Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Operation Bridge Reporter CRITICAL 9.8
CVE-2020-11856EPSS 5%

Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow r…

Fix: after 10.40
Fix from $2,300 2020-09-22
Horizon Daas MEDIUM 6.5
CVE-2020-3977

VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first …

Fix: after 8.0.1
Fix from $1,600 2020-09-22
P1 Firmware CRITICAL 9.8
CVE-2020-23512

VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) with…

No fix yet
Fix from $2,300 2020-09-15
Command Centre CRITICAL 9.8
CVE-2020-16098

It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior…

Fix: 8.00.1228 / 8.10.1211+
Fix from $2,300 2020-09-15
GitLab MEDIUM 5.4
CVE-2020-13289

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA …

Fix: 13.1.10 / 13.2.8+
Fix from $1,600 2020-09-14
Activemq MEDIUM 5.9
CVE-2020-13920

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to con…

Fix: 5.15.12+
Fix from $1,600 2020-09-10
Email Subscribers \& Newsletters MEDIUM 5.3
CVE-2020-5780

Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, …

Fix: 4.5.6+
Fix from $1,600 2020-09-10
Phpkb HIGH 7.5
CVE-2020-11579EPSS 26%

An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unau…

No fix yet
Fix from $1,950 2020-09-03
Teamwire MEDIUM 6.1
CVE-2020-12621

The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component.

No fix yet
Fix from $1,600 2020-09-02
Givewp MEDIUM 5.3
CVE-2020-20627

The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

Fix: after 2.5.9
Fix from $1,600 2020-08-31
Tl Wa855re Firmware HIGH 8.8
CVE-2020-24363 KEVEPSS 21%

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a fac…

Fix: 200731+
Fix from $1,950 2020-08-31
Security Guardium HIGH 7.5
CVE-2018-1501

IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-F…

Patch available
Fix from $1,950 2020-08-26
M1000 Multipara Patient Monitor Firmware MEDIUM 6.8
CVE-2020-15483

An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, wit…

No fix yet
Fix from $1,600 2020-08-26
Probase MEDIUM 5.3
CVE-2020-9062

Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages betwe…

Mitigation only
Fix from $1,600 2020-08-21
Aptra Xfs HIGH 7.1
CVE-2020-10124

NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer,…

Mitigation only
Fix from $1,950 2020-08-21
Exvf5c 2 Firmware CRITICAL 9.8
CVE-2020-24051

The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authenticatio…

No fix yet
Fix from $2,300 2020-08-21
Cyber Vision Center MEDIUM 5.8
CVE-2020-3448

A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authen…

Fix: 3.0.4+
Fix from $1,600 2020-08-17
Koala Firmware HIGH 7.5
CVE-2020-17475

Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet dat…

Mitigation only
Fix from $1,950 2020-08-14
Fortios MEDIUM 6.5
CVE-2019-5591 KEVEPSS 18%

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by imper…

Fix: after 6.2.0
Fix from $1,600 2020-08-14
Vpncrypt M10 Firmware CRITICAL 9.8
CVE-2020-12106

The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative fun…

Mitigation only
Fix from $2,300 2020-08-12
Businessobjects Business Intelligence Platform CRITICAL 9.1
CVE-2020-6294

Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for fun…

Mitigation only
Fix from $2,300 2020-08-12
Netweaver Application Server Java HIGH 7.5
CVE-2020-6309

SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authent…

Mitigation only
Fix from $1,950 2020-08-12
Launcher Os CRITICAL 9.1
CVE-2020-16167

Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and an…

Fix: after 13146
Fix from $2,300 2020-08-07
Etcd MEDIUM 6.5
CVE-2020-15136

In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gatew…

Fix: 3.3.23 / 3.4.10+
Fix from $1,600 2020-08-06
Contour HIGH 7.5
CVE-2020-15127

In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entir…

Fix: 1.7.0+
Fix from $1,950 2020-08-05
Data Center Network Manager MEDIUM 5.3
CVE-2020-3461

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …

Fix: 11.4+
Fix from $1,600 2020-07-31
Data Center Network Manager CRITICAL 9.8
CVE-2020-3376

A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypa…

Mitigation only
Fix from $2,300 2020-07-31
Package Analytics CRITICAL 9.8
CVE-2020-2076

SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST …

Fix: after 04.0.0
Fix from $2,300 2020-07-29
Devspace CRITICAL 9.8
CVE-2020-15391

The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket p…

Patch available
Fix from $2,300 2020-07-23
C More Hmi Ea9 Firmware CRITICAL 9.8
CVE-2020-10920

This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen p…

Mitigation only
Fix from $2,300 2020-07-23