Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2020-10888 This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 router… Ac1750 Firmware Mitigation only Fix from $2,3002020-03-25 HIGH 7.5 CVE-2019-20618 An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allows unauthenticated unpinning of an app. The Samsun… Android Mitigation only Fix from $1,9502020-03-24 HIGH 7.5 CVE-2019-20620 An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application allows unauthenticated changes. The Samsung IDs are … Android Mitigation only Fix from $1,9502020-03-24 HIGH 7.5 CVE-2019-20565 An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can change the USB configuration without authentication.… Android Mitigation only Fix from $1,9502020-03-24 MEDIUM 5.5 CVE-2020-10846 An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devi… Android Mitigation only Fix from $1,6002020-03-24 MEDIUM 6.8 CVE-2020-10847 An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SV… Android Mitigation only Fix from $1,6002020-03-24 HIGH 8.8 CVE-2020-8863EPSS 77% This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 route… Dir 878 Firmware after 1.20b03 Fix from $1,9502020-03-23 HIGH 8.1 CVE-2020-1864 Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain some information and forge the p… Secospace Antiddos8000 Firmware Mitigation only Fix from $1,9502020-03-20 MEDIUM 5.5 CVE-2020-1878 Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper a… Oxfords An00a Firmware 10.0.1.152d / 10.0.1.160+ Fix from $1,6002020-03-20 HIGH 7.5 CVE-2020-10669 The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthent… Oce Colorwave 500 Firmware No fix yet Fix from $1,9502020-03-19 MEDIUM 6.3 CVE-2020-4205 IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the ser… Datapower Gateway after 2018.4.1.8 Fix from $1,6002020-03-19 HIGH 7.5 CVE-2020-6988 Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix… Micrologix 1400 A Firmware after 21.001 Fix from $1,9502020-03-16 MEDIUM 6.5 CVE-2018-13060 Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue. Easy\!appointments 1.2.1+ Fix from $1,6002020-03-16 CRITICAL 9.1 CVE-2020-10594 An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working t… Django Rest Framework Json Web Tokens 1.15.1+ Fix from $2,3002020-03-15 MEDIUM 5.5 CVE-2020-9064 Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentication vulnerability. Authentic… Honor V30 Firmware Mitigation only Fix from $1,6002020-03-12 MEDIUM 6.8 CVE-2020-8994 An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then th… Mdz 25 Dt Firmware No fix yet Fix from $1,6002020-03-05 MEDIUM 5.3 CVE-2020-8664 CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) acros… Envoy after 1.13.0 Fix from $1,6002020-03-04 HIGH 8.8 CVE-2020-5536 OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentication and to initialize the de… Openblocks Iot Vx2 Firmware 4.0.0+ Fix from $1,9502020-03-04 HIGH 7.5 CVE-2018-15819 EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js. Easyio 30p Firmware 2.0.5.27+ Fix from $1,9502020-03-02 CRITICAL 9.8 CVE-2019-20489 An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other proble… Wnr1000 Firmware Mitigation only Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2020-3923 DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET, contain misconfigured authentication mechanism. Attackers can crack the def… Tat 77104g1 Firmware after 20181221_76216g3 Fix from $2,3002020-02-27 HIGH 7.2 CVE-2019-5165 An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configu… Awk 3131a Firmware No fix yet Fix from $1,9502020-02-25 CRITICAL 9.8 CVE-2018-14705 In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing th… 5n2 Firmware Mitigation only Fix from $2,3002020-02-24 CRITICAL 9.8 CVE-2019-20481 In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in … Xgw 3000 Zigbee Gateway Firmware 2.4.0+ Fix from $2,3002020-02-24 HIGH 8.8 CVE-2019-15299 An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the… Centreon Web after 19.04.3 Fix from $1,9502020-02-24 HIGH 8.8 CVE-2020-8861EPSS 7% This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range e… Dap 1330 Firmware 1.10b01+ Fix from $1,9502020-02-22 HIGH 8.8 CVE-2020-8862EPSS 13% This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 router… Dap 2610 Firmware after 2.01rc067 Fix from $1,9502020-02-22 HIGH 8.6 CVE-2020-3944 vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authenti… Vrealize Operations 6.6.1 / 6.7.1+ Fix from $1,9502020-02-19 HIGH 7.5 CVE-2011-2054 A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Seconda… Asa 5500 Firmware Mitigation only Fix from $1,9502020-02-19 CRITICAL 9.8 CVE-2014-3879 OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, whi… FreeBSD after 9.2 Fix from $2,3002020-02-18