Show filters
423 Total Results
Displaying 11-20 of 423
Sort by:
Attacker Value
High
CVE-2020-4427
Disclosure Date: April 21, 2020 (last updated February 21, 2025)
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.
0
Attacker Value
Very Low
CVE-2020-8862
Disclosure Date: February 22, 2020 (last updated February 21, 2025)
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from the lack of proper password checking. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-10082.
0
Attacker Value
Very High
Serpico admin user can be accessed without admin creds
Disclosure Date: January 15, 2020 (last updated February 21, 2025)
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin to enter an Old Password value on the Change Password screen does not enhance security. This is problematic in conjunction with XSS.
0
Attacker Value
Unknown
CVE-2021-27878
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.
0
Attacker Value
Unknown
CVE-2021-27877
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.
0
Attacker Value
Unknown
CVE-2021-27876
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.
0
Attacker Value
Unknown
CVE-2021-3332
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
0
Attacker Value
Unknown
CVE-2021-21513
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain admin access on the affected system.
0
Attacker Value
Unknown
CVE-2021-25315
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions.
0
Attacker Value
Unknown
CVE-2021-21308
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2
0