Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Integrated Management Controller Supervisor MEDIUM 5.4
CVE-2017-6617

A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) c…

Mitigation only
Fix from $1,600 2017-04-20
Garoon CRITICAL 9.8
CVE-2016-1219

Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.

Fix: after 4.2.1
Fix from $2,300 2017-04-20
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-5410

firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (…

Fix: after 0.4.3.2
Fix from $1,600 2017-04-19
Enterprise Backup HIGH 8.8
CVE-2017-7284

An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the passw…

Fix: after 9.1.1
Fix from $1,950 2017-04-12
Mfc Firmware CRITICAL 9.8
CVE-2017-7588EPSS 34%

On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affect…

No fix yet
Fix from $2,300 2017-04-12
Debian Linux CRITICAL 9.8
CVE-2016-1908EPSS 14%

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-contr…

Patch available
Fix from $2,300 2017-04-11
Aleos Firmware CRITICAL 9.8
CVE-2016-5068

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.

No fix yet
Fix from $2,300 2017-04-10
Tv Ip743sic HIGH 8.8
CVE-2015-2880

TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.

No fix yet
Fix from $1,950 2017-04-10
Ibootbar Firmware CRITICAL 9.8
CVE-2007-6759

Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle a…

Fix: after 2007-09-20
Fix from $2,300 2017-04-07
Ibootbar Firmware CRITICAL 9.8
CVE-2007-6760

Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attac…

Fix: after 2007-09-20
Fix from $2,300 2017-04-07
Hdmi Dongle Firmware CRITICAL 9.8
CVE-2017-7450

AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. It is possible to extract all…

Fix: after 2.1.1
Fix from $2,300 2017-04-05
Fibeair Ip 10 Firmware CRITICAL 9.8
CVE-2016-10309

In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value …

Fix: after 7.1.0
Fix from $2,300 2017-03-30
Ruggedcom Rox I HIGH 8.8
CVE-2017-2689

Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain pri…

Fix: after 2.9.0
Fix from $1,950 2017-03-29
Revive Adserver CRITICAL 9.8
CVE-2016-9124

Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable …

Fix: after 3.2.2
Fix from $2,300 2017-03-28
Nextcloud Server HIGH 8.1
CVE-2016-9463

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownC…

Fix: 8.2.9 / 9.0.4+
Fix from $1,950 2017-03-28
Ev 07s Gps Tracker Firmware HIGH 7.5
CVE-2017-5237

Due to a lack of authentication, an unauthenticated user who knows the Eview EV-07S GPS Tracker's phone number can revert the device to a factory def…

Mitigation only
Fix from $1,950 2017-03-27
Junos Space CRITICAL 9.8
CVE-2016-4926

Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to …

Fix: after 15.2
Fix from $2,300 2017-03-20
Adaptive Security Appliance Software MEDIUM 5.3
CVE-2017-3867

A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implementation of Cisco Adaptive Security Appliance (AS…

Mitigation only
Fix from $1,600 2017-03-17
Webex Meetings Server MEDIUM 6.5
CVE-2017-3880

An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting infor…

Mitigation only
Fix from $1,600 2017-03-17
Xrdp HIGH 7.3
CVE-2017-6967

xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with …

Patch available
Fix from $1,950 2017-03-17
Windows 10 HIGH 7.8
CVE-2017-0100

A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windo…

Patch available
Fix from $1,950 2017-03-17
Aironet Access Point Software CRITICAL 9.8
CVE-2017-3831EPSS 5%

A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass au…

Mitigation only
Fix from $2,300 2017-03-15
Wireless Lan Controller Firmware HIGH 8.8
CVE-2017-3854

A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote attacker to impersonate a WLC…

Mitigation only
Fix from $1,950 2017-03-15
Virusscan Enterprise HIGH 7.5
CVE-2016-8022EPSS 13%

Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated…

Fix: after 2.0.3
Fix from $1,950 2017-03-14
Virusscan Enterprise HIGH 8.1
CVE-2016-8023EPSS 9%

Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote u…

Fix: after 2.0.3
Fix from $1,950 2017-03-14
Zammad CRITICAL 9.8
CVE-2017-5619

An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g.…

Fix: after 1.0.3
Fix from $2,300 2017-03-13
Dnalims CRITICAL 9.8
CVE-2017-6526EPSS 57%

An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected adm…

No fix yet
Fix from $2,300 2017-03-09
Rt Ac53 Firmware HIGH 8.8
CVE-2017-6549EPSS 8%

Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87…

No fix yet
Fix from $1,950 2017-03-09
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2016-9729

IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. …

Patch available
Fix from $1,600 2017-03-07
Nefarious2 CRITICAL 9.8
CVE-2016-7145

The m_authenticate function in ircd/m_authenticate.c in nefarious2 allows remote attackers to spoof certificate fingerprints and consequently log in …

Patch available
Fix from $2,300 2017-03-07