Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Android MEDIUM 6.8
CVE-2017-10709

The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressin…

Mitigation only
Fix from $1,600 2017-06-30
Modbus Firmware CRITICAL 9.8
CVE-2017-6034EPSS 5%

An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted i…

No fix yet
Fix from $2,300 2017-06-30
Opendaylight CRITICAL 9.8
CVE-2015-1778

The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and pass…

Patch available
Fix from $2,300 2017-06-27
Avamar Server CRITICAL 9.8
CVE-2017-4989

In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypa…

Mitigation only
Fix from $2,300 2017-06-21
HTTP Server CRITICAL 9.8
CVE-2017-3167EPSS 20%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication p…

Fix: 2.2.33 / 2.4.26+
Fix from $2,300 2017-06-20
Xclarity Administrator HIGH 7.8
CVE-2017-3745

In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password …

Fix: after 1.2.2
Fix from $1,950 2017-06-20
Photo Station HIGH 7.8
CVE-2017-9552

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology …

Mitigation only
Fix from $1,950 2017-06-13
Dir 615 Firmware CRITICAL 9.8
CVE-2017-9542EPSS 5%

D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to val…

Mitigation only
Fix from $2,300 2017-06-11
Skysea Client View CRITICAL 9.8
CVE-2016-7836 KEVEPSS 19%

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the mana…

Fix: after 11.221.03
Fix from $2,300 2017-06-09
S5700 Firmware HIGH 7.5
CVE-2015-2800

The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH012 and S7700, S9300, and S97…

Mitigation only
Fix from $1,950 2017-06-08
Personify360 E Business HIGH 7.5
CVE-2017-7314

An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of databa…

Fix: after 7.6.1
Fix from $1,950 2017-06-07
MongoDB MEDIUM 5.5
CVE-2014-8180

MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can caus…

Patch available
Fix from $1,600 2017-06-06
Android HIGH 7.8
CVE-2014-9952

In the Secure File System in all Android releases from CAF using the Linux kernel, a capture-replay vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Freeradius CRITICAL 9.8
CVE-2017-9148

The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably …

Mitigation only
Fix from $2,300 2017-05-29
Spring Security HIGH 7.3
CVE-2014-0097

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows…

Mitigation only
Fix from $1,950 2017-05-25
Spring Security CRITICAL 9.8
CVE-2014-3527

When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authent…

Mitigation only
Fix from $2,300 2017-05-25
Pgbouncer HIGH 8.1
CVE-2015-6817

PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.

Patch available
Fix from $1,950 2017-05-23
Dir 600m Firmware HIGH 8.8
CVE-2017-9100EPSS 85%

login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the…

No fix yet
Fix from $1,950 2017-05-21
Dolibarr Erp\/crm MEDIUM 6.8
CVE-2017-8879

Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to ob…

No fix yet
Fix from $1,600 2017-05-10
Genixcms CRITICAL 9.1
CVE-2017-8827

forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibl…

Patch available
Fix from $2,300 2017-05-08
Mesr901 Firmware CRITICAL 9.8
CVE-2017-7909

A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses…

Fix: after 1.5.2
Fix from $2,300 2017-05-06
Ds 2cd2032 I Firmware CRITICAL 9.8
CVE-2017-7921 KEVEPSS 100%

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5…

Patch available
Fix from $2,300 2017-05-06
iOS MEDIUM 5.3
CVE-2017-6624

A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthoriz…

Mitigation only
Fix from $1,600 2017-05-03
4k Camera Firmware HIGH 8.8
CVE-2017-8403

360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, whi…

Mitigation only
Fix from $1,950 2017-05-01
Appgoat HIGH 7.3
CVE-2017-2101

Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to perform arb…

Fix: after 3.0.0
Fix from $1,950 2017-04-28
Wireless Ip Camera \(p2p\) Firmware HIGH 7.5
CVE-2017-8223

On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via …

No fix yet
Fix from $1,950 2017-04-25
Northstar Controller HIGH 8.3
CVE-2017-2319

A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromi…

Fix: after 2.1.0
Fix from $1,950 2017-04-24
Northstar Controller MEDIUM 6.2
CVE-2017-2329

An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an …

Fix: after 2.1.0
Fix from $1,600 2017-04-24
Northstar Controller HIGH 8.8
CVE-2017-2332

An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a m…

Fix: after 2.1.0
Fix from $1,950 2017-04-24
Tl Sg108e Firmware MEDIUM 5.3
CVE-2017-8078

On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This af…

No fix yet
Fix from $1,600 2017-04-23