Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
C1 Firmware HIGH 8.8
CVE-2017-2871

Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. An attack…

No fix yet
Fix from $1,950 2018-04-17
Plays.tv CRITICAL 9.8
CVE-2018-6546EPSS 17%

plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes c…

Fix: 1.27.7.0+
Fix from $2,300 2018-04-13
Plays.tv CRITICAL 9.1
CVE-2018-6547

plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, contains a…

Fix: 1.27.7.0+
Fix from $2,300 2018-04-13
Debian Linux MEDIUM 5.3
CVE-2016-9646

ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572),…

Fix: 3.20161229+
Fix from $1,600 2018-04-13
Debian Linux CRITICAL 9.8
CVE-2017-0356

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker …

Fix: 3.20170111+
Fix from $2,300 2018-04-13
Horde Ldap HIGH 8.1
CVE-2014-3999

The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.

Fix: 2.0.6+
Fix from $1,950 2018-04-10
Ilc Plcs Firmware HIGH 7.3
CVE-2016-8371EPSS 11%

The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

No fix yet
Fix from $1,950 2018-04-05
Ilc Plcs Firmware HIGH 7.3
CVE-2016-8380EPSS 11%

The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

No fix yet
Fix from $1,950 2018-04-05
Moodle HIGH 8.1
CVE-2018-1082

A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspende…

Fix: after 3.4.1
Fix from $1,950 2018-04-04
Auth0.js CRITICAL 9.8
CVE-2018-6873

The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.

Fix: after 8.10.1
Fix from $2,300 2018-04-04
Vdsl2 Modem Hg 150 Ub Firmware CRITICAL 9.8
CVE-2018-9248EPSS 15%

FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.

No fix yet
Fix from $2,300 2018-04-04
Vdsl2 Modem Hg 150 Ub Firmware CRITICAL 9.8
CVE-2018-9249EPSS 6%

FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to a…

Mitigation only
Fix from $2,300 2018-04-04
X Pack CRITICAL 9.8
CVE-2018-3822

X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. …

Mitigation only
Fix from $2,300 2018-03-30
My Cloud Firmware CRITICAL 9.8
CVE-2018-9148

Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass…

No fix yet
Fix from $2,300 2018-03-30
Mdm9206 Firmware CRITICAL 9.8
CVE-2017-14911

In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 2…

Mitigation only
Fix from $2,300 2018-03-30
Tim 1531 Irc Firmware CRITICAL 9.8
CVE-2018-4841

A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could…

Fix: 1.1+
Fix from $2,300 2018-03-29
Ios Xe HIGH 8.8
CVE-2018-0195

A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the AP…

Fix: 16.2.2+
Fix from $1,950 2018-03-28
iOS MEDIUM 6.5
CVE-2018-0163

A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to…

Mitigation only
Fix from $1,600 2018-03-28
Alice 6 Firmware CRITICAL 9.8
CVE-2018-5451

In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficiently prove…

Mitigation only
Fix from $2,300 2018-03-28
Nordvpn HIGH 8.8
CVE-2018-9105

NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privileged helper tool's implemente…

Mitigation only
Fix from $1,950 2018-03-27
Emc Scaleio CRITICAL 9.8
CVE-2018-1237

Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This…

Fix: 2.5+
Fix from $2,300 2018-03-27
Tealeaf Customer Experience MEDIUM 6.5
CVE-2015-4987

The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified ve…

Fix: after 9.0.2
Fix from $1,600 2018-03-27
Dir 850l Firmware CRITICAL 9.8
CVE-2018-9032EPSS 28%

An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version…

Fix: after 2.06
Fix from $2,300 2018-03-27
Norton App Lock MEDIUM 6.7
CVE-2017-15534

The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can a…

Fix: 1.3.0.13+
Fix from $1,600 2018-03-26
HTTP Server CRITICAL 9.8
CVE-2018-1312EPSS 16%

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g…

Mitigation only
Fix from $2,300 2018-03-26
G Cam\/efd 2250 Firmware CRITICAL 9.8
CVE-2018-7532EPSS 8%

Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras,…

No fix yet
Fix from $2,300 2018-03-22
Usb Memory Stick With Fingerprint Firwmare MEDIUM 6.8
CVE-2017-16242

An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data acces…

Mitigation only
Fix from $1,600 2018-03-22
Wireless Appliance Firmware MEDIUM 6.7
CVE-2017-17743

Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5…

Fix: 4.4.20 / 5.0.19+
Fix from $1,600 2018-03-22
Infinia Hawkeye 4 Firmware CRITICAL 9.8
CVE-2017-14002

GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Succ…

Mitigation only
Fix from $2,300 2018-03-20
Gemnet License Server CRITICAL 9.8
CVE-2017-14004

GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation …

Mitigation only
Fix from $2,300 2018-03-20