Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ceph Storage MEDIUM 6.5
CVE-2018-1129

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who…

Patch available
Fix from $1,600 2018-07-10
Trackr Bravo Firmware HIGH 8.8
CVE-2016-6541

TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updat…

Fix: 2.2.5 / 5.1.6+
Fix from $1,950 2018-07-06
Nextcloud Server HIGH 8.1
CVE-2018-3761

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handin…

Fix: 12.0.8 / 13.0.3+
Fix from $1,950 2018-07-05
Elastic Cloud Storage CRITICAL 9.8
CVE-2018-11052

Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulner…

Mitigation only
Fix from $2,300 2018-07-03
Siclock Tc400 Firmware CRITICAL 9.8
CVE-2018-4852

A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device c…

Mitigation only
Fix from $2,300 2018-07-03
Tl Wr841n Firmware CRITICAL 9.8
CVE-2018-12575

On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of auth…

Mitigation only
Fix from $2,300 2018-07-02
Avalanche MEDIUM 6.5
CVE-2018-8902

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to …

Fix: after 6.2
Fix from $1,600 2018-06-29
Hycus Cms CRITICAL 9.8
CVE-2018-12984

Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials.

No fix yet
Fix from $2,300 2018-06-29
Mcafee Web Gateway CRITICAL 9.8
CVE-2018-6667

Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to exe…

Fix: after 7.8.1.5
Fix from $2,300 2018-06-26
phpMyAdmin HIGH 8.8
CVE-2018-12613EPSS 98%

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vu…

Fix: 4.8.2+
Fix from $1,950 2018-06-21
Privileged Access Manager MEDIUM 5.3
CVE-2018-9024

An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.

Fix: 3.0.0+
Fix from $1,600 2018-06-18
Openshift Container Platform CRITICAL 9.8
CVE-2018-1085

openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabl…

Fix: 3.9.31+
Fix from $2,300 2018-06-15
Dropbox MEDIUM 6.4
CVE-2018-12271

An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication…

Mitigation only
Fix from $1,600 2018-06-13
Symfony CRITICAL 9.8
CVE-2018-11407

An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It all…

Fix: 2.8.37 / 3.3.17+
Fix from $2,300 2018-06-13
Lbp7110cw Firmware CRITICAL 9.8
CVE-2018-12048EPSS 5%

A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal…

No fix yet
Fix from $2,300 2018-06-08
Lbp6030w Firmware CRITICAL 9.8
CVE-2018-12049EPSS 5%

A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /por…

No fix yet
Fix from $2,300 2018-06-08
Prime Collaboration CRITICAL 9.8
CVE-2018-0318

A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gai…

Fix: after 12.1
Fix from $2,300 2018-06-07
Prime Collaboration CRITICAL 9.8
CVE-2018-0319

A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to …

Fix: after 12.1
Fix from $2,300 2018-06-07
Prime Collaboration CRITICAL 9.8
CVE-2018-0321

A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invo…

Fix: after 11.6
Fix from $2,300 2018-06-07
Ip Gateway Firmware CRITICAL 9.8
CVE-2017-7931

In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the co…

Fix: after 3.39
Fix from $2,300 2018-06-06
Nas Proxy Server MEDIUM 5.3
CVE-2017-7639

QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the se…

Fix: 1.3.0+
Fix from $1,600 2018-06-05
Intellivue Mp2 Firmware HIGH 8.3
CVE-2018-10597

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M an…

Mitigation only
Fix from $1,950 2018-06-05
1288h V5 Firmware HIGH 8.8
CVE-2018-7943

There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some sp…

Mitigation only
Fix from $1,950 2018-06-05
Nes MEDIUM 5.9
CVE-2017-16025

Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerabili…

Fix: after 6.4.0
Fix from $1,600 2018-06-04
Mds Pulsenet CRITICAL 9.8
CVE-2018-10611

Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unaut…

Fix: after 3.2.1
Fix from $2,300 2018-06-04
Mf210 Firmware CRITICAL 9.8
CVE-2018-11711EPSS 5%

A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html via vectors i…

No fix yet
Fix from $2,300 2018-06-04
Lbp3370 Firmware CRITICAL 9.8
CVE-2018-11692

An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for …

No fix yet
Fix from $2,300 2018-06-04
1288h V5 Firmware HIGH 8.8
CVE-2018-7949

The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send s…

Mitigation only
Fix from $1,950 2018-06-01
Console Io CRITICAL 9.8
CVE-2016-10532

console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execut…

Fix: after 2.2.13
Fix from $2,300 2018-05-31
Woocommerce Category Banner Management MEDIUM 5.3
CVE-2018-11579

class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Ch…

No fix yet
Fix from $1,600 2018-05-31