Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ubuntu Linux MEDIUM 6.8
CVE-2015-1330

unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in…

Fix: after 0.86
Fix from $1,600 2015-07-01
Resident Anywhere HIGH 7.5
CVE-2014-4882

Aptexx Resident Anywhere does not require authentication, which allows remote attackers to obtain sensitive information or modify data via a direct r…

Mitigation only
Fix from $1,950 2015-06-23
Tippingpoint Security Management System HIGH 7.5
CVE-2015-2117EPSS 9%

HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1…

Fix: after 4.2
Fix from $1,950 2015-04-27
Wincc MEDIUM 6.8
CVE-2015-2823

Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Up…

Fix: after 13.0
Fix from $1,600 2015-04-08
General Parallel File System HIGH 10.0
CVE-2015-0198

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows …

Patch available
Fix from $1,950 2015-03-24
Spa500 Firmware MEDIUM 6.4
CVE-2015-0670

The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows re…

Mitigation only
Fix from $1,600 2015-03-21
Expressway Software HIGH 10.0
CVE-2015-0653

The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before…

Mitigation only
Fix from $1,950 2015-03-13
Netmri HIGH 10.0
CVE-2015-2033

Anyterm Daemon in Infoblox Network Automation NetMRI before NETMRI-23483 allows remote attackers to execute arbitrary commands with root privileges v…

Fix: after 6.8.2.11
Fix from $1,950 2015-02-20
Owncloud MEDIUM 5.0
CVE-2014-9045

The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requ…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Owncloud MEDIUM 5.0
CVE-2014-9043

The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Webex Meetings Server MEDIUM 5.0
CVE-2014-8033

The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID…

Mitigation only
Fix from $1,600 2015-01-09
Vdg Sense MEDIUM 5.0
CVE-2014-9578

VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain l…

No fix yet
Fix from $1,600 2015-01-08
Umbraco Cms HIGH 7.5
CVE-2013-4793

The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require…

Fix: after 6.0.3
Fix from $1,950 2014-12-27
Hp Ux HIGH 8.5
CVE-2014-7879

HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configuration includes libpam_updbe, allows remote authenticated users to bypass authentication,…

Patch available
Fix from $1,950 2014-12-10
Cloudstack MEDIUM 5.0
CVE-2014-7807

Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, …

Mitigation only
Fix from $1,600 2014-12-10
Graylog2 MEDIUM 5.0
CVE-2014-9217

Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.

Fix: after 0.91.3
Fix from $1,600 2014-12-08
Rsa Adaptive Authentication On Premise MEDIUM 5.0
CVE-2014-4631

RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authent…

Mitigation only
Fix from $1,600 2014-12-08
Zxdsl MEDIUM 5.0
CVE-2014-9184

ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) …

No fix yet
Fix from $1,600 2014-12-02
Vap2500 Firmware HIGH 7.8
CVE-2014-8424EPSS 60%

ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.

Fix: after 08.41
Fix from $1,950 2014-11-28
Qradar Risk Manager MEDIUM 5.8
CVE-2014-4831

IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2…

Patch available
Fix from $1,600 2014-11-28
Axm Net HIGH 7.5
CVE-2014-2373

The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors…

Patch available
Fix from $1,950 2014-11-05
Cloud Service Management MEDIUM 6.8
CVE-2014-8472

CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assi…

Fix: after 2014
Fix from $1,600 2014-11-04
Wss4j MEDIUM 5.0
CVE-2014-3623EPSS 9%

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does …

Fix: 1.6.17 / 2.0.2+
Fix from $1,600 2014-10-30
Network Data Loss Prevention HIGH 7.5
CVE-2014-8522

The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers t…

Fix: after 9.2.2
Fix from $1,950 2014-10-29
Dokuwiki MEDIUM 5.0
CVE-2014-8763

DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password sta…

Fix: after 2014-05-05a
Fix from $1,600 2014-10-22
Mageia MEDIUM 5.0
CVE-2014-8764

DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user na…

Fix: after 2013-12-08
Fix from $1,600 2014-10-22
Zend Framework MEDIUM 5.0
CVE-2014-8088

The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to …

Fix: after 1.12.7
Fix from $1,600 2014-10-22
Mantisbt MEDIUM 5.0
CVE-2014-6387

gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers a…

Fix: after 1.2.17
Fix from $1,600 2014-10-22
Technik Microcontrol Firmware HIGH 10.0
CVE-2014-8329

Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which…

Fix: after 1.7.0
Fix from $1,950 2014-10-20
Jenkins MEDIUM 6.5
CVE-2014-2062

Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to reta…

Fix: after 1.550
Fix from $1,600 2014-10-17