Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2020-7115EPSS 65% The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker cou… Clearpass Policy Manager 6.8.6 / 6.9.1+ Fix from $2,3002020-06-03 CRITICAL 9.8 CVE-2020-12017 GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application … Rt430 Firmware 08a05+ Fix from $2,3002020-06-02 HIGH 7.2 CVE-2020-13695 In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root withou… Quickbox after 2.5.5 Fix from $1,9502020-06-01 CRITICAL 9.8 CVE-2020-1955 CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e… Couchdb Mitigation only Fix from $2,3002020-05-20 CRITICAL 9.8 CVE-2019-18666 An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented … Dap 1360 Revision F Firmware after 6.12b01 Fix from $2,3002020-05-15 HIGH 7.5 CVE-2020-12877 Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication. Aptare 10.4+ Fix from $1,9502020-05-14 CRITICAL 9.8 CVE-2020-6242 SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central… Businessobjects Business Intelligence Platform Mitigation only Fix from $2,3002020-05-12 HIGH 7.5 CVE-2020-9315EPSS 82% ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administratio… Iplanet Web Server after 7.0.27 Fix from $1,9502020-05-10 CRITICAL 9.8 CVE-2020-12720EPSS 89% vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. Vbulletin 5.5.6+ Fix from $2,3002020-05-08 HIGH 7.5 CVE-2020-10972 An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentic… Wn530hg4 Firmware Mitigation only Fix from $1,9502020-05-07 HIGH 7.5 CVE-2020-10973EPSS 8% An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a cr… Wn530hg4 Firmware Mitigation only Fix from $1,9502020-05-07 HIGH 7.5 CVE-2020-10974 An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, includi… Wl Wn575a3 Firmware Mitigation only Fix from $1,9502020-05-07 MEDIUM 5.3 CVE-2020-12117 Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration values via a crafted packet to U… Nport 5100a Firmware after 1.5 Fix from $1,6002020-05-01 HIGH 7.5 CVE-2020-11028 In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of… WordPress 5.4.1+ Fix from $1,9502020-04-30 CRITICAL 9.8 CVE-2019-5620EPSS 70% ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function. Microscada Pro Sys600 No fix yet Fix from $2,3002020-04-29 HIGH 7.5 CVE-2020-12478EPSS 8% TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files. Teampass No fix yet Fix from $1,9502020-04-29 HIGH 7.5 CVE-2020-10641 An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This res… Ignition Gateway 8.0.10+ Fix from $1,9502020-04-28 HIGH 7.5 CVE-2020-12266 An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system informa… Wl Wn579g3 Firmware Mitigation only Fix from $1,9502020-04-27 HIGH 8.1 CVE-2020-5870 In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer. Big Iq Centralized Management 7.1.0+ Fix from $1,9502020-04-24 CRITICAL 9.8 CVE-2018-21132 Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17. Wac505 Firmware 5.0.0.17+ Fix from $2,3002020-04-23 MEDIUM 6.5 CVE-2020-11649 An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted. GitLab 12.7.9 / 12.8.9+ Fix from $1,6002020-04-22 CRITICAL 9.8 CVE-2019-19104 The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application wit… Tg\/s3.2 Firmware Mitigation only Fix from $2,3002020-04-22 HIGH 8.1 CVE-2020-11539 An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE sec… Sf Rush Smart Band Firmware No fix yet Fix from $1,9502020-04-22 CRITICAL 9.8 CVE-2020-9275 An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltratio… Dsl 2640b Firmware No fix yet Fix from $2,3002020-04-20 CRITICAL 9.1 CVE-2020-9278 An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated… Dsl 2640b Firmware No fix yet Fix from $2,3002020-04-20 HIGH 7.5 CVE-2020-11946EPSS 52% Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. Manageengine Opmanager Mitigation only Fix from $1,9502020-04-20 CRITICAL 9.8 CVE-2020-7114 A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain da… Clearpass 6.7.13 / 6.8.4+ Fix from $2,3002020-04-16 CRITICAL 9.8 CVE-2019-12524 An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid… Debian Linux after 4.7 Fix from $2,3002020-04-15 HIGH 8.6 CVE-2020-6235 SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, … Solution Manager Mitigation only Fix from $1,9502020-04-14 CRITICAL 9.8 CVE-2019-16879 The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has a Missing Authentication for Critical Function (C… Husky Rtu 6049 E70 Firmware after 5.0 Fix from $2,3002020-04-14