Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Webaccess CRITICAL 9.8
CVE-2017-12698

An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible a…

Fix: after 8.2
Fix from $2,300 2017-08-30
Vcm5010 Firmware HIGH 8.8
CVE-2015-8332

Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows r…

Mitigation only
Fix from $1,950 2017-08-28
Ldap \/ Sso Authentication CRITICAL 9.8
CVE-2015-1401

Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.

Mitigation only
Fix from $2,300 2017-08-28
Pi Data Archive HIGH 7.4
CVE-2017-7930

An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws …

Fix: after 3.4.410.1256
Fix from $1,950 2017-08-25
Pi Data Archive MEDIUM 5.9
CVE-2017-7934

An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older prot…

Fix: after 3.4.410.1256
Fix from $1,600 2017-08-25
Dns 322l Firmware CRITICAL 9.8
CVE-2014-7857EPSS 15%

D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and …

Fix: after 2.00b07
Fix from $2,300 2017-08-25
Dnr 326 Firmware CRITICAL 9.8
CVE-2014-7858EPSS 15%

The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username c…

Fix: after 1.40b03
Fix from $2,300 2017-08-25
Dns 327l Firmware MEDIUM 5.3
CVE-2014-7860EPSS 10%

The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which …

Fix: after 1.03b04
Fix from $1,600 2017-08-25
Pykerberos HIGH 8.1
CVE-2015-3206

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a…

Patch available
Fix from $1,950 2017-08-25
Lxdm HIGH 7.8
CVE-2015-8308

LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.

Fix: after 0.5.1
Fix from $1,950 2017-08-24
Haproxy MEDIUM 5.3
CVE-2016-2102

HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.

No fix yet
Fix from $1,600 2017-08-22
Pony Mail CRITICAL 9.8
CVE-2016-4460EPSS 6%

Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.

Patch available
Fix from $2,300 2017-08-22
Dnsdist HIGH 8.8
CVE-2017-7557

dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.

Patch available
Fix from $1,950 2017-08-22
Enterprise Developer CRITICAL 9.8
CVE-2017-7420

An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterpr…

Fix: after 2.3
Fix from $2,300 2017-08-21
Kg Sha104 Firmware CRITICAL 9.8
CVE-2015-4464

Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server.

No fix yet
Fix from $2,300 2017-08-18
Policy Suite MEDIUM 5.3
CVE-2017-6781

A vulnerability in the management of shell user accounts for Cisco Policy Suite (CPS) Software for CPS appliances could allow an authenticated, local…

Mitigation only
Fix from $1,600 2017-08-17
PostgreSQL CRITICAL 9.8
CVE-2017-7546EPSS 62%

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain …

Mitigation only
Fix from $2,300 2017-08-16
Fedora CRITICAL 9.8
CVE-2015-6816

ganglia-web before 3.7.1 allows remote attackers to bypass authentication.

Fix: after 3.7.0
Fix from $2,300 2017-08-09
Workspaces HIGH 8.8
CVE-2017-9370

An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legi…

Mitigation only
Fix from $1,950 2017-08-09
Cxf CRITICAL 9.8
CVE-2012-0803

The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as pa…

Patch available
Fix from $2,300 2017-08-08
Photo Station CRITICAL 9.8
CVE-2017-11151EPSS 16%

A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files wi…

Fix: after 6.7.2-3429
Fix from $2,300 2017-08-08
Viewport For Web Office Portal CRITICAL 9.8
CVE-2017-6869

A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user …

Mitigation only
Fix from $2,300 2017-08-08
Simatic Wincc Sm\@rtclient MEDIUM 5.4
CVE-2017-6871

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Andr…

Fix: after 1.0.2.1
Fix from $1,600 2017-08-08
Sipass Integrated CRITICAL 9.8
CVE-2017-9939

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPas…

Fix: after 2.65
Fix from $2,300 2017-08-08
Debian Linux CRITICAL 9.8
CVE-2015-7871EPSS 82%

Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

Fix: 4.2.8 / 4.3.77+
Fix from $2,300 2017-08-07
Unitrends Backup CRITICAL 9.8
CVE-2017-12477EPSS 68%

It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which it…

Fix: 10.0+
Fix from $2,300 2017-08-07
Unitrends Backup CRITICAL 9.8
CVE-2017-12478EPSS 78%

It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not…

Fix: 10.0+
Fix from $2,300 2017-08-07
Vsn300 Firmware HIGH 7.5
CVE-2017-7920

An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versi…

Fix: after 1.8.15
Fix from $1,950 2017-08-07
Laserwash G5 Firmware CRITICAL 9.4
CVE-2017-9630

An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash…

Mitigation only
Fix from $2,300 2017-08-07
Identity Services Engine CRITICAL 9.8
CVE-2017-6747EPSS 5%

A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local …

Mitigation only
Fix from $2,300 2017-08-07