Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Secure Firewall Management Center HIGH 7.8
CVE-2016-6434

Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CL…

No fix yet
Fix from $1,950 2016-10-06
Onetouch Ping Firmware CRITICAL 9.8
CVE-2016-5686

Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a …

Mitigation only
Fix from $2,300 2016-10-05
Onetouch Ping Firmware CRITICAL 9.8
CVE-2016-5086

Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.

Mitigation only
Fix from $2,300 2016-10-05
Leap HIGH 7.5
CVE-2016-7141EPSS 8%

curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authen…

Fix: after 7.50.1
Fix from $1,950 2016-10-03
Azure Active Directory Passport HIGH 8.1
CVE-2016-7191EPSS 29%

The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize th…

Patch available
Fix from $1,950 2016-09-28
Ws331a Router Firmware HIGH 7.5
CVE-2016-6159

The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and…

Mitigation only
Fix from $1,950 2016-09-21
Fortiwan MEDIUM 6.5
CVE-2016-4966

The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via v…

Fix: after 4.2.4
Fix from $1,600 2016-09-21
Stardom Fcn\/fcj HIGH 7.3
CVE-2016-4860

Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers…

Mitigation only
Fix from $1,950 2016-09-19
Operations Manager CRITICAL 9.8
CVE-2016-0883

Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installa…

Fix: after 1.5.13
Fix from $2,300 2016-09-18
Junos CRITICAL 9.8
CVE-2016-1279

J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 1…

Fix: after 12.1x46
Fix from $2,300 2016-09-09
En100 Ethernet Module Firmware HIGH 8.8
CVE-2016-7114

A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP …

Mitigation only
Fix from $1,950 2016-09-06
En100 Ethernet Module Firmware CRITICAL 9.8
CVE-2016-7112

A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP …

Fix: after 4.28
Fix from $2,300 2016-09-06
Media Origination System Suite HIGH 8.1
CVE-2016-6377

Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and ma…

Mitigation only
Fix from $1,950 2016-09-03
Rv110w Wireless N Vpn Firewall Firmware HIGH 8.8
CVE-2015-6397

Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obt…

Mitigation only
Fix from $1,950 2016-08-08
Junos HIGH 7.8
CVE-2016-1278

Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a…

Fix: after 12.1x46
Fix from $1,950 2016-08-05
Chrome MEDIUM 5.3
CVE-2016-5133

Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a prox…

Fix: after 51.0.2704.106
Fix from $1,600 2016-07-23
Device Server Web Console 5232 N Firmware CRITICAL 9.8
CVE-2016-4503

Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings and data, via vectors relate…

Mitigation only
Fix from $2,300 2016-07-12
Ntp HIGH 7.5
CVE-2016-4953EPSS 17%

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypt…

Fix: 4.2.8 / 4.3.93+
Fix from $1,950 2016-07-05
Prime Network Registrar HIGH 7.5
CVE-2016-1427

The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remo…

Mitigation only
Fix from $1,950 2016-06-18
Cloudstack MEDIUM 6.5
CVE-2016-3085

Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl…

No fix yet
Fix from $1,600 2016-06-10
Networker CRITICAL 9.8
CVE-2016-0916EPSS 8%

EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary…

Fix: 8.2.2.6 / 9.0.0.6+
Fix from $2,300 2016-06-10
Vtscada CRITICAL 9.1
CVE-2016-4510EPSS 20%

The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbit…

Mitigation only
Fix from $2,300 2016-06-09
Qpid Broker J CRITICAL 9.1
CVE-2016-4432EPSS 8%

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons…

Fix: 6.0.3+
Fix from $2,300 2016-06-01
Qpid Broker J MEDIUM 5.9
CVE-2016-3094EPSS 8%

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a…

Fix: after 6.0.2
Fix from $1,600 2016-06-01
Miineport E2 1242 Firmware HIGH 7.5
CVE-2016-2286

Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 …

Mitigation only
Fix from $1,950 2016-05-31
Identity Services Engine Software HIGH 7.5
CVE-2016-1402

The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorizati…

Mitigation only
Fix from $1,950 2016-05-21
Network Node Manager I MEDIUM 6.5
CVE-2016-2012

HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors.

Patch available
Fix from $1,600 2016-05-07
Debian Linux CRITICAL 9.8
CVE-2016-4422

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg…

Mitigation only
Fix from $2,300 2016-05-06
Telepresence Tc Software CRITICAL 9.8
CVE-2016-1387

The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8…

Mitigation only
Fix from $2,300 2016-05-05
Integraxor MEDIUM 6.5
CVE-2016-2300

Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.

Fix: after 4.2.4502
Fix from $1,600 2016-04-22