Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
System Management Homepage MEDIUM 5.6
CVE-2017-12549

A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

Fix: 7.6.1+
Fix from $1,600 2018-02-15
Mod Nss CRITICAL 9.8
CVE-2011-4973

Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and en…

Mitigation only
Fix from $2,300 2018-02-15
Duke L09 Firmware MEDIUM 6.8
CVE-2017-17161

The 'Find Phone' function in some Huawei smart phones with software earlier than Duke-L09C10B186 versions, earlier than Duke-L09C432B187 versions, ea…

Mitigation only
Fix from $1,600 2018-02-15
Honor V9 Play Firmware MEDIUM 6.8
CVE-2017-15351

The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an authentication bypass vulnerabili…

Mitigation only
Fix from $1,600 2018-02-15
Tew 751dr Firmware HIGH 7.5
CVE-2018-7034

TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demon…

No fix yet
Fix from $1,950 2018-02-14
Pfc200 Firmware CRITICAL 9.8
CVE-2018-5459

An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different …

Fix: 02.07.07+
Fix from $2,300 2018-02-13
Sitefinity HIGH 8.8
CVE-2017-18179

Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termina…

No fix yet
Fix from $1,950 2018-02-12
Twitter Kit MEDIUM 5.4
CVE-2017-0911

Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to…

Fix: after 3.2.1
Fix from $1,600 2018-02-09
Control Manager CRITICAL 9.8
CVE-2018-3601

A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication o…

Patch available
Fix from $2,300 2018-02-09
Online Voting Platform CRITICAL 9.8
CVE-2018-6180

A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts.

No fix yet
Fix from $2,300 2018-02-08
Netvault Backup CRITICAL 9.8
CVE-2018-1163EPSS 16%

This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw…

Mitigation only
Fix from $2,300 2018-02-08
Mobility Services Engine HIGH 7.2
CVE-2018-0116

A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subsc…

Mitigation only
Fix from $1,950 2018-02-08
Sandstorm CRITICAL 9.8
CVE-2017-6199

A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field.

Fix: 0.203+
Fix from $2,300 2018-02-06
Web Connection HIGH 8.8
CVE-2018-6569

West Wind Web Server 6.x does not require authentication for /ADMIN.ASP.

Mitigation only
Fix from $1,950 2018-02-06
Wing MEDIUM 5.3
CVE-2018-5794

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is No Authentication for the Aero…

Fix: 5.8.6.9 / 5.9.1.3+
Fix from $1,600 2018-02-05
Puppet Enterprise HIGH 7.5
CVE-2017-2297

Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issu…

Fix: 2016.4.5+
Fix from $1,950 2018-02-01
Packetfence CRITICAL 9.8
CVE-2011-4068

The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty passwor…

Fix: after 3.0.1
Fix from $2,300 2018-02-01
Crowd MEDIUM 6.8
CVE-2017-16858

The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an …

Fix: 3.1.2+
Fix from $1,600 2018-01-31
Jenkins HIGH 8.8
CVE-2017-1000354

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user. T…

Fix: after 2.56
Fix from $1,950 2018-01-29
Dsl Ac51 Firmware CRITICAL 9.8
CVE-2017-14698

ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N…

Patch available
Fix from $2,300 2018-01-29
Telecontrol Server Basic MEDIUM 5.3
CVE-2018-4835

A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's port 8000/t…

Fix: 3.1+
Fix from $1,600 2018-01-25
Telecontrol Server Basic HIGH 8.8
CVE-2018-4836

A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleControl Se…

Fix: 3.1+
Fix from $1,950 2018-01-25
389 Directory Server HIGH 8.1
CVE-2017-15135

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during th…

Fix: after 1.4.0.3
Fix from $1,950 2018-01-24
Reporter CRITICAL 9.8
CVE-2017-15531

Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users.…

Fix: 9.5.4.1+
Fix from $2,300 2018-01-23
Enterprise Manager HIGH 8.8
CVE-2017-16590

This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.699 build 1…

Mitigation only
Fix from $1,950 2018-01-23
Eshop HIGH 7.5
CVE-2015-6926

The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address …

Fix: after 4.4.8
Fix from $1,950 2018-01-19
Contractorweb.net CRITICAL 9.8
CVE-2018-5328

ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can…

No fix yet
Fix from $2,300 2018-01-15
Adsl Dsl5018en \(1t1r\) Firmware HIGH 7.5
CVE-2014-6435EPSS 13%

cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attacker…

No fix yet
Fix from $1,950 2018-01-12
Adsl Dsl5018en \(1t1r\) Firmware CRITICAL 9.8
CVE-2014-6436EPSS 42%

Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opp…

No fix yet
Fix from $2,300 2018-01-12
Junos MEDIUM 6.2
CVE-2018-0008

An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain in…

Mitigation only
Fix from $1,600 2018-01-10