Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Airflow MEDIUM 5.3
CVE-2021-26697

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h…

Mitigation only
Fix from $1,600 2021-02-17
M\!dge Firmware MEDIUM 5.3
CVE-2021-20067

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication.

Mitigation only
Fix from $1,600 2021-02-16
Iview CRITICAL 9.8
CVE-2021-22652EPSS 37%

Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to ch…

Fix: 5.7.03.6112+
Fix from $2,300 2021-02-11
Emc Powerscale Onefs HIGH 7.8
CVE-2020-26192

Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISI_PRIV_LOGIN_CONSOLE or…

Mitigation only
Fix from $1,950 2021-02-09
Software Provisioning Manager HIGH 8.8
CVE-2021-21472

SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installati…

Mitigation only
Fix from $1,950 2021-02-09
Simatic Hmi Comfort Panels Firmware CRITICAL 9.8
CVE-2020-15798EPSS 5%

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Pane…

Fix: 16.0+
Fix from $2,300 2021-02-09
Epikur HIGH 7.8
CVE-2020-10537

An issue was discovered in Epikur before 20.1.1. A Glassfish 4.1 server with a default configuration is running on TCP port 4848. No password is requ…

Fix: 20.1.1+
Fix from $1,950 2021-02-05
Onetest Performance CRITICAL 9.8
CVE-2020-14245

HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a s…

Mitigation only
Fix from $2,300 2021-02-04
Pacsone Server CRITICAL 9.8
CVE-2020-29165

PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privi…

Fix: 7.1.1+
Fix from $2,300 2021-02-03
Mofi4500 4gxelte Firmware HIGH 7.5
CVE-2020-15834

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an …

Patch available
Fix from $1,950 2021-02-01
Mofi4500 4gxelte Firmware HIGH 7.5
CVE-2020-13856

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains…

Patch available
Fix from $1,950 2021-02-01
Htcondor HIGH 8.8
CVE-2021-25312

HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.

Fix: 8.9.11+
Fix from $1,950 2021-01-27
Insider Threat Management HIGH 7.8
CVE-2021-22159

Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent …

Fix: 7.4.3 / 7.5.4+
Fix from $1,950 2021-01-26
Newbee Mall CRITICAL 9.8
CVE-2020-23448

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication …

No fix yet
Fix from $2,300 2021-01-26
Security Identity Governance And Intelligence CRITICAL 9.8
CVE-2020-4958

IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity …

Mitigation only
Fix from $2,300 2021-01-21
Oaklouds Portal CRITICAL 9.8
CVE-2021-22850

HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.

Mitigation only
Fix from $2,300 2021-01-19
Finesse MEDIUM 6.1
CVE-2021-1246

Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerabilit…

Fix: 12.0+
Fix from $1,600 2021-01-13
Emui MEDIUM 5.3
CVE-2020-9143

There is a missing authentication vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability may lead to low-sensitive inf…

Mitigation only
Fix from $1,600 2021-01-13
Scalance X200 4pirt Firmware MEDIUM 6.5
CVE-2020-15799

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch fam…

Fix: 5.5.0+
Fix from $1,600 2021-01-12
Spectrum Protect Plus MEDIUM 5.3
CVE-2020-5022

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai…

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Crimson CRITICAL 9.1
CVE-2020-27285

The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authenti…

Mitigation only
Fix from $2,300 2021-01-06
Quiz And Survey Master CRITICAL 9.9
CVE-2020-35951EPSS 76%

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.…

Fix: 7.0.1+
Fix from $2,300 2021-01-01
Orion Platform CRITICAL 9.8
CVE-2020-10148 KEVEPSS 92%

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou…

Mitigation only
Fix from $2,300 2020-12-29
Imanager Neteco 6000 MEDIUM 6.5
CVE-2020-9208

There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authentication. Attackers without access…

Mitigation only
Fix from $1,600 2020-12-29
Urve CRITICAL 9.1
CVE-2020-29551

An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the …

No fix yet
Fix from $2,300 2020-12-23
Dsl2888a Firmware HIGH 7.5
CVE-2020-24580

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attack…

No fix yet
Fix from $1,950 2020-12-22
Plone CRITICAL 9.8
CVE-2020-35190

The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone d…

Fix: 4.3.18-alpine+
Fix from $2,300 2020-12-17
Drupal Docker Images CRITICAL 9.8
CVE-2020-35191

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker…

Fix: after 8.5.10-fpm-alpine
Fix from $2,300 2020-12-17
Vault CRITICAL 9.8
CVE-2020-35192

The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected…

Fix: 0.11.6+
Fix from $2,300 2020-12-17
Haproxy Docker Image CRITICAL 9.8
CVE-2020-35195

The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker c…

Fix: 1.8.18+
Fix from $2,300 2020-12-17