Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Line HIGH 7.0
CVE-2018-13446

An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipu…

No fix yet
Fix from $1,950 2018-08-16
Line MEDIUM 6.3
CVE-2018-13434

An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentica…

No fix yet
Fix from $1,600 2018-08-16
Openemr CRITICAL 9.1
CVE-2018-15152EPSS 26%

Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) porta…

Fix: 5.0.1.4+
Fix from $2,300 2018-08-15
Supplier Relationship Management Mdm Catalog HIGH 8.6
CVE-2018-2449

SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid reposito…

Mitigation only
Fix from $1,950 2018-08-14
508 Minimed Insulin Pump Firmware MEDIUM 5.3
CVE-2018-14781

Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), ar…

Mitigation only
Fix from $1,600 2018-08-13
Nextcloud Server HIGH 8.8
CVE-2018-3775

Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Aut…

Fix: 12.0.3+
Fix from $1,950 2018-08-12
Tsw X60 Firmware CRITICAL 9.8
CVE-2018-10630EPSS 11%

For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, a…

Fix: 1.502.0047.001 / 2.001.0037.001+
Fix from $2,300 2018-08-10
Nwl 25 Firmware HIGH 7.5
CVE-2018-14782

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and pr…

Fix: after 2.0.29.11
Fix from $1,950 2018-08-10
Aruba Clearpass Policy Manager CRITICAL 9.8
CVE-2018-7058

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerabi…

Fix: 6.6.9+
Fix from $2,300 2018-08-06
Centralview Fraud Risk Management HIGH 7.5
CVE-2018-7069

HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This …

Fix: 6.1+
Fix from $1,950 2018-08-06
Keycloak HIGH 8.1
CVE-2016-8609

It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing …

Fix: 2.3.0+
Fix from $1,950 2018-08-01
Telem Gwm Firmware CRITICAL 9.8
CVE-2018-10603

Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, whi…

Fix: after 2018.04.18-linux_4-01-601cb47
Fix from $2,300 2018-07-31
Api Connect HIGH 8.1
CVE-2018-1638

IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for…

Fix: after 5.0.8.3
Fix from $1,950 2018-07-31
Prosody HIGH 8.8
CVE-2018-10847

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user…

Fix: 0.9.14+
Fix from $1,950 2018-07-30
Distributed Fork HIGH 8.8
CVE-2017-2652

It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the d…

Fix: after 1.5.0
Fix from $1,950 2018-07-27
Drive Encryption MEDIUM 6.6
CVE-2018-6686

Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically proximate attackers to bypass …

Mitigation only
Fix from $1,600 2018-07-27
Enterprise Linux MEDIUM 6.5
CVE-2017-7562

An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at…

Fix: 1.16.1+
Fix from $1,600 2018-07-26
Kafka MEDIUM 6.8
CVE-2017-12610

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol mess…

Fix: after 0.11.0.1
Fix from $1,600 2018-07-26
Hg100 Firmware CRITICAL 9.8
CVE-2018-11491EPSS 7%

ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution.

Fix: 1.05.12+
Fix from $2,300 2018-07-25
Smartserver 1 Firmware CRITICAL 9.8
CVE-2018-8859

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An atta…

Fix: 4.11.007+
Fix from $2,300 2018-07-24
Samlbase HIGH 7.5
CVE-2018-5387

Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to ma…

Fix: 1.4.2+
Fix from $1,950 2018-07-24
Connect CRITICAL 9.8
CVE-2018-12804EPSS 11%

Adobe Connect versions 9.7.5 and earlier have an Authentication Bypass vulnerability. Successful exploitation could lead to session hijacking.

Fix: after 9.7.5
Fix from $2,300 2018-07-20
Sddm HIGH 7.5
CVE-2018-14345

An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing …

Fix: after 0.17.0
Fix from $1,950 2018-07-17
Jboss Data Grid MEDIUM 6.5
CVE-2017-2638

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability…

Fix: 9.0.0+
Fix from $1,600 2018-07-16
Php Formmail Generator CRITICAL 9.8
CVE-2016-9482

Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by…

Mitigation only
Fix from $2,300 2018-07-13
Hn7740s Firmware HIGH 8.8
CVE-2016-9497

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate pa…

Mitigation only
Fix from $1,950 2018-07-13
Itrack Easy HIGH 7.5
CVE-2016-6544

getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be e…

Mitigation only
Fix from $1,950 2018-07-13
Asp.net Core HIGH 7.5
CVE-2018-8171EPSS 10%

A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature…

Patch available
Fix from $1,950 2018-07-11
Ceph Storage HIGH 8.1
CVE-2018-10861

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po…

Patch available
Fix from $1,950 2018-07-10
Ceph Storage HIGH 7.5
CVE-2018-1128

It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access…

Fix: after 13.2.1
Fix from $1,950 2018-07-10