Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Zen Mobile App Native HIGH 7.5
CVE-2017-6104EPSS 7%

Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

Fix: after 3.0
Fix from $1,950 2017-03-02
Mod Auth Openidc HIGH 8.6
CVE-2017-6413

The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip …

Fix: after 2.1.5
Fix from $1,950 2017-03-02
Mod Auth Openidc HIGH 8.6
CVE-2017-6062

The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip …

Fix: after 2.1.4
Fix from $1,950 2017-03-02
Camera Firmware HIGH 8.1
CVE-2017-6343EPSS 60%

The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and Smart…

Mitigation only
Fix from $1,950 2017-02-27
FreeBSD HIGH 7.5
CVE-2016-1888

The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vec…

Mitigation only
Fix from $1,950 2017-02-15
Nport 5100 Series Firmware CRITICAL 9.8
CVE-2016-9361EPSS 20%

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2…

Fix: after 3.10
Fix from $2,300 2017-02-13
Pfc200 Firmware CRITICAL 9.1
CVE-2016-9362

An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 075…

Mitigation only
Fix from $2,300 2017-02-13
Nport 5100 Series Firmware CRITICAL 9.8
CVE-2016-9369EPSS 9%

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2…

Fix: after 3.10
Fix from $2,300 2017-02-13
Webaccess CRITICAL 9.1
CVE-2017-5152

An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious use…

Mitigation only
Fix from $2,300 2017-02-13
Oncellg3470a Lte Firmware MEDIUM 6.5
CVE-2016-8362

An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, W…

Fix: after 10-31-2016
Fix from $1,600 2017-02-13
Webdatorcentral CRITICAL 9.8
CVE-2016-8347

An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0. WDC does not limit authentication attempts that may al…

Mitigation only
Fix from $2,300 2017-02-13
Isilon Insightiq CRITICAL 9.8
CVE-2017-2765

EMC Isilon InsightIQ 4.1.0, 4.0.1, 4.0.0, 3.2.2, 3.2.1, 3.2.0, 3.1.1, 3.1.0, 3.0.1, 3.0.0 is affected by an authentication bypass vulnerability that …

Mitigation only
Fix from $2,300 2017-02-08
Snapcenter Server HIGH 7.3
CVE-2016-1502

NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified ve…

Patch available
Fix from $1,950 2017-02-07
Symfony CRITICAL 9.8
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, w…

Mitigation only
Fix from $2,300 2017-02-07
Smarts Network Configuration Manager CRITICAL 9.8
CVE-2017-2767EPSS 6%

EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC …

Mitigation only
Fix from $2,300 2017-02-03
Smarts Network Configuration Manager CRITICAL 9.8
CVE-2017-2768

EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC …

No fix yet
Fix from $2,300 2017-02-03
Cisco Prime Home CRITICAL 10.0
CVE-2017-3791

A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions…

Mitigation only
Fix from $2,300 2017-02-01
Salt MEDIUM 5.6
CVE-2016-3176

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentica…

Fix: after 2015.5.9
Fix from $1,600 2017-01-31
Webex Meetings Server MEDIUM 5.4
CVE-2017-3795

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct arbitrary password changes against any non-ad…

Mitigation only
Fix from $1,600 2017-01-26
Cryptsetup MEDIUM 6.8
CVE-2016-4484

The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in …

Fix: after 2.1.7.3-2
Fix from $1,600 2017-01-23
Oxygenos HIGH 8.1
CVE-2017-5554

An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be…

Fix: after 3.5.4
Fix from $1,950 2017-01-23
Unrealircd HIGH 8.1
CVE-2016-7144

The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate finge…

Fix: after 3.2.10.5
Fix from $1,950 2017-01-18
Cloud Foundry Uaa Bosh HIGH 8.1
CVE-2016-6659

Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) bef…

Fix: after 247.0
Fix from $1,950 2016-12-23
iOS HIGH 7.3
CVE-2016-6474

A vulnerability in the implementation of X.509 Version 3 for SSH authentication functionality in Cisco IOS and IOS XE Software could allow an unauthe…

Mitigation only
Fix from $1,950 2016-12-14
Bladelogic Server Automation Console CRITICAL 9.8
CVE-2016-4322EPSS 5%

BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or p…

No fix yet
Fix from $2,300 2016-12-13
Omnivista 8770 Network Management System CRITICAL 9.8
CVE-2016-9796EPSS 13%

Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An a…

No fix yet
Fix from $2,300 2016-12-03
Bigfix Remote Control CRITICAL 9.8
CVE-2016-2944

IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access …

Fix: after 9.1.2
Fix from $2,300 2016-11-30
Prime Home CRITICAL 9.8
CVE-2016-6452

A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authent…

Mitigation only
Fix from $2,300 2016-11-03
Ip Interoperability And Collaboration System CRITICAL 9.8
CVE-2016-6397

A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Service…

Mitigation only
Fix from $2,300 2016-10-28
Wireless H500 MEDIUM 5.3
CVE-2016-1000214

Ruckus Wireless H500 web management interface authentication bypass

Mitigation only
Fix from $1,600 2016-10-25