Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Clearpass Policy Manager CRITICAL 9.8
CVE-2020-7115EPSS 65%

The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker cou…

Fix: 6.8.6 / 6.9.1+
Fix from $2,300 2020-06-03
Rt430 Firmware CRITICAL 9.8
CVE-2020-12017

GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application …

Fix: 08a05+
Fix from $2,300 2020-06-02
Quickbox HIGH 7.2
CVE-2020-13695

In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root withou…

Fix: after 2.5.5
Fix from $1,950 2020-06-01
Couchdb CRITICAL 9.8
CVE-2020-1955

CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…

Mitigation only
Fix from $2,300 2020-05-20
Dap 1360 Revision F Firmware CRITICAL 9.8
CVE-2019-18666

An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented …

Fix: after 6.12b01
Fix from $2,300 2020-05-15
Aptare HIGH 7.5
CVE-2020-12877

Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication.

Fix: 10.4+
Fix from $1,950 2020-05-14
Businessobjects Business Intelligence Platform CRITICAL 9.8
CVE-2020-6242

SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central…

Mitigation only
Fix from $2,300 2020-05-12
Iplanet Web Server HIGH 7.5
CVE-2020-9315EPSS 82%

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administratio…

Fix: after 7.0.27
Fix from $1,950 2020-05-10
Vbulletin CRITICAL 9.8
CVE-2020-12720EPSS 89%

vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

Fix: 5.5.6+
Fix from $2,300 2020-05-08
Wn530hg4 Firmware HIGH 7.5
CVE-2020-10972

An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentic…

Mitigation only
Fix from $1,950 2020-05-07
Wn530hg4 Firmware HIGH 7.5
CVE-2020-10973EPSS 8%

An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a cr…

Mitigation only
Fix from $1,950 2020-05-07
Wl Wn575a3 Firmware HIGH 7.5
CVE-2020-10974

An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, includi…

Mitigation only
Fix from $1,950 2020-05-07
Nport 5100a Firmware MEDIUM 5.3
CVE-2020-12117

Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration values via a crafted packet to U…

Fix: after 1.5
Fix from $1,600 2020-05-01
WordPress HIGH 7.5
CVE-2020-11028

In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of…

Fix: 5.4.1+
Fix from $1,950 2020-04-30
Microscada Pro Sys600 CRITICAL 9.8
CVE-2019-5620EPSS 70%

ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.

No fix yet
Fix from $2,300 2020-04-29
Teampass HIGH 7.5
CVE-2020-12478EPSS 8%

TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.

No fix yet
Fix from $1,950 2020-04-29
Ignition Gateway HIGH 7.5
CVE-2020-10641

An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This res…

Fix: 8.0.10+
Fix from $1,950 2020-04-28
Wl Wn579g3 Firmware HIGH 7.5
CVE-2020-12266

An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system informa…

Mitigation only
Fix from $1,950 2020-04-27
Big Iq Centralized Management HIGH 8.1
CVE-2020-5870

In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer.

Fix: 7.1.0+
Fix from $1,950 2020-04-24
Wac505 Firmware CRITICAL 9.8
CVE-2018-21132

Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

Fix: 5.0.0.17+
Fix from $2,300 2020-04-23
GitLab MEDIUM 6.5
CVE-2020-11649

An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.

Fix: 12.7.9 / 12.8.9+
Fix from $1,600 2020-04-22
Tg\/s3.2 Firmware CRITICAL 9.8
CVE-2019-19104

The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application wit…

Mitigation only
Fix from $2,300 2020-04-22
Sf Rush Smart Band Firmware HIGH 8.1
CVE-2020-11539

An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE sec…

No fix yet
Fix from $1,950 2020-04-22
Dsl 2640b Firmware CRITICAL 9.8
CVE-2020-9275

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltratio…

No fix yet
Fix from $2,300 2020-04-20
Dsl 2640b Firmware CRITICAL 9.1
CVE-2020-9278

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated…

No fix yet
Fix from $2,300 2020-04-20
Manageengine Opmanager HIGH 7.5
CVE-2020-11946EPSS 52%

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

Mitigation only
Fix from $1,950 2020-04-20
Clearpass CRITICAL 9.8
CVE-2020-7114

A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain da…

Fix: 6.7.13 / 6.8.4+
Fix from $2,300 2020-04-16
Debian Linux CRITICAL 9.8
CVE-2019-12524

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid…

Fix: after 4.7
Fix from $2,300 2020-04-15
Solution Manager HIGH 8.6
CVE-2020-6235

SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, …

Mitigation only
Fix from $1,950 2020-04-14
Husky Rtu 6049 E70 Firmware CRITICAL 9.8
CVE-2019-16879

The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has a Missing Authentication for Critical Function (C…

Fix: after 5.0
Fix from $2,300 2020-04-14