Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2019-19518 CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows… Ca Automic Sysload after 6.1.2 Fix from $2,3002020-01-08 HIGH 7.5 CVE-2019-20360 A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiabl… Givewp 2.5.5+ Fix from $1,9502020-01-08 CRITICAL 9.8 CVE-2013-5122 Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access Linksys Ea2700 Firmware No fix yet Fix from $2,3002020-01-07 HIGH 7.8 CVE-2019-6854 A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 … Clearscada Mitigation only Fix from $1,9502020-01-06 HIGH 7.5 CVE-2018-19831 The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change t… Cryptbond Network Mitigation only Fix from $1,9502019-12-31 HIGH 7.5 CVE-2018-19832 The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, allows attackers to change the… Newinteltechmedia Mitigation only Fix from $1,9502019-12-31 HIGH 7.5 CVE-2018-19833 The owned function of a smart contract implementation for DDQ, an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract… Ddq Mitigation only Fix from $1,9502019-12-31 HIGH 7.5 CVE-2018-19834 The quaker function of a smart contract implementation for BOMBBA (BOMB), an tradable Ethereum ERC20 token, allows attackers to change the owner of t… Bombba Mitigation only Fix from $1,9502019-12-31 MEDIUM 5.3 CVE-2018-20489 An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A… GitLab 11.4.13 / 11.5.6+ Fix from $1,6002019-12-30 CRITICAL 9.8 CVE-2013-4621 Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities Magnolia Cms 4.5.9+ Fix from $2,3002019-12-27 CRITICAL 9.8 CVE-2013-4976EPSS 36% Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials Ds 2cd7153 E Firmware No fix yet Fix from $2,3002019-12-27 CRITICAL 9.8 CVE-2013-4982EPSS 13% AVTECH AVN801 DVR has a security bypass via the administration login captcha Avn801 Dvr Firmware No fix yet Fix from $2,3002019-12-27 CRITICAL 9.8 CVE-2013-3085 An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2. F5d8236 4 Firmware No fix yet Fix from $2,3002019-12-26 CRITICAL 9.8 CVE-2013-3088 Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging". N900 Firmware Mitigation only Fix from $2,3002019-12-26 HIGH 8.8 CVE-2012-3462 A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event tha… Sssd Patch available Fix from $1,9502019-12-26 CRITICAL 9.8 CVE-2019-16327 D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-… Dir 601 Firmware No fix yet Fix from $2,3002019-12-26 MEDIUM 5.3 CVE-2019-19982 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit … Email Subscribers \& Newsletters 4.2.3+ Fix from $1,6002019-12-26 MEDIUM 6.5 CVE-2019-5108EPSS 10% An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by trig… Linux Kernel 5.3+ Fix from $1,6002019-12-23 HIGH 8.8 CVE-2019-5486 A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used… GitLab 12.1.10 / 12.2.6+ Fix from $1,9502019-12-18 MEDIUM 5.7 CVE-2019-8804 An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical prox… Ipados 13.2+ Fix from $1,6002019-12-18 MEDIUM 6.8 CVE-2019-8760 This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolle… Iphone Os 13.0+ Fix from $1,6002019-12-18 MEDIUM 5.5 CVE-2019-8704 An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user… Iphone Os 13 / 13.0+ Fix from $1,6002019-12-18 HIGH 8.8 CVE-2019-8634 An authentication issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5. A user may be unexpectedly logged … Mac Os X 10.12.6 / 10.13.6+ Fix from $1,9502019-12-18 HIGH 7.8 CVE-2019-8533 A lock handling issue was addressed with improved lock handling. This issue is fixed in macOS Mojave 10.14.4. A Mac may not lock when disconnecting f… Mac Os X 10.14.4+ Fix from $1,9502019-12-18 CRITICAL 9.8 CVE-2014-8650 python-requests-Kerberos through 0.5 does not handle mutual authentication Debian Linux after 0.5 Fix from $2,3002019-12-15 MEDIUM 5.9 CVE-2019-5253 E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does not perform a sufficient auth… E5572 855 Firmware 8.0.1.3+ Fix from $1,6002019-12-13 HIGH 7.8 CVE-2014-1867 suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution Suphp 0.7.2+ Fix from $1,9502019-12-13 MEDIUM 6.5 CVE-2019-5061 An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for statio… Hostapd Mitigation only Fix from $1,6002019-12-12 CRITICAL 9.8 CVE-2019-18337 A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authenticatio… Sinvr 3 Central Control Server Mitigation only Fix from $2,3002019-12-12 MEDIUM 5.3 CVE-2019-18341 A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Cen… Sinvr 3 Central Control Server Mitigation only Fix from $1,6002019-12-12