Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Harmony Hub Firmware CRITICAL 9.8
CVE-2018-15721

The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers c…

Fix: 4.15.206+
Fix from $2,300 2018-12-20
Api Connect HIGH 8.1
CVE-2018-1778

IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is ex…

Fix: after 2018.4.1.0
Fix from $1,950 2018-12-20
Dva 5592 Firmware CRITICAL 9.8
CVE-2018-17777

An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000)…

Mitigation only
Fix from $2,300 2018-12-18
Simatic It Line Monitoring System HIGH 8.1
CVE-2018-13804

A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UA Discrete…

Mitigation only
Fix from $1,950 2018-12-13
Tim 1531 Irc Firmware CRITICAL 10.0
CVE-2018-13816

A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although con…

Fix: 2.0+
Fix from $2,300 2018-12-12
Clearpass Policy Manager HIGH 7.2
CVE-2018-7067

A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of Clea…

Fix: 6.6.10 / 6.7.6+
Fix from $1,950 2018-12-07
5n2 Firmware CRITICAL 9.8
CVE-2018-14708

An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.

No fix yet
Fix from $2,300 2018-12-03
5n2 Firmware CRITICAL 9.8
CVE-2018-14709

Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure to…

No fix yet
Fix from $2,300 2018-12-03
Keycloak HIGH 8.1
CVE-2018-14637

The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th…

Fix: 4.6.0+
Fix from $1,950 2018-11-30
Espace 7950 Firmware HIGH 7.4
CVE-2018-7958

There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-mid…

Mitigation only
Fix from $1,950 2018-11-27
Php Proxy HIGH 7.5
CVE-2018-19458EPSS 33%

In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability …

No fix yet
Fix from $1,950 2018-11-22
Securecore HIGH 7.8
CVE-2018-16160

SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Windows PC.

Fix: 3.0+
Fix from $1,950 2018-11-15
Zxhn H168n Firmware HIGH 8.8
CVE-2018-7358EPSS 90%

ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, wh…

No fix yet
Fix from $1,950 2018-11-14
Raid Web Console 3 MEDIUM 5.5
CVE-2018-3696

Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative priv…

Fix: 4.186+
Fix from $1,600 2018-11-14
Alp Al00b Firmware MEDIUM 6.8
CVE-2018-7910

Some Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.127(C432), 8.0.0.128(C432), 8…

Mitigation only
Fix from $1,600 2018-11-13
I5 Application Firmware CRITICAL 9.8
CVE-2018-19076

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $2,300 2018-11-07
Circarlife Firmware CRITICAL 9.8
CVE-2018-17918

Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.

Fix: 4.3.1+
Fix from $2,300 2018-11-02
Mini 8 Firmware CRITICAL 9.8
CVE-2018-6908

An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing a…

Fix: after 4.0.975
Fix from $2,300 2018-11-01
Mini 8 Firmware HIGH 8.1
CVE-2018-6011

The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2nd generation) uses the admin…

Fix: after 4.0.975
Fix from $1,950 2018-11-01
Minicms HIGH 7.5
CVE-2018-18891

MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.

No fix yet
Fix from $1,950 2018-11-01
Gluster Storage MEDIUM 6.5
CVE-2016-2125EPSS 9%

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh…

Fix: 4.3.13 / 4.4.8+
Fix from $1,600 2018-10-31
Nextcloud Server MEDIUM 5.7
CVE-2018-16464

A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had change…

Fix: 14.0.0+
Fix from $1,600 2018-10-30
Nextcloud Server MEDIUM 5.3
CVE-2018-16465

Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor fail…

Fix: 14.0.0+
Fix from $1,600 2018-10-30
Nextcloud Server MEDIUM 5.3
CVE-2018-16467

A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.

Fix: 14.0.0+
Fix from $1,600 2018-10-30
Projectsend CRITICAL 9.8
CVE-2016-10732

ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-d…

Mitigation only
Fix from $2,300 2018-10-29
Saga1 L8b Firmware MEDIUM 6.9
CVE-2018-17923

SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may able to repr…

Mitigation only
Fix from $1,600 2018-10-24
Salt CRITICAL 9.8
CVE-2018-15751EPSS 5%

SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-a…

Fix: 2017.7.8 / 2018.3.3+
Fix from $2,300 2018-10-24
H.264 Poe Ip Camera Firmware CRITICAL 9.8
CVE-2018-12666

SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, whic…

No fix yet
Fix from $2,300 2018-10-19
H.264 Poe Ip Camera Firmware CRITICAL 9.8
CVE-2018-12667

The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) is affected by an improper authentication vulnerabili…

No fix yet
Fix from $2,300 2018-10-19
Flashsystem 900 Firmware CRITICAL 9.8
CVE-2018-1822

IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability t…

Patch available
Fix from $2,300 2018-10-18