Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Intelligent Management Center CRITICAL 9.8
CVE-2018-7076EPSS 12%

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04.

Fix: 7.3+
Fix from $2,300 2018-10-17
Ubuntu Linux CRITICAL 9.1
CVE-2018-10933EPSS 92%

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without fir…

Fix: 0.7.6 / 0.8.4+
Fix from $2,300 2018-10-17
Neo4j CRITICAL 9.8
CVE-2018-18389

Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and Sys…

Fix: 3.4.9+
Fix from $2,300 2018-10-16
Rut900 Firmware MEDIUM 6.8
CVE-2018-17534

Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows atta…

Fix: 00.04.233+
Fix from $1,600 2018-10-15
Security Key Lifecycle Manager HIGH 7.1
CVE-2018-1738

IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integr…

Fix: after 3.0.0.1
Fix from $1,950 2018-10-11
Responsive Filemanager HIGH 7.5
CVE-2018-18061

An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them wit…

No fix yet
Fix from $1,950 2018-10-10
Nplug Firmware HIGH 8.1
CVE-2018-12455EPSS 6%

Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interface just by…

No fix yet
Fix from $1,950 2018-10-10
Infocad Fm HIGH 7.5
CVE-2018-13789

An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on re…

Fix: 3.1.0.0+
Fix from $1,950 2018-10-10
Tinc MEDIUM 5.3
CVE-2018-16737

tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.

Fix: 1.0.30+
Fix from $1,600 2018-10-10
Junos HIGH 8.1
CVE-2018-0052

If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the devi…

Mitigation only
Fix from $1,950 2018-10-10
Junos MEDIUM 6.8
CVE-2018-0053

An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full co…

Mitigation only
Fix from $1,600 2018-10-10
Junos HIGH 8.1
CVE-2018-0044

An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if a…

Fix: after 18.1r3
Fix from $1,950 2018-10-10
Telegram MEDIUM 6.4
CVE-2018-15542

An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime m…

Mitigation only
Fix from $1,600 2018-10-09
Telegram MEDIUM 6.8
CVE-2018-15543

An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows au…

Mitigation only
Fix from $1,600 2018-10-09
Dir 809 A1 Firmware HIGH 7.5
CVE-2018-14080

An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechan…

Fix: after 1.11
Fix from $1,950 2018-10-09
Extplorer CRITICAL 9.8
CVE-2012-6710EPSS 25%

ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login r…

Fix: after 2.1.2
Fix from $2,300 2018-10-07
Ios Xe MEDIUM 6.7
CVE-2018-15371

A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication …

Mitigation only
Fix from $1,600 2018-10-05
Umbrella CRITICAL 9.1
CVE-2018-0435

A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other o…

Mitigation only
Fix from $2,300 2018-10-05
Servers Ultimate CRITICAL 9.8
CVE-2013-7465

Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote attackers to execute arbitrary …

No fix yet
Fix from $2,300 2018-10-05
Debian Linux MEDIUM 6.5
CVE-2018-0505

Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock

Fix: 1.31.1+
Fix from $1,600 2018-10-04
Subscription Management Tool CRITICAL 9.1
CVE-2018-12472

A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux…

Fix: 3.0.37+
Fix from $2,300 2018-10-04
Data Loss Prevention Endpoint HIGH 7.8
CVE-2018-6689

Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 all…

Fix: 10.0.510 / 11.0.600+
Fix from $1,950 2018-10-03
Emg 12 Firmware CRITICAL 9.8
CVE-2018-14826EPSS 8%

Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a special…

Fix: after 2.57
Fix from $2,300 2018-10-02
Dir 823g Firmware CRITICAL 9.8
CVE-2018-17786

On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, whic…

No fix yet
Fix from $2,300 2018-10-02
Websphere Portal MEDIUM 6.3
CVE-2018-1672

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to ac…

Patch available
Fix from $1,600 2018-10-01
Storcenter Px12 450r Firmware MEDIUM 5.9
CVE-2018-9080

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into …

Mitigation only
Fix from $1,600 2018-09-28
Storageworks Xp7 Automation Director MEDIUM 5.9
CVE-2018-7108

HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerabili…

Fix: 8.6.1-00+
Fix from $1,600 2018-09-27
Rational Engineering Lifecycle Manager MEDIUM 6.5
CVE-2018-1539

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct …

Fix: after 6.0.6
Fix from $1,600 2018-09-25
Bigtree Cms HIGH 8.1
CVE-2018-17341

BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, …

No fix yet
Fix from $1,950 2018-09-23
Core I3 HIGH 7.6
CVE-2018-12169

Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th G…

Mitigation only
Fix from $1,950 2018-09-21