Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ininet Webserver CRITICAL 10.0
CVE-2017-13995

An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not proper…

Fix: after 2.02.0000
Fix from $2,300 2017-10-05
Skyrouter Z4200 Firmware CRITICAL 9.4
CVE-2017-14000

An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a specific unifo…

Fix: after 6.00.05
Fix from $2,300 2017-10-05
Blue Ocean HIGH 8.5
CVE-2017-1000106

Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing …

Fix: after 1.1.5
Fix from $1,950 2017-10-05
Sentinel Ldk Rte Firmware CRITICAL 9.8
CVE-2017-12819

Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK produ…

Fix: after 7.50
Fix from $2,300 2017-10-04
Bsm Platform Application Performance Management System Health CRITICAL 9.8
CVE-2017-13983EPSS 6%

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows rem…

Mitigation only
Fix from $2,300 2017-09-30
Bsm Platform Application Performance Management System Health MEDIUM 6.5
CVE-2017-13984

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows rem…

Mitigation only
Fix from $1,600 2017-09-30
Ios Xe CRITICAL 9.8
CVE-2017-12229EPSS 5%

A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote atta…

Mitigation only
Fix from $2,300 2017-09-29
Ios Xe CRITICAL 9.8
CVE-2017-12236

A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, r…

Mitigation only
Fix from $2,300 2017-09-29
Simple Student Result HIGH 7.5
CVE-2017-14766

The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function an…

Fix: after 1.6.3
Fix from $1,950 2017-09-27
Application Delivery Controller Firmware HIGH 7.2
CVE-2017-14602

A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 …

Patch available
Fix from $1,950 2017-09-26
Salt HIGH 8.8
CVE-2017-5192

When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, externa…

Fix: after 2015.8.12
Fix from $1,950 2017-09-26
I Suite CRITICAL 9.8
CVE-2017-14706EPSS 28%

DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservice…

Patch available
Fix from $2,300 2017-09-22
Mobile Security CRITICAL 9.8
CVE-2017-14080

Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific par…

Patch available
Fix from $2,300 2017-09-22
Dir 626l Firmware CRITICAL 9.8
CVE-2015-1187 KEVEPSS 83%

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

Mitigation only
Fix from $2,300 2017-09-21
Ldap HIGH 8.1
CVE-2017-14623

In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application…

Fix: after 2.5.0
Fix from $1,950 2017-09-20
Ruby HIGH 8.8
CVE-2017-10784EPSS 16%

The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject …

Fix: after 2.2.7
Fix from $1,950 2017-09-19
Netsweeper CRITICAL 9.8
CVE-2014-9611EPSS 13%

Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/i…

Fix: after 4.0.4
Fix from $2,300 2017-09-19
Netsweeper CRITICAL 9.8
CVE-2014-9618EPSS 73%

The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authenticati…

Fix: after 3.1.9
Fix from $2,300 2017-09-19
Solr HIGH 7.5
CVE-2017-9803

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or a…

Mitigation only
Fix from $1,950 2017-09-18
Wa3002g4 Firmware CRITICAL 9.8
CVE-2017-14243EPSS 15%

An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administr…

No fix yet
Fix from $2,300 2017-09-17
Misp HIGH 8.1
CVE-2017-14337

When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST A…

Fix: after 2.4.79
Fix from $1,950 2017-09-12
Mantisbt HIGH 7.5
CVE-2014-9624

CAPTCHA bypass vulnerability in MantisBT before 1.2.19.

Fix: after 1.2.18
Fix from $1,950 2017-09-12
Kura CRITICAL 9.8
CVE-2017-7649

The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be con…

Fix: after 2.0.2
Fix from $2,300 2017-09-11
Debian Linux MEDIUM 6.5
CVE-2017-7650

In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or rem…

Fix: 1.4.12+
Fix from $1,600 2017-09-11
Prime Lan Management Solution MEDIUM 6.5
CVE-2017-12225

A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another u…

Mitigation only
Fix from $1,600 2017-09-07
Adsl An1020 25 Firmware CRITICAL 9.8
CVE-2017-14147EPSS 66%

An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its …

No fix yet
Fix from $2,300 2017-09-07
Xpert.line CRITICAL 9.8
CVE-2015-3442

Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API call.

No fix yet
Fix from $2,300 2017-09-07
U Verse Firmware MEDIUM 5.9
CVE-2017-14117EPSS 8%

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures an unauthenticated pro…

No fix yet
Fix from $1,600 2017-09-03
Data Ontap CRITICAL 9.8
CVE-2015-7746

NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtain sensitive information from …

Fix: after 8.2.3
Fix from $2,300 2017-09-01
Mbed Tls HIGH 8.1
CVE-2017-14032

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via …

Patch available
Fix from $1,950 2017-08-30