Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2020-3531 A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end data… Iot Field Network Director 4.6.1+ Fix from $2,3002020-11-18 HIGH 7.5 CVE-2020-3392 A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on… Iot Field Network Director 4.6.1+ Fix from $1,9502020-11-18 CRITICAL 10.0 CVE-2020-26821 SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check… Solution Manager Mitigation only Fix from $2,3002020-11-10 CRITICAL 10.0 CVE-2020-26822 SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check… Solution Manager Mitigation only Fix from $2,3002020-11-10 CRITICAL 10.0 CVE-2020-26823 SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check… Solution Manager Mitigation only Fix from $2,3002020-11-10 CRITICAL 10.0 CVE-2020-26824 SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check… Solution Manager Mitigation only Fix from $2,3002020-11-10 CRITICAL 9.8 CVE-2020-13927 KEVEPSS 100% The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us… Airflow 1.10.11+ Fix from $2,3002020-11-10 MEDIUM 5.5 CVE-2020-27019EPSS 18% Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an … Interscan Messaging Security Virtual Appliance after 9.1 Fix from $1,6002020-11-09 HIGH 7.5 CVE-2020-10291 Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making … Visual Components Network License Server Mitigation only Fix from $1,9502020-11-06 CRITICAL 9.8 CVE-2020-7128 A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. Airwave Glass 1.3.2+ Fix from $2,3002020-11-04 HIGH 7.5 CVE-2020-27986EPSS 16% SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reported… Sonarqube Mitigation only Fix from $1,9502020-10-28 HIGH 7.5 CVE-2020-25966 Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentic… Spectra 3.4.0+ Fix from $1,9502020-10-28 HIGH 8.1 CVE-2020-26649 AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php Atomxcms 2 No fix yet Fix from $1,9502020-10-22 HIGH 8.8 CVE-2018-11764 Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even … Hadoop Mitigation only Fix from $1,9502020-10-21 CRITICAL 9.8 CVE-2020-12500 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES… Es7510 Xt Firmware No fix yet Fix from $2,3002020-10-15 CRITICAL 9.8 CVE-2020-15243 Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 … Smartstore Mitigation only Fix from $2,3002020-10-08 MEDIUM 5.5 CVE-2020-26567EPSS 17% An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any a… Dsr 250n Firmware 3.17b+ Fix from $1,6002020-10-08 MEDIUM 6.5 CVE-2020-3598 A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to acc… Vision Dynamic Signage Director 6.2.0+ Fix from $1,6002020-10-08 HIGH 7.5 CVE-2020-26876EPSS 11% The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by u… Wp Courses after 2.0.27 Fix from $1,9502020-10-07 MEDIUM 5.3 CVE-2020-26599 An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can be accepted without authentic… Android Mitigation only Fix from $1,6002020-10-06 CRITICAL 9.8 CVE-2020-24217EPSS 40% An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authenti… Iptv\/h.264 Video Encoder Firmware No fix yet Fix from $2,3002020-10-06 CRITICAL 9.8 CVE-2020-6875 A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attacke… Zxone 19700 Snpe Firmware Mitigation only Fix from $2,3002020-10-05 HIGH 7.5 CVE-2020-26061 ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword functio… Passwordstate 8.5+ Fix from $1,9502020-10-05 HIGH 7.5 CVE-2020-12127EPSS 7% An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to… Wn530h4 Firmware Mitigation only Fix from $1,9502020-10-02 HIGH 7.5 CVE-2020-9487 In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to c… Nifi after 1.11.4 Fix from $1,9502020-10-01 HIGH 8.2 CVE-2020-12505 Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without aut… 750 852 Firmware Mitigation only Fix from $1,9502020-09-30 CRITICAL 9.1 CVE-2020-12506 Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by send… 750 362 Firmware Mitigation only Fix from $2,3002020-09-30 CRITICAL 9.4 CVE-2020-25747 The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP… Rv 3406 Firmware Mitigation only Fix from $2,3002020-09-25 CRITICAL 9.8 CVE-2020-15851 Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories … Backup \& Replication Transporter No fix yet Fix from $2,3002020-09-24 MEDIUM 6.5 CVE-2019-16004 A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentic… Vision Dynamic Signage Director 6.2.0+ Fix from $1,6002020-09-23