Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2020-16088 iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key mat… OpenBSD after 6.7 Fix from $2,3002020-07-28 CRITICAL 9.8 CVE-2020-12812 KEVEPSS 49% An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succe… Fortios 6.0.10 / 6.2.4+ Fix from $2,3002020-07-24 HIGH 8.8 CVE-2020-8207 Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic upd… Workspace Mitigation only Fix from $1,9502020-07-24 CRITICAL 9.8 CVE-2020-15921EPSS 18% Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as … Eframework after 2.9.0 Fix from $2,3002020-07-24 HIGH 7.5 CVE-2020-10918 This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen pa… C More Hmi Ea9 Firmware Mitigation only Fix from $1,9502020-07-23 MEDIUM 6.8 CVE-2020-12638 An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK dev… Esp Idf after 4.2 Fix from $1,6002020-07-23 HIGH 7.5 CVE-2020-15896 An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessi… Dap 1522 Firmware Patch available Fix from $1,9502020-07-22 CRITICAL 9.8 CVE-2020-6871 The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server a… R8500g4 Firmware Mitigation only Fix from $2,3002020-07-20 CRITICAL 9.8 CVE-2020-14485 OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a sessio… Openclinic Ga Mitigation only Fix from $2,3002020-07-20 CRITICAL 9.8 CVE-2020-14494 OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to prot… Openclinic Ga Mitigation only Fix from $2,3002020-07-20 MEDIUM 6.5 CVE-2020-9259 Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerability. The system does not su… Honor V30 Firmware 10.1.0.212+ Fix from $1,6002020-07-17 HIGH 7.8 CVE-2020-3388 A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands that are execut… Sd Wan Firmware 19.2.2 / 20.1.1+ Fix from $1,9502020-07-16 MEDIUM 5.3 CVE-2020-3197 A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Re… Meeting Server Mitigation only Fix from $1,6002020-07-16 CRITICAL 9.8 CVE-2020-3144 A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction … Rv110w Firmware 1.0.3.55 / 1.2.2.8+ Fix from $2,3002020-07-16 CRITICAL 9.8 CVE-2020-15027 ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attem… Automate 2019.12+ Fix from $2,3002020-07-16 CRITICAL 9.8 CVE-2020-10288 IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can inpu… Robotware Mitigation only Fix from $2,3002020-07-15 MEDIUM 6.5 CVE-2020-8193 KEVEPSS 88% Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW… Application Delivery Controller Firmware 10.2.7 / 10.5-70.18+ Fix from $1,6002020-07-10 MEDIUM 5.5 CVE-2020-1838 HUAWEI Mate 30 Pro with versions earlier than 10.1.0.150(C00E136R5P3) have is an improper authentication vulnerability. The device does not sufficien… Mate 30 Pro Firmware 10.1.0.150+ Fix from $1,6002020-07-06 CRITICAL 9.8 CVE-2020-4074 In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and e… Prestashop 1.7.6.6+ Fix from $2,3002020-07-02 CRITICAL 9.8 CVE-2020-3297 A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, … Sg250x 24 Firmware 2.5.5.47+ Fix from $2,3002020-07-02 CRITICAL 9.8 CVE-2020-14070 An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessable credentials to admin/execut… Mk Auth Mitigation only Fix from $2,3002020-06-29 MEDIUM 5.3 CVE-2019-20412 The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following in… Jira 7.13.9 / 8.4.2+ Fix from $1,6002020-06-29 HIGH 8.1 CVE-2017-18906 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody el… Mattermost Server 3.9.2 / 3.10.2+ Fix from $1,9502020-06-19 CRITICAL 9.8 CVE-2017-18908 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-ma… Mattermost Server 3.9.2 / 3.10.2+ Fix from $2,3002020-06-19 MEDIUM 5.3 CVE-2017-18919 An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation. Mattermost Server 3.6.3+ Fix from $1,6002020-06-19 MEDIUM 6.5 CVE-2016-11072 An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled. Mattermost Server 3.0.2+ Fix from $1,6002020-06-19 CRITICAL 9.8 CVE-2016-11074 An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused. Mattermost Server 3.0.0+ Fix from $2,3002020-06-19 HIGH 8.8 CVE-2018-21263 An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a craft… Mattermost Server 4.5.2 / 4.6.2+ Fix from $1,9502020-06-19 MEDIUM 5.3 CVE-2019-20875 An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is… Mattermost Server 4.10.8 / 5.7.3+ Fix from $1,6002020-06-19 MEDIUM 6.5 CVE-2020-14455 An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-20… Mattermost Desktop 4.4.0+ Fix from $1,6002020-06-19