Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Jenkins MEDIUM 6.8
CVE-2014-2066

Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving th…

Fix: after 1.550
Fix from $1,600 2014-10-17
Arx HIGH 9.3
CVE-2014-2927EPSS 8%

The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and …

No fix yet
Fix from $1,950 2014-10-15
Junos HIGH 7.5
CVE-2014-6379

Juniper Junos 11.4 before R12, 12.1 before R10, 12.1X44 before D35, 12.1X45 before D25, 12.1X46 before D20, 12.1X47 before D10, 12.2 before R8, 12.2X…

Mitigation only
Fix from $1,950 2014-10-14
Intrusion Prevention System MEDIUM 5.0
CVE-2014-3402

The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection …

Fix: after 7.0
Fix from $1,600 2014-10-10
Joomla\! HIGH 7.5
CVE-2014-6632

Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions…

Mitigation only
Fix from $1,950 2014-10-08
Moab MEDIUM 5.0
CVE-2014-5300EPSS 7%

Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execu…

Fix: after 7.2.8
Fix from $1,600 2014-10-08
Shiro HIGH 7.5
CVE-2014-0074EPSS 5%

Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e…

No fix yet
Fix from $1,950 2014-10-06
N300 Firmware HIGH 8.3
CVE-2013-3092

The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation o…

No fix yet
Fix from $1,950 2014-09-29
Rational Clearcase MEDIUM 5.0
CVE-2014-3106

IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not properly implement the Local Access Only protec…

Patch available
Fix from $1,600 2014-09-23
Rational Clearcase MEDIUM 5.0
CVE-2014-3101

The login form in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not insert a…

Patch available
Fix from $1,600 2014-09-23
Clearscada MEDIUM 5.0
CVE-2014-5412

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access…

Mitigation only
Fix from $1,600 2014-09-18
Zend Framework HIGH 7.5
CVE-2014-2685

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 v…

Fix: after 2.0.1
Fix from $1,950 2014-09-04
Rsa Identity Management And Governance HIGH 9.3
CVE-2014-4619

EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manag…

No fix yet
Fix from $1,950 2014-08-28
Django MEDIUM 6.0
CVE-2014-0482

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release c…

Fix: after 1.4.13
Fix from $1,600 2014-08-26
Little Kernel Bootloader HIGH 7.2
CVE-2014-4325

The cmd_boot function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contri…

Patch available
Fix from $1,950 2014-08-25
Little Kernel Bootloader HIGH 7.2
CVE-2014-0973

The image_verify function in platform/msm_shared/image_verify.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center …

Patch available
Fix from $1,950 2014-08-25
Shopizer MEDIUM 5.0
CVE-2014-5385

com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which make…

Fix: after 1.1.5
Fix from $1,600 2014-08-21
Solution Manager HIGH 7.5
CVE-2014-5175

The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspecified vectors, related to a ve…

Mitigation only
Fix from $1,950 2014-07-31
Ts Wlcam\/v Camera Firmware MEDIUM 6.4
CVE-2014-3895

The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 an…

Fix: after 1.08
Fix from $1,600 2014-07-29
Moodle MEDIUM 6.0
CVE-2014-3552

The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not chec…

Fix: after 2.3.11
Fix from $1,600 2014-07-29
Mailpoet Newsletters HIGH 7.5
CVE-2014-4725EPSS 60%

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrar…

Fix: after 2.6.6
Fix from $1,950 2014-07-27
Px HIGH 10.0
CVE-2014-2955

Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher s…

Fix: after 1.5.8
Fix from $1,950 2014-07-14
Dvr Firmware HIGH 7.5
CVE-2013-6117EPSS 70%

Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials,…

No fix yet
Fix from $1,950 2014-07-11
Spa 301 1 Line Ip Phone MEDIUM 6.9
CVE-2014-3312

The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to ex…

Mitigation only
Fix from $1,600 2014-07-09
Sitescope HIGH 7.5
CVE-2014-2614

Unspecified vulnerability in HP SiteScope 11.1x through 11.13 and 11.2x through 11.24 allows remote attackers to bypass authentication via unknown ve…

Mitigation only
Fix from $1,950 2014-07-07
Iodine MEDIUM 5.0
CVE-2014-4168

(1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been …

Fix: after 0.6.0
Fix from $1,600 2014-07-03
Fedora MEDIUM 6.8
CVE-2014-4668

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthe…

Fix: after 1.2.103
Fix from $1,600 2014-07-02
Enterprise Console MEDIUM 6.8
CVE-2014-2005

Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resu…

Fix: after 5.2.1
Fix from $1,600 2014-06-25
Security Access Manager For Web 8.0 Firmware HIGH 8.0
CVE-2014-3053

The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Acce…

Mitigation only
Fix from $1,950 2014-06-21
Executive Scorecard HIGH 10.0
CVE-2014-2609EPSS 13%

The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2014-06-19