Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 5.3 CVE-2021-26697 The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h… Airflow Mitigation only Fix from $1,6002021-02-17 MEDIUM 5.3 CVE-2021-20067 Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication. M\!dge Firmware Mitigation only Fix from $1,6002021-02-16 CRITICAL 9.8 CVE-2021-22652EPSS 37% Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to ch… Iview 5.7.03.6112+ Fix from $2,3002021-02-11 HIGH 7.8 CVE-2020-26192 Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISI_PRIV_LOGIN_CONSOLE or… Emc Powerscale Onefs Mitigation only Fix from $1,9502021-02-09 HIGH 8.8 CVE-2021-21472 SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installati… Software Provisioning Manager Mitigation only Fix from $1,9502021-02-09 CRITICAL 9.8 CVE-2020-15798EPSS 5% A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Pane… Simatic Hmi Comfort Panels Firmware 16.0+ Fix from $2,3002021-02-09 HIGH 7.8 CVE-2020-10537 An issue was discovered in Epikur before 20.1.1. A Glassfish 4.1 server with a default configuration is running on TCP port 4848. No password is requ… Epikur 20.1.1+ Fix from $1,9502021-02-05 CRITICAL 9.8 CVE-2020-14245 HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a s… Onetest Performance Mitigation only Fix from $2,3002021-02-04 CRITICAL 9.8 CVE-2020-29165 PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privi… Pacsone Server 7.1.1+ Fix from $2,3002021-02-03 HIGH 7.5 CVE-2020-15834 An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an … Mofi4500 4gxelte Firmware Patch available Fix from $1,9502021-02-01 HIGH 7.5 CVE-2020-13856 An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains… Mofi4500 4gxelte Firmware Patch available Fix from $1,9502021-02-01 HIGH 8.8 CVE-2021-25312 HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method. Htcondor 8.9.11+ Fix from $1,9502021-01-27 HIGH 7.8 CVE-2021-22159 Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent … Insider Threat Management 7.4.3 / 7.5.4+ Fix from $1,9502021-01-26 CRITICAL 9.8 CVE-2020-23448 newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication … Newbee Mall No fix yet Fix from $2,3002021-01-26 CRITICAL 9.8 CVE-2020-4958 IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity … Security Identity Governance And Intelligence Mitigation only Fix from $2,3002021-01-21 CRITICAL 9.8 CVE-2021-22850 HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions. Oaklouds Portal Mitigation only Fix from $2,3002021-01-19 MEDIUM 6.1 CVE-2021-1246 Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerabilit… Finesse 12.0+ Fix from $1,6002021-01-13 MEDIUM 5.3 CVE-2020-9143 There is a missing authentication vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability may lead to low-sensitive inf… Emui Mitigation only Fix from $1,6002021-01-13 MEDIUM 6.5 CVE-2020-15799 A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch fam… Scalance X200 4pirt Firmware 5.5.0+ Fix from $1,6002021-01-12 MEDIUM 5.3 CVE-2020-5022 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai… Spectrum Protect Plus 10.1.7+ Fix from $1,6002021-01-08 CRITICAL 9.1 CVE-2020-27285 The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authenti… Crimson Mitigation only Fix from $2,3002021-01-06 CRITICAL 9.9 CVE-2020-35951EPSS 76% An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.… Quiz And Survey Master 7.0.1+ Fix from $2,3002021-01-01 CRITICAL 9.8 CVE-2020-10148 KEVEPSS 92% The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou… Orion Platform Mitigation only Fix from $2,3002020-12-29 MEDIUM 6.5 CVE-2020-9208 There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authentication. Attackers without access… Imanager Neteco 6000 Mitigation only Fix from $1,6002020-12-29 CRITICAL 9.1 CVE-2020-29551 An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the … Urve No fix yet Fix from $2,3002020-12-23 HIGH 7.5 CVE-2020-24580 An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attack… Dsl2888a Firmware No fix yet Fix from $1,9502020-12-22 CRITICAL 9.8 CVE-2020-35190 The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone d… Plone 4.3.18-alpine+ Fix from $2,3002020-12-17 CRITICAL 9.8 CVE-2020-35191 The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker… Drupal Docker Images after 8.5.10-fpm-alpine Fix from $2,3002020-12-17 CRITICAL 9.8 CVE-2020-35192 The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected… Vault 0.11.6+ Fix from $2,3002020-12-17 CRITICAL 9.8 CVE-2020-35195 The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker c… Haproxy Docker Image 1.8.18+ Fix from $2,3002020-12-17