Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Sunny Boy 3600 Firmware HIGH 8.1
CVE-2017-9857

An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: …

Mitigation only
Fix from $1,950 2017-08-05
Sunny Boy 3600 Firmware CRITICAL 9.8
CVE-2017-9860

An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device f…

Mitigation only
Fix from $2,300 2017-08-05
Malion HIGH 8.1
CVE-2017-10815

MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control" is insta…

Fix: after 5.2.1
Fix from $1,950 2017-08-04
Malion CRITICAL 9.8
CVE-2017-10817

MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server.

Fix: after 5.2.1
Fix from $2,300 2017-08-04
Xfinity Wifi Hotspot MEDIUM 5.9
CVE-2017-9475

Comcast XFINITY WiFi Home Hotspot devices allow remote attackers to spoof the identities of Comcast customers via a forged MAC address.

Mitigation only
Fix from $1,600 2017-07-31
4gt101w Software CRITICAL 9.8
CVE-2017-11645

NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 do not require authentication for logfile.html, status.…

Mitigation only
Fix from $2,300 2017-07-28
Wapm 1166d Firmware CRITICAL 9.8
CVE-2017-2126

WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access t…

Fix: after 1.16.1
Fix from $2,300 2017-07-22
Coaxdata Gateway 1gbps Firmware CRITICAL 9.8
CVE-2017-6530

Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 do not check password.shtml authorization, leading to Arbitrary password change.

Mitigation only
Fix from $2,300 2017-07-20
Rsa Authentication Manager MEDIUM 5.9
CVE-2017-8006

In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as…

Fix: after 8.2
Fix from $1,600 2017-07-17
Junos HIGH 8.8
CVE-2017-2341

An insufficient authentication vulnerability on platforms where Junos OS instances are run in a virtualized environment, may allow unprivileged users…

Mitigation only
Fix from $1,950 2017-07-17
Testtrack HIGH 7.5
CVE-2017-1000068

TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resulting in the ability to disab…

Fix: after 1.0
Fix from $1,950 2017-07-17
Phpcas HIGH 8.1
CVE-2017-1000071

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS…

Mitigation only
Fix from $1,950 2017-07-17
Junos CRITICAL 9.8
CVE-2017-10601

A specific device configuration can result in a commit failure condition. When this occurs, a user is logged in without being prompted for a password…

Mitigation only
Fix from $2,300 2017-07-17
Embedded Web Servers CRITICAL 9.8
CVE-2017-1000020

SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by …

Fix: after 1.3.1
Fix from $2,300 2017-07-17
Glassfish Server CRITICAL 9.8
CVE-2017-1000030

Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possib…

Mitigation only
Fix from $2,300 2017-07-17
Emptoris Strategic Supply Management HIGH 7.5
CVE-2016-8951

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vu…

Patch available
Fix from $1,950 2017-07-13
Windows 10 HIGH 7.5
CVE-2017-8495

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,…

Patch available
Fix from $1,950 2017-07-11
Impala CRITICAL 9.8
CVE-2017-5640

It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to ski…

Mitigation only
Fix from $2,300 2017-07-10
Solr HIGH 7.5
CVE-2017-7660EPSS 6%

Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node…

Mitigation only
Fix from $1,950 2017-07-07
Simatic Cp 44x 1 Redundant Network Access Modules HIGH 8.1
CVE-2017-6868

An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attacker may …

Fix: after 1.4.0
Fix from $1,950 2017-07-07
Home Spot Cube 2 Firmware HIGH 8.8
CVE-2017-2186

HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to bypass authentication to load malicious firmware via WebUI.

Mitigation only
Fix from $1,950 2017-07-07
Dir 615 CRITICAL 9.8
CVE-2017-7405

On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the…

Fix: after 20.12ptb01
Fix from $2,300 2017-07-07
Ultra Services Framework CRITICAL 9.1
CVE-2017-6711

A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain u…

Fix: after 5.0.2
Fix from $2,300 2017-07-06
Security Guardium HIGH 7.5
CVE-2017-1264

IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or fun…

Mitigation only
Fix from $1,950 2017-07-05
Security Guardium MEDIUM 6.5
CVE-2017-1258

IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access…

Mitigation only
Fix from $1,600 2017-07-05
Jabberd2 CRITICAL 9.8
CVE-2017-10807

JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enable…

Fix: after 2.6.0
Fix from $2,300 2017-07-04
Prime Collaboration Provisioning MEDIUM 5.9
CVE-2017-6703

A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack a…

Mitigation only
Fix from $1,600 2017-07-04
Unified Contact Center Express MEDIUM 6.1
CVE-2017-6722

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauth…

Mitigation only
Fix from $1,600 2017-07-04
Xps Cx Firmware CRITICAL 9.8
CVE-2017-7919

An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific uniform r…

Mitigation only
Fix from $2,300 2017-07-03
Nc250 Firmware MEDIUM 6.5
CVE-2017-10796

On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:…

Fix: after 1.2.1
Fix from $1,600 2017-07-02