Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Debian Linux CRITICAL 9.8
CVE-2017-16613EPSS 8%

An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and …

Fix: after 2.15.1
Fix from $2,300 2017-11-21
Jooan A5 Ip Camera Firmware CRITICAL 9.8
CVE-2017-16566

On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core s…

Mitigation only
Fix from $2,300 2017-11-17
Emergency Responder CRITICAL 9.8
CVE-2017-12337EPSS 6%

A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an u…

Mitigation only
Fix from $2,300 2017-11-16
Identity Services Engine Software HIGH 7.5
CVE-2017-12316

A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform mul…

Mitigation only
Fix from $1,950 2017-11-16
Psftpd MEDIUM 5.3
CVE-2017-15272

The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The app…

No fix yet
Fix from $1,600 2017-11-15
Nvr5464 16p 4ks2 Firmware HIGH 8.8
CVE-2017-9314

Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171…

Mitigation only
Fix from $1,950 2017-11-13
Userpro CRITICAL 9.8
CVE-2017-16562EPSS 27%

The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and…

Fix: 4.9.17.1+
Fix from $2,300 2017-11-10
Joomla\! CRITICAL 9.8
CVE-2017-16634

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

Fix: after 3.8.1
Fix from $2,300 2017-11-10
Circle With Disney Firmware HIGH 8.1
CVE-2017-2914

An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token c…

No fix yet
Fix from $1,950 2017-11-07
Circle With Disney Firmware CRITICAL 9.8
CVE-2017-2864

An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets …

Mitigation only
Fix from $2,300 2017-11-07
Mahara CRITICAL 9.8
CVE-2017-1000154

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara'…

Patch available
Fix from $2,300 2017-11-03
Aironet 1800 Firmware HIGH 7.5
CVE-2017-12281

A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Air…

Mitigation only
Fix from $1,950 2017-11-02
Openam HIGH 8.1
CVE-2017-10873

OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vul…

Fix: after 13.0.0-73
Fix from $1,950 2017-11-02
Bigfix Platform MEDIUM 6.5
CVE-2017-1222

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allow…

Patch available
Fix from $1,600 2017-10-26
Keycloak HIGH 7.2
CVE-2017-12160

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit…

Mitigation only
Fix from $1,950 2017-10-26
Apogee Pxc Firmware HIGH 7.5
CVE-2017-9946EPSS 25%

A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network …

Fix: 3.5+
Fix from $1,950 2017-10-23
Nifi HIGH 7.5
CVE-2017-5635

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin…

Mitigation only
Fix from $1,950 2017-10-19
Cloud Services Platform 2100 CRITICAL 9.9
CVE-2017-12251

A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciou…

Mitigation only
Fix from $2,300 2017-10-19
Email Marketer CRITICAL 9.8
CVE-2017-14322EPSS 37%

The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attack…

Fix: after 6.1.5
Fix from $2,300 2017-10-18
Envidas Ultimate HIGH 8.2
CVE-2017-9625

An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authenticat…

Fix: after 1.0.0.4
Fix from $1,950 2017-10-17
Point Of Sale Xpress Server CRITICAL 9.8
CVE-2017-15295

Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.

Mitigation only
Fix from $2,300 2017-10-16
Host Agent HIGH 7.5
CVE-2017-15297

SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.

Mitigation only
Fix from $1,950 2017-10-16
Point Of Sale Xpress Server CRITICAL 9.8
CVE-2017-15293

Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain at…

Mitigation only
Fix from $2,300 2017-10-16
Junos Space CRITICAL 9.8
CVE-2017-10622EPSS 5%

An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based a…

Mitigation only
Fix from $2,300 2017-10-13
Junos Space HIGH 8.1
CVE-2017-10623

Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to interc…

Fix: after 16.2
Fix from $1,950 2017-10-13
Jtc 200 Firmware CRITICAL 9.8
CVE-2016-5791

An Improper Authentication issue was discovered in JanTek JTC-200, all versions. The improper authentication could provide an undocumented BusyBox Li…

Mitigation only
Fix from $2,300 2017-10-13
Intelligent Management Center Plat CRITICAL 9.8
CVE-2017-5791EPSS 69%

The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via un…

Mitigation only
Fix from $2,300 2017-10-11
Ether Serial Link Firmware CRITICAL 9.8
CVE-2017-14003

An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior vers…

Fix: after 6.01.00
Fix from $2,300 2017-10-11
Mondopad HIGH 7.5
CVE-2017-14972

InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Mana…

No fix yet
Fix from $1,950 2017-10-09
Tivoli Storage Manager CRITICAL 9.8
CVE-2016-8937

The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclo…

Patch available
Fix from $2,300 2017-10-05