2.3.16 / 6.3.0.6+ Fix from $2,3002020-09-23 MEDIUM 5.3 CVE-2019-15993EPSS 10% A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information… Sg250x 24 Firmware 2.5.0.92+ Fix from $1,6002020-09-23 HIGH 7.5 CVE-2020-8253 Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before R… Xenmobile Server after 10.8.0 Fix from $1,9502020-09-18 MEDIUM 6.5 CVE-2020-8200 Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory doma… Storefront Server 3.0.8001 / 3.12.5001+ Fix from $1,6002020-09-18 MEDIUM 5.7 CVE-2020-7297 Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard … Web Gateway 7.8.2.22 / 8.2.9+ Fix from $1,6002020-09-16 CRITICAL 9.0 CVE-2020-7293 Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change… Web Gateway 7.8.2.23 / 8.2.11+ Fix from $2,3002020-09-15 MEDIUM 5.7 CVE-2020-7296 Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configurat… Web Gateway 7.8.2.23 / 8.2.11+ Fix from $1,6002020-09-15 CRITICAL 9.8 CVE-2020-16098 It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior… Command Centre 8.00.1228 / 8.10.1211+ Fix from $2,3002020-09-15 MEDIUM 6.5 CVE-2020-13303 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized use… GitLab 13.1.10 / 13.2.8+ Fix from $1,6002020-09-15 MEDIUM 5.9 CVE-2020-15802EPSS 7% Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specific… Bluetooth Core Specification 5.1+ Fix from $1,6002020-09-11 HIGH 8.8 CVE-2020-16222 In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a g… Patient Information Center Ix No fix yet Fix from $1,9502020-09-11 CRITICAL 9.1 CVE-2020-25251 An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and … Onbase after 20.3.10.1000 Fix from $2,3002020-09-11 CRITICAL 9.8 CVE-2020-15787 A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authenticat… Simatic Hmi United Comfort Panels Firmware Mitigation only Fix from $2,3002020-09-09 MEDIUM 6.9 CVE-2020-7323 Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical lo… Endpoint Security 10.7.0+ Fix from $1,6002020-09-09 HIGH 7.8 CVE-2019-10562 u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into se… Ipq6018 Firmware Mitigation only Fix from $1,9502020-09-08 CRITICAL 9.8 CVE-2020-24987 Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authenticati… Ac18 Firmware Mitigation only Fix from $2,3002020-09-04 CRITICAL 9.8 CVE-2020-24029 Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple reque… Qualiex Mitigation only Fix from $2,3002020-09-02 CRITICAL 9.8 CVE-2020-5777EPSS 23% MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database … Magmi 0.7.24+ Fix from $2,3002020-09-01 CRITICAL 9.8 CVE-2020-24786EPSS 13% An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo… Manageengine Adselfservice Plus after 12.1.2 Fix from $2,3002020-08-31 HIGH 7.8 CVE-2020-8097 An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivile… Endpoint Security 6.6.18.261+ Fix from $1,9502020-08-30 CRITICAL 10.0 CVE-2020-15164 in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repea… Scratch Login 1.1+ Fix from $2,3002020-08-28 HIGH 8.1 CVE-2020-15601 If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated … Deep Security Manager Patch available Fix from $1,9502020-08-27 HIGH 8.1 CVE-2020-15605 If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthe… Deep Security Manager Patch available Fix from $1,9502020-08-27