Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Xeleris CRITICAL 9.8
CVE-2017-14006

GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credenti…

Mitigation only
Fix from $2,300 2018-03-20
Centricity Pacs Ra1000 CRITICAL 9.8
CVE-2017-14008

GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successf…

Mitigation only
Fix from $2,300 2018-03-20
Gemfire For Pivotal Cloud Foundry CRITICAL 9.8
CVE-2016-9880

The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and cou…

Fix: 1.6.5+
Fix from $2,300 2018-03-16
Appweb HIGH 8.1
CVE-2018-8715EPSS 23%

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forge…

Fix: after 7.0.2
Fix from $1,950 2018-03-15
Unitrends Backup CRITICAL 9.8
CVE-2018-6328EPSS 65%

It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unau…

Fix: 10.1+
Fix from $2,300 2018-03-14
Woocommerce Products Filter CRITICAL 9.8
CVE-2018-8710

A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the …

Fix: 2.2.0+
Fix from $2,300 2018-03-14
Windows 10 HIGH 7.0
CVE-2018-0886EPSS 82%

The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, W…

Patch available
Fix from $1,950 2018-03-14
Seq CRITICAL 9.8
CVE-2018-8096EPSS 49%

Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","…

Fix: 4.2.605+
Fix from $2,300 2018-03-14
Ansible Engine CRITICAL 9.8
CVE-2018-7750EPSS 27%

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2…

Patch available
Fix from $2,300 2018-03-13
Snh V6410pn Firmware CRITICAL 9.8
CVE-2018-6294

Unsecured way of firmware update in Hanwha Techwin Smartcams

No fix yet
Fix from $2,300 2018-03-13
Snh V6410pn Firmware CRITICAL 9.8
CVE-2018-6299

Authentication bypass in Hanwha Techwin Smartcams

No fix yet
Fix from $2,300 2018-03-13
Asyncssh CRITICAL 9.8
CVE-2018-7749

The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests.…

Fix: 1.12.1+
Fix from $2,300 2018-03-12
Curl CRITICAL 9.8
CVE-2017-2628

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not refl…

Mitigation only
Fix from $2,300 2018-03-12
Blur CRITICAL 9.8
CVE-2018-7213

The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authentication and macOS disk-encry…

No fix yet
Fix from $2,300 2018-03-11
Remedy Action Request System HIGH 8.1
CVE-2017-18223

BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.

Fix: 9.1.03+
Fix from $1,950 2018-03-10
Mps110 1 Firmware MEDIUM 5.3
CVE-2018-7227

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of spe…

Fix: 3.29.67+
Fix from $1,600 2018-03-09
Mps110 1 Firmware CRITICAL 9.8
CVE-2018-7228

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticate…

Fix: 3.29.67+
Fix from $2,300 2018-03-09
Mps110 1 Firmware HIGH 8.1
CVE-2018-7236

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due …

Fix: 3.29.67+
Fix from $1,950 2018-03-09
Security Access Manager MEDIUM 5.9
CVE-2018-1443

An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated …

Fix: after 9.0.4
Fix from $1,600 2018-03-08
Media Streaming Add On MEDIUM 6.5
CVE-2017-7638

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitatio…

Fix: after 430.1.2.0
Fix from $1,600 2018-03-08
Asyncos MEDIUM 5.6
CVE-2018-0087

A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP serv…

Mitigation only
Fix from $1,600 2018-03-08
Razor HIGH 7.5
CVE-2018-7745EPSS 12%

An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/installation/createuserinfo reque…

No fix yet
Fix from $1,950 2018-03-07
Snapcenter Server HIGH 7.2
CVE-2017-15519

Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File S…

Fix: after 3.0.1
Fix from $1,950 2018-03-06
Privileged Account Manager CRITICAL 9.8
CVE-2018-1343

PAM exposure enabling unauthenticated access to remote host

Fix: 3.1.0.4 / 3.2.0.3+
Fix from $2,300 2018-03-06
Oncell G3110 Hspa Firmware CRITICAL 9.8
CVE-2018-5455

A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and …

Fix: after 1.4
Fix from $2,300 2018-03-05
Edirectory CRITICAL 9.8
CVE-2017-9285

NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.

Fix: after 9.0
Fix from $2,300 2018-03-02
Imanager HIGH 7.5
CVE-2017-5189

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extrac…

Mitigation only
Fix from $1,950 2018-03-02
Netscaler Application Delivery Controller HIGH 7.5
CVE-2018-5314

Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build…

Mitigation only
Fix from $1,950 2018-03-01
Openmeetings MEDIUM 6.5
CVE-2018-1286

In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny servi…

Fix: after 4.0.1
Fix from $1,600 2018-02-28
Elastic Services Controller CRITICAL 9.8
CVE-2018-0121

A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unau…

Mitigation only
Fix from $2,300 2018-02-22