Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Vcenter Server HIGH 7.6
CVE-2016-2076

Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Iden…

Fix: after 6.0
Fix from $1,950 2016-04-15
Ranger CRITICAL 9.8
CVE-2016-0733

The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to by…

Fix: after 0.5.0
Fix from $2,300 2016-04-12
Support Assistant CRITICAL 9.8
CVE-2016-2245EPSS 6%

HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.

Fix: after 8.1.40.3
Fix from $2,300 2016-03-19
X14j Firmware CRITICAL 9.8
CVE-2016-1329

Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardc…

Fix: 2.50+
Fix from $2,300 2016-03-03
Gs1900 10hp Firmware MEDIUM 5.4
CVE-2016-1307

The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it e…

Fix: 2.50+
Fix from $1,600 2016-02-07
Moduweb Vision HIGH 8.1
CVE-2015-7914

Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without k…

Fix: after 1.5.5
Fix from $1,950 2016-02-06
Smart Toy Bear HIGH 7.5
CVE-2015-8269

The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 80…

Mitigation only
Fix from $1,950 2016-02-04
Curl HIGH 7.3
CVE-2016-0755EPSS 9%

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow …

Fix: after 7.46.0
Fix from $1,950 2016-01-29
Hive HIGH 8.3
CVE-2015-7521EPSS 6%

The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, …

No fix yet
Fix from $1,950 2016-01-29
Debian Linux HIGH 7.7
CVE-2015-7974EPSS 6%

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remot…

Fix: 4.2.8 / 4.3.90+
Fix from $1,950 2016-01-26
Wireless Lan Controller Software CRITICAL 9.8
CVE-2015-6314

Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change conf…

Mitigation only
Fix from $2,300 2016-01-15
Eki 1321 Series Firmware CRITICAL 9.8
CVE-2015-7938

Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors.

Fix: after 2015-10-06
Fix from $2,300 2016-01-09
Oncell Central Manager HIGH 8.3
CVE-2015-6480

The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain a…

Fix: after 2.0
Fix from $1,950 2015-12-21
Hive HIGH 7.3
CVE-2015-1772EPSS 7%

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.…

Mitigation only
Fix from $1,950 2015-12-21
Screenos CRITICAL 9.8
CVE-2015-7755 KEVEPSS 61%

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15…

Mitigation only
Fix from $2,300 2015-12-19
Epc3928 Docsis 3.0 8x4 Wireless Residential Gateway With Embedded Digital Voice Adapter HIGH 7.5
CVE-2015-6401EPSS 8%

Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspeci…

No fix yet
Fix from $1,950 2015-12-14
Prime Collaboration Assurance HIGH 9.0
CVE-2015-6389

Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH…

Mitigation only
Fix from $1,950 2015-12-13
Gprs Cs2300 R Firmware MEDIUM 5.8
CVE-2015-7285

CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allo…

No fix yet
Fix from $1,600 2015-11-25
Fortios HIGH 9.3
CVE-2015-7361

FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for a…

Mitigation only
Fix from $1,950 2015-10-15
Garoon HIGH 7.0
CVE-2015-5649

Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP inj…

Mitigation only
Fix from $1,950 2015-10-08
Nevisauth MEDIUM 5.0
CVE-2015-5372

The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 c…

Fix: after 4.18.3.0
Fix from $1,600 2015-09-28
iOS HIGH 9.3
CVE-2015-6280

The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S before 3.10.6S, 3.11S before…

Mitigation only
Fix from $1,950 2015-09-28
Impero Education Pro HIGH 10.0
CVE-2015-5998

Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remote attackers to execute arbitr…

Fix: after 5008
Fix from $1,950 2015-09-14
Netsweeper HIGH 9.4
CVE-2014-9605

WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a syst…

Fix: 3.1.10 / 4.0.9+
Fix from $1,950 2015-09-04
Identity Services Engine Software MEDIUM 5.0
CVE-2015-6266

The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote att…

Mitigation only
Fix from $1,600 2015-08-28
Activemq HIGH 7.5
CVE-2014-3612EPSS 7%

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att…

Mitigation only
Fix from $1,950 2015-08-24
Mac Os X HIGH 7.2
CVE-2015-3775

Apple OS X before 10.10.5 does not properly implement authentication, which allows local users to obtain admin privileges via unspecified vectors.

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Endpoint Protection Manager HIGH 7.5
CVE-2015-1486EPSS 68%

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a…

No fix yet
Fix from $1,950 2015-08-01
Yoyaku MEDIUM 5.0
CVE-2015-2978

Webservice-DIC yoyaku_v41 allows remote attackers to bypass authentication and complete a conference-room reservation via unspecified vectors, as dem…

No fix yet
Fix from $1,600 2015-07-29
Openemr MEDIUM 5.0
CVE-2015-4453

interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive informa…

Patch available
Fix from $1,600 2015-07-05