Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Foreman CRITICAL 9.8
CVE-2018-14643EPSS 6%

An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely exec…

Patch available
Fix from $2,300 2018-09-21
Messaging Gateway CRITICAL 9.8
CVE-2018-12242

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allo…

Fix: 10.6.6+
Fix from $2,300 2018-09-19
Application And Change Control HIGH 7.8
CVE-2017-3912

Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbit…

Mitigation only
Fix from $1,950 2018-09-18
Circarlife Scada MEDIUM 5.3
CVE-2018-16670EPSS 25%

An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.

Fix: 4.3+
Fix from $1,600 2018-09-18
Circarlife Scada MEDIUM 5.3
CVE-2018-16668EPSS 10%

An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /ht…

Fix: 4.3+
Fix from $1,600 2018-09-18
My Cloud Wdbctl0020hwt Firmware CRITICAL 9.8
CVE-2018-17153EPSS 87%

It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated …

Fix: 2.30.196+
Fix from $2,300 2018-09-18
Karaf HIGH 8.1
CVE-2018-11787

In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re…

Fix: 3.0.9 / 4.0.9+
Fix from $1,950 2018-09-18
C1 Firmware HIGH 7.2
CVE-2017-2872

Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A HTTP re…

No fix yet
Fix from $1,950 2018-09-17
Supersign Cms CRITICAL 9.8
CVE-2018-16286EPSS 22%

LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is lim…

No fix yet
Fix from $2,300 2018-09-14
Pulse Secure Desktop MEDIUM 6.8
CVE-2018-7572

Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windo…

Mitigation only
Fix from $1,600 2018-09-12
Debian Linux CRITICAL 9.8
CVE-2018-16947

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not…

Fix: 1.6.23 / 1.8.2+
Fix from $2,300 2018-09-12
Group Controller Firmware CRITICAL 9.1
CVE-2018-15485

An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or authorization, aka KONE-03.

Fix: 4.6.5+
Fix from $2,300 2018-09-07
Felcom 250 Firmware CRITICAL 9.8
CVE-2018-16590

FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.

No fix yet
Fix from $2,300 2018-09-06
Thermal Management Center Firmware HIGH 7.5
CVE-2017-14026

In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allow an att…

Fix: 4.13+
Fix from $1,950 2018-09-06
Wifi Switch Firmware HIGH 8.1
CVE-2018-15478

An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LE…

Fix: 2.58 / 2.66+
Fix from $1,950 2018-08-30
Wifi Switch Firmware MEDIUM 6.5
CVE-2018-15479

An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LE…

Fix: 2.58 / 2.66+
Fix from $1,600 2018-08-30
Unified Infrastructure Management CRITICAL 9.8
CVE-2018-13821

A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, inc…

Patch available
Fix from $2,300 2018-08-30
Modicon M221 Firmware CRITICAL 9.8
CVE-2018-7791

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior t…

Fix: 1.6.2.0+
Fix from $2,300 2018-08-29
Esoms CRITICAL 9.8
CVE-2018-14805

ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values withi…

Mitigation only
Fix from $2,300 2018-08-29
Grafana CRITICAL 9.8
CVE-2018-15727EPSS 64%

Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cooki…

Fix: 4.6.4 / 5.2.3+
Fix from $2,300 2018-08-29
Bharat Interface For Money \(bhim\) CRITICAL 9.8
CVE-2017-9819

The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier …

Mitigation only
Fix from $2,300 2018-08-24
Bharat Interface For Money \(bhim\) CRITICAL 9.8
CVE-2017-9820

The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Acce…

Mitigation only
Fix from $2,300 2018-08-24
Alaris Gs Firmware CRITICAL 9.4
CVE-2018-14786

Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and pri…

Fix: after 2.3.6
Fix from $2,300 2018-08-23
Jenkins MEDIUM 5.4
CVE-2018-1999045

A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2…

Fix: after 2.137
Fix from $1,600 2018-08-23
Insteon Hub Firmware HIGH 7.5
CVE-2017-16348

An exploitable denial of service vulnerability exists in Insteon Hub running firmware version 1012. Leftover demo functionality allows for arbitraril…

No fix yet
Fix from $1,950 2018-08-23
Airmail HIGH 7.5
CVE-2018-15667

An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send" command in the URL scheme all…

Mitigation only
Fix from $1,950 2018-08-21
Traefik HIGH 7.5
CVE-2018-15598

Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is pu…

Fix: 1.6.6+
Fix from $1,950 2018-08-21
Niagara CRITICAL 9.8
CVE-2017-16748EPSS 5%

An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using…

Fix: after 4.4
Fix from $2,300 2018-08-20
Smart Hp Wmt CRITICAL 9.8
CVE-2018-14078

Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL …

Mitigation only
Fix from $2,300 2018-08-20
Line HIGH 7.0
CVE-2018-13435

An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulati…

No fix yet
Fix from $1,950 2018-08-16