Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Enterprise Network Operating System HIGH 7.0
CVE-2017-3765

In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoo…

Fix: 8.4.6.0+
Fix from $1,950 2018-01-10
Shanghai Onstar HIGH 8.8
CVE-2017-12695

An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this …

Mitigation only
Fix from $1,950 2018-01-09
Sitefinity CRITICAL 9.8
CVE-2017-15883

Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of servic…

Mitigation only
Fix from $2,300 2018-01-08
Communigate Pro MEDIUM 5.7
CVE-2018-3815

The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS…

No fix yet
Fix from $1,600 2018-01-08
Avamar Server CRITICAL 9.8
CVE-2017-15548

An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Inte…

Mitigation only
Fix from $2,300 2018-01-05
Mautic HIGH 8.1
CVE-2017-1000489

Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address

Mitigation only
Fix from $1,950 2018-01-03
Debian Linux HIGH 8.1
CVE-2017-1000433

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without k…

Fix: after 4.4.0
Fix from $1,950 2018-01-02
Smart Google Code Inserter CRITICAL 9.8
CVE-2018-3810EPSS 91%

Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to inse…

Fix: 3.5+
Fix from $2,300 2018-01-01
Jboss Fuse CRITICAL 9.8
CVE-2014-0121

The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.

Fix: after 1.2.2
Fix from $2,300 2017-12-29
Ip360 CRITICAL 9.8
CVE-2015-6237

The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerat…

Mitigation only
Fix from $2,300 2017-12-27
Puppetlabs Mysql CRITICAL 9.8
CVE-2015-7224

puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password …

Fix: after 3.6.0
Fix from $2,300 2017-12-21
Paid To Read Script CRITICAL 9.8
CVE-2017-17777

Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parame…

No fix yet
Fix from $2,300 2017-12-20
My Cloud Pr4100 Firmware CRITICAL 9.8
CVE-2017-17560EPSS 73%

An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.ph…

Patch available
Fix from $2,300 2017-12-12
Business Intelligence Promotion Management Application CRITICAL 9.8
CVE-2017-16684

SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionaliti…

Mitigation only
Fix from $2,300 2017-12-12
Sap Kernel HIGH 8.8
CVE-2017-16689

A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT, 7.22, 7.22EXT; SAP KERNEL f…

Mitigation only
Fix from $1,950 2017-12-12
Netborder\/vega Session Firmware CRITICAL 9.8
CVE-2017-17430

Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface.

Mitigation only
Fix from $2,300 2017-12-07
Vt20i Firmware HIGH 8.8
CVE-2017-17435

An issue was discovered in the software on Vaultek Gun Safe VT20i products, aka BlueSteal. An attacker can remotely unlock any safe in this product l…

Mitigation only
Fix from $1,950 2017-12-07
Zxdsl 831cii Firmware HIGH 7.5
CVE-2017-16953EPSS 11%

connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration …

No fix yet
Fix from $1,950 2017-12-01
Ptw Wms1 Firmware CRITICAL 9.8
CVE-2017-10903

Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device with root privileges and conduct…

Mitigation only
Fix from $2,300 2017-12-01
Authentication Agent For Web CRITICAL 9.8
CVE-2017-14377

EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Bu…

Mitigation only
Fix from $2,300 2017-11-29
Mac Os X HIGH 8.1
CVE-2017-13872EPSS 37%

An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory U…

Patch available
Fix from $1,950 2017-11-29
Nvr11hs Firmware MEDIUM 6.5
CVE-2017-9316

Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal D…

Patch available
Fix from $1,600 2017-11-27
Zulip Server HIGH 8.8
CVE-2017-0910

In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the …

Fix: 1.7.1+
Fix from $1,950 2017-11-27
Debian Linux HIGH 8.1
CVE-2017-8028

In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP Bind…

Mitigation only
Fix from $1,950 2017-11-27
Honor 8 Firmware MEDIUM 6.2
CVE-2017-8214

Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, …

Mitigation only
Fix from $1,600 2017-11-22
Fusionsphere Openstack HIGH 8.8
CVE-2017-8194

The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authen…

Mitigation only
Fix from $1,950 2017-11-22
Fusionsphere Openstack HIGH 8.8
CVE-2017-8195

The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authen…

Mitigation only
Fix from $1,950 2017-11-22
Honor 5s Firmware MEDIUM 6.8
CVE-2017-8151

Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design…

Mitigation only
Fix from $1,600 2017-11-22
Vcm5010 Firmware CRITICAL 9.8
CVE-2017-2738

VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability. This is due to improper implementation of…

Mitigation only
Fix from $2,300 2017-11-22
3960hd Firmware CRITICAL 9.8
CVE-2017-8861

Missing authentication for the remote configuration port 1236/tcp on the Cohu 3960HD allows an attacker to change configuration parameters such as IP…

Mitigation only
Fix from $2,300 2017-11-22