Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Icar 2 Wi Fi Obd2 Firmware HIGH 8.8
CVE-2018-11478

An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the ca…

Mitigation only
Fix from $1,950 2018-05-30
Paypal Ipn MEDIUM 5.9
CVE-2014-10067

paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal …

Fix: 3.0.0+
Fix from $1,600 2018-05-29
Hapi Auth Jwt2 CRITICAL 9.8
CVE-2016-10525

When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authenticati…

Fix: after 5.1.1
Fix from $2,300 2018-05-29
Kiteworks MEDIUM 6.5
CVE-2017-9421

Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web …

Fix: 2017.01.00+
Fix from $1,600 2018-05-24
Dsl 3782 Firmware CRITICAL 9.8
CVE-2018-8898EPSS 13%

A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer…

No fix yet
Fix from $2,300 2018-05-23
Digital Network Architecture Center CRITICAL 9.8
CVE-2018-0271

A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass a…

Fix: 1.1.2+
Fix from $2,300 2018-05-17
Mimo Baby 2 Firmware MEDIUM 5.3
CVE-2018-10825

Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows…

Mitigation only
Fix from $1,600 2018-05-15
Easy Hosting Control Panel HIGH 7.8
CVE-2018-6617

Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by le…

No fix yet
Fix from $1,950 2018-05-11
Mate 9 Firmware MEDIUM 6.2
CVE-2018-7940

Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authenti…

Fix: 8.0.0.129+
Fix from $1,600 2018-05-10
Ch121 V3 Firmware HIGH 8.8
CVE-2018-7941

Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authe…

Mitigation only
Fix from $1,950 2018-05-10
Sd 320an Firmware MEDIUM 6.5
CVE-2018-6020

In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, whi…

Fix: after 2.01
Fix from $1,600 2018-05-09
Wildfly CRITICAL 9.8
CVE-2018-10682EPSS 8%

An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authe…

No fix yet
Fix from $2,300 2018-05-09
Wildfly CRITICAL 9.8
CVE-2018-10683

An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful…

No fix yet
Fix from $2,300 2018-05-09
Flex System X240 M5 Bios MEDIUM 6.4
CVE-2017-3775

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code …

Fix: 2.23 / 2.61+
Fix from $1,600 2018-05-04
Gpon Router Firmware CRITICAL 9.8
CVE-2018-10561 KEVEPSS 93%

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device th…

Mitigation only
Fix from $2,300 2018-05-04
Dir 601 Firmware HIGH 8.1
CVE-2018-10641

D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.

No fix yet
Fix from $1,950 2018-05-04
Mss110 Firmware CRITICAL 9.8
CVE-2018-10544

Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.

Fix: after 1.1.24
Fix from $2,300 2018-05-02
Be126 Firmware HIGH 7.8
CVE-2018-9232

Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and …

No fix yet
Fix from $1,950 2018-05-01
Ap200 Firmware HIGH 7.8
CVE-2018-10576

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native A…

Fix: 1.2.9.15+
Fix from $1,950 2018-04-30
Qradar Security Information And Event Manager HIGH 8.8
CVE-2018-1418EPSS 52%

IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.

Fix: 7.2.8+
Fix from $1,950 2018-04-26
Accent Firmware HIGH 8.8
CVE-2017-12712

The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stam…

Mitigation only
Fix from $1,950 2018-04-25
Glusterfs HIGH 8.8
CVE-2018-1112

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to conne…

Fix: 3.10.12+
Fix from $1,950 2018-04-25
Phpliteadmin CRITICAL 9.8
CVE-2018-10362

An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for th…

Fix: after 1.9.7.1
Fix from $2,300 2018-04-25
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-1106

An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed package…

Mitigation only
Fix from $1,600 2018-04-23
Sterling B2b Integrator HIGH 8.1
CVE-2014-0927

The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass …

Patch available
Fix from $1,950 2018-04-20
Horizon Daas HIGH 8.8
CVE-2018-6960

VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication.…

Fix: 8.0.0+
Fix from $1,950 2018-04-20
Unified Computing System Director CRITICAL 9.9
CVE-2018-0238EPSS 5%

A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, …

Mitigation only
Fix from $2,300 2018-04-19
Bmxnor0200 Firmware CRITICAL 9.8
CVE-2018-7760

An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI …

Mitigation only
Fix from $2,300 2018-04-18
Sd 820 Firmware HIGH 7.5
CVE-2016-10434

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 820 and SD 820A, the input to…

Mitigation only
Fix from $1,950 2018-04-18
Undertow MEDIUM 5.9
CVE-2017-12196

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that…

Fix: after 1.4.18
Fix from $1,600 2018-04-18