Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Iot Field Network Director CRITICAL 9.8
CVE-2020-3531

A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end data…

Fix: 4.6.1+
Fix from $2,300 2020-11-18
Iot Field Network Director HIGH 7.5
CVE-2020-3392

A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on…

Fix: 4.6.1+
Fix from $1,950 2020-11-18
Solution Manager CRITICAL 10.0
CVE-2020-26821

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Solution Manager CRITICAL 10.0
CVE-2020-26822

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Solution Manager CRITICAL 10.0
CVE-2020-26823

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Solution Manager CRITICAL 10.0
CVE-2020-26824

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Airflow CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…

Fix: 1.10.11+
Fix from $2,300 2020-11-10
Interscan Messaging Security Virtual Appliance MEDIUM 5.5
CVE-2020-27019EPSS 18%

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an …

Fix: after 9.1
Fix from $1,600 2020-11-09
Visual Components Network License Server HIGH 7.5
CVE-2020-10291

Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making …

Mitigation only
Fix from $1,950 2020-11-06
Airwave Glass CRITICAL 9.8
CVE-2020-7128

A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

Fix: 1.3.2+
Fix from $2,300 2020-11-04
Sonarqube HIGH 7.5
CVE-2020-27986EPSS 16%

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reported…

Mitigation only
Fix from $1,950 2020-10-28
Spectra HIGH 7.5
CVE-2020-25966

Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentic…

Fix: 3.4.0+
Fix from $1,950 2020-10-28
Atomxcms 2 HIGH 8.1
CVE-2020-26649

AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php

No fix yet
Fix from $1,950 2020-10-22
Hadoop HIGH 8.8
CVE-2018-11764

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even …

Mitigation only
Fix from $1,950 2020-10-21
Es7510 Xt Firmware CRITICAL 9.8
CVE-2020-12500

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…

No fix yet
Fix from $2,300 2020-10-15
Smartstore CRITICAL 9.8
CVE-2020-15243

Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 …

Mitigation only
Fix from $2,300 2020-10-08
Dsr 250n Firmware MEDIUM 5.5
CVE-2020-26567EPSS 17%

An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any a…

Fix: 3.17b+
Fix from $1,600 2020-10-08
Vision Dynamic Signage Director MEDIUM 6.5
CVE-2020-3598

A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to acc…

Fix: 6.2.0+
Fix from $1,600 2020-10-08
Wp Courses HIGH 7.5
CVE-2020-26876EPSS 11%

The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by u…

Fix: after 2.0.27
Fix from $1,950 2020-10-07
Android MEDIUM 5.3
CVE-2020-26599

An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can be accepted without authentic…

Mitigation only
Fix from $1,600 2020-10-06
Iptv\/h.264 Video Encoder Firmware CRITICAL 9.8
CVE-2020-24217EPSS 40%

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authenti…

No fix yet
Fix from $2,300 2020-10-06
Zxone 19700 Snpe Firmware CRITICAL 9.8
CVE-2020-6875

A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attacke…

Mitigation only
Fix from $2,300 2020-10-05
Passwordstate HIGH 7.5
CVE-2020-26061

ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword functio…

Fix: 8.5+
Fix from $1,950 2020-10-05
Wn530h4 Firmware HIGH 7.5
CVE-2020-12127EPSS 7%

An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to…

Mitigation only
Fix from $1,950 2020-10-02
Nifi HIGH 7.5
CVE-2020-9487

In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to c…

Fix: after 1.11.4
Fix from $1,950 2020-10-01
750 852 Firmware HIGH 8.2
CVE-2020-12505

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without aut…

Mitigation only
Fix from $1,950 2020-09-30
750 362 Firmware CRITICAL 9.1
CVE-2020-12506

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by send…

Mitigation only
Fix from $2,300 2020-09-30
Rv 3406 Firmware CRITICAL 9.4
CVE-2020-25747

The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP…

Mitigation only
Fix from $2,300 2020-09-25
Backup \& Replication Transporter CRITICAL 9.8
CVE-2020-15851

Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories …

No fix yet
Fix from $2,300 2020-09-24
Vision Dynamic Signage Director MEDIUM 6.5
CVE-2019-16004

A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentic…

Fix: 6.2.0+
Fix from $1,600 2020-09-23