Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2020-8591 eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. Eg Manager No fix yet Fix from $2,3002020-02-03 CRITICAL 9.8 CVE-2020-8510 An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang)… Phpabook Mitigation only Fix from $2,3002020-02-03 HIGH 7.5 CVE-2016-2032 A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called… Airwave 4.1.3.0 / 8.2.0.0+ Fix from $1,9502020-01-31 MEDIUM 6.1 CVE-2013-5114 LastPass prior to 2.5.1 allows secure wipe bypass. Lastpass 2.5.1+ Fix from $1,6002020-01-31 HIGH 7.1 CVE-2013-5116 Evernote prior to 5.5.1 has insecure password change Evernote 5.5.1+ Fix from $1,9502020-01-31 CRITICAL 10.0 CVE-2020-5206 In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that use… Opencast 7.6+ Fix from $2,3002020-01-30 CRITICAL 9.8 CVE-2013-3316 Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". Wnr1000 Firmware 1.0.2.60+ Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2013-3317 Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. Wnr1000 Firmware 1.0.2.60+ Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2013-3215EPSS 69% vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. Vtiger Crm after 5.4.0 Fix from $2,3002020-01-29 HIGH 7.5 CVE-2013-2569EPSS 31% A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could… F3105 Firmware after 1.6.03 Fix from $1,9502020-01-29 MEDIUM 5.3 CVE-2013-1600EPSS 19% An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_… Dcs 2102 Firmware No fix yet Fix from $1,6002020-01-28 CRITICAL 9.8 CVE-2013-3071 NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass. Wndr4700 Firmware No fix yet Fix from $2,3002020-01-28 HIGH 8.8 CVE-2013-4863EPSS 12% The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLu… Veralite Firmware No fix yet Fix from $1,9502020-01-28 CRITICAL 9.8 CVE-2019-15585 Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML … GitLab 12.1.12 / 12.2.6+ Fix from $2,3002020-01-28 CRITICAL 9.8 CVE-2019-19825EPSS 30% On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin… A3002ru Firmware after 4.0.0 Fix from $2,3002020-01-27 CRITICAL 9.1 CVE-2013-4462 WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability Portable Phpmyadmin No fix yet Fix from $2,3002020-01-27 HIGH 8.8 CVE-2020-5224 In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used t… Django User Sessions 1.7.1+ Fix from $1,9502020-01-24 MEDIUM 5.3 CVE-2013-1596EPSS 10% An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554. Pt7135 Firmware No fix yet Fix from $1,6002020-01-24 CRITICAL 9.8 CVE-2012-6451 Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability Lnc116 Firmware after 030312 Fix from $2,3002020-01-24 MEDIUM 5.5 CVE-2020-1788 Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not p… Honor V30 Firmware 10.0.1.135+ Fix from $1,6002020-01-21 MEDIUM 6.0 CVE-2020-1840 HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker wit… Mate 20 Firmware after 10.0.0.175 Fix from $1,6002020-01-21 MEDIUM 5.3 CVE-2020-7222 An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to … Web Server No fix yet Fix from $1,6002020-01-18 MEDIUM 6.5 CVE-2019-19857 An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the… Serpico Mitigation only Fix from $1,6002020-01-15 HIGH 7.5 CVE-2012-3824 In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization. Campaign Enterprise 11.0.551+ Fix from $1,9502020-01-10 CRITICAL 9.8 CVE-2014-5081EPSS 10% sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass Sphider 1.3.6 / 3.2+ Fix from $2,3002020-01-10 CRITICAL 9.8 CVE-2012-2714 The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via … Browserid Mitigation only Fix from $2,3002020-01-09 MEDIUM 6.5 CVE-2012-1258 cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow… Scrutinizer Netflow \& Sflow Analyzer 9.0.1.19899+ Fix from $1,6002020-01-09 MEDIUM 6.6 CVE-2020-1787 HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error u… Mate 20 Firmware 9.1.0.139+ Fix from $1,6002020-01-09 CRITICAL 9.8 CVE-2014-2651 Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface Openstage 80 Firmware Mitigation only Fix from $2,3002020-01-09 MEDIUM 6.5 CVE-2019-17023 After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS … Firefox 72.0+ Fix from $1,6002020-01-08