Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2020-11856EPSS 5% Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow r… Operation Bridge Reporter after 10.40 Fix from $2,3002020-09-22 MEDIUM 6.5 CVE-2020-3977 VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first … Horizon Daas after 8.0.1 Fix from $1,6002020-09-22 CRITICAL 9.8 CVE-2020-23512 VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) with… P1 Firmware No fix yet Fix from $2,3002020-09-15 CRITICAL 9.8 CVE-2020-16098 It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior… Command Centre 8.00.1228 / 8.10.1211+ Fix from $2,3002020-09-15 MEDIUM 5.4 CVE-2020-13289 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA … GitLab 13.1.10 / 13.2.8+ Fix from $1,6002020-09-14 MEDIUM 5.9 CVE-2020-13920 Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to con… Activemq 5.15.12+ Fix from $1,6002020-09-10 MEDIUM 5.3 CVE-2020-5780 Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, … Email Subscribers \& Newsletters 4.5.6+ Fix from $1,6002020-09-10 HIGH 7.5 CVE-2020-11579EPSS 26% An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unau… Phpkb No fix yet Fix from $1,9502020-09-03 MEDIUM 6.1 CVE-2020-12621 The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component. Teamwire No fix yet Fix from $1,6002020-09-02 MEDIUM 5.3 CVE-2020-20627 The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change. Givewp after 2.5.9 Fix from $1,6002020-08-31 HIGH 8.8 CVE-2020-24363 KEVEPSS 21% TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a fac… Tl Wa855re Firmware 200731+ Fix from $1,9502020-08-31 HIGH 7.5 CVE-2018-1501 IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-F… Security Guardium Patch available Fix from $1,9502020-08-26 MEDIUM 6.8 CVE-2020-15483 An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, wit… M1000 Multipara Patient Monitor Firmware No fix yet Fix from $1,6002020-08-26 MEDIUM 5.3 CVE-2020-9062 Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages betwe… Probase Mitigation only Fix from $1,6002020-08-21 HIGH 7.1 CVE-2020-10124 NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer,… Aptra Xfs Mitigation only Fix from $1,9502020-08-21 CRITICAL 9.8 CVE-2020-24051 The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authenticatio… Exvf5c 2 Firmware No fix yet Fix from $2,3002020-08-21 MEDIUM 5.8 CVE-2020-3448 A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authen… Cyber Vision Center 3.0.4+ Fix from $1,6002020-08-17 HIGH 7.5 CVE-2020-17475 Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet dat… Koala Firmware Mitigation only Fix from $1,9502020-08-14 MEDIUM 6.5 CVE-2019-5591 KEVEPSS 18% A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by imper… Fortios after 6.2.0 Fix from $1,6002020-08-14 CRITICAL 9.8 CVE-2020-12106 The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative fun… Vpncrypt M10 Firmware Mitigation only Fix from $2,3002020-08-12 CRITICAL 9.1 CVE-2020-6294 Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for fun… Businessobjects Business Intelligence Platform Mitigation only Fix from $2,3002020-08-12 HIGH 7.5 CVE-2020-6309 SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authent… Netweaver Application Server Java Mitigation only Fix from $1,9502020-08-12 CRITICAL 9.1 CVE-2020-16167 Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and an… Launcher Os after 13146 Fix from $2,3002020-08-07 MEDIUM 6.5 CVE-2020-15136 In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gatew… Etcd 3.3.23 / 3.4.10+ Fix from $1,6002020-08-06 HIGH 7.5 CVE-2020-15127 In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entir… Contour 1.7.0+ Fix from $1,9502020-08-05 MEDIUM 5.3 CVE-2020-3461 A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to … Data Center Network Manager 11.4+ Fix from $1,6002020-07-31 CRITICAL 9.8 CVE-2020-3376 A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypa… Data Center Network Manager Mitigation only Fix from $2,3002020-07-31 CRITICAL 9.8 CVE-2020-2076 SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST … Package Analytics after 04.0.0 Fix from $2,3002020-07-29 CRITICAL 9.8 CVE-2020-15391 The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket p… Devspace Patch available Fix from $2,3002020-07-23 CRITICAL 9.8 CVE-2020-10920 This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen p… C More Hmi Ea9 Firmware Mitigation only Fix from $2,3002020-07-23