Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Sppa T3000 Application Server MEDIUM 5.3
CVE-2019-18332

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…

Mitigation only
Fix from $1,600 2019-12-12
Sppa T3000 Application Server CRITICAL 9.8
CVE-2019-18314

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…

Mitigation only
Fix from $2,300 2019-12-12
Sppa T3000 Application Server CRITICAL 9.8
CVE-2019-18315

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…

Mitigation only
Fix from $2,300 2019-12-12
Sppa T3000 Application Server HIGH 7.5
CVE-2019-18317

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…

Mitigation only
Fix from $1,950 2019-12-12
Sppa T3000 Application Server HIGH 7.5
CVE-2019-18318

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…

Mitigation only
Fix from $1,950 2019-12-12
Sppa T3000 Application Server HIGH 7.5
CVE-2019-18319

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…

Mitigation only
Fix from $1,950 2019-12-12
Sppa T3000 Application Server HIGH 7.5
CVE-2019-18320

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…

Mitigation only
Fix from $1,950 2019-12-12
Sppa T3000 Ms3000 Migration Server CRITICAL 9.1
CVE-2019-18321

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could …

Mitigation only
Fix from $2,300 2019-12-12
Sppa T3000 Ms3000 Migration Server CRITICAL 9.1
CVE-2019-18322

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could …

Mitigation only
Fix from $2,300 2019-12-12
Sppa T3000 Ms3000 Migration Server MEDIUM 5.3
CVE-2019-18312

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could …

Mitigation only
Fix from $1,600 2019-12-12
Sppa T3000 Application Server CRITICAL 9.8
CVE-2019-18284

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without au…

No fix yet
Fix from $2,300 2019-12-12
Sppa T3000 Application Server MEDIUM 5.3
CVE-2019-18286

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory…

No fix yet
Fix from $1,600 2019-12-12
Sppa T3000 Application Server MEDIUM 5.3
CVE-2019-18287

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory…

No fix yet
Fix from $1,600 2019-12-12
Omniauth Facebook HIGH 7.5
CVE-2013-4593

RubyGem omniauth-facebook has an access token security vulnerability

Fix: after 1.5.0
Fix from $1,950 2019-12-11
Fedora MEDIUM 5.4
CVE-2019-14870

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation mode…

Fix: 4.9.17 / 4.10.11+
Fix from $1,600 2019-12-10
Monkey CRITICAL 9.8
CVE-2013-2159

Monkey HTTP Daemon: broken user name authentication

No fix yet
Fix from $2,300 2019-12-10
Industrial Control System Protection MEDIUM 6.5
CVE-2019-18380

Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow…

Fix: 6.1.1.123+
Fix from $1,600 2019-12-09
Beegfs CRITICAL 9.6
CVE-2019-15897

beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not exp…

Fix: after 7.1.3
Fix from $2,300 2019-12-05
Keycloak CRITICAL 9.8
CVE-2019-14910

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…

Mitigation only
Fix from $2,300 2019-12-05
Pan Os HIGH 7.8
CVE-2019-17437

An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate pri…

Fix: 7.1.25 / 8.0.20+
Fix from $1,950 2019-12-05
Dap 1860 Firmware HIGH 8.8
CVE-2019-19598

D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value.…

No fix yet
Fix from $1,950 2019-12-05
OpenBSD HIGH 7.8
CVE-2019-19519

In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main fun…

No fix yet
Fix from $1,950 2019-12-05
OpenBSD CRITICAL 9.8
CVE-2019-19521

libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/au…

No fix yet
Fix from $2,300 2019-12-05
Keycloak HIGH 8.3
CVE-2019-14909

A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will…

Mitigation only
Fix from $1,950 2019-12-04
Json Pattern Validator MEDIUM 5.3
CVE-2019-19507

In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a confli…

Fix: 2.1.1+
Fix from $1,600 2019-12-02
Management System CRITICAL 9.8
CVE-2019-12394

Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authen…

Mitigation only
Fix from $2,300 2019-12-02
Band 2 Firmware HIGH 8.8
CVE-2019-5218

There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try t…

Mitigation only
Fix from $1,950 2019-11-29
Ruby HIGH 7.5
CVE-2019-16201EPSS 5%

WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by…

Fix: after 2.6.4
Fix from $1,950 2019-11-26
Big Ip Link Controller CRITICAL 9.8
CVE-2019-6675

BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a v…

Fix: after 15.0.1.0.48.11-eng_hotfix
Fix from $2,300 2019-11-26
Ansible MEDIUM 6.5
CVE-2019-14856

ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None

Fix: 2.6.20 / 2.7.14+
Fix from $1,600 2019-11-26