Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2018-7076EPSS 12% A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04. Intelligent Management Center 7.3+ Fix from $2,3002018-10-17 CRITICAL 9.1 CVE-2018-10933EPSS 92% A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without fir… Ubuntu Linux 0.7.6 / 0.8.4+ Fix from $2,3002018-10-17 CRITICAL 9.8 CVE-2018-18389 Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and Sys… Neo4j 3.4.9+ Fix from $2,3002018-10-16 MEDIUM 6.8 CVE-2018-17534 Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows atta… Rut900 Firmware 00.04.233+ Fix from $1,6002018-10-15 HIGH 7.1 CVE-2018-1738 IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integr… Security Key Lifecycle Manager after 3.0.0.1 Fix from $1,9502018-10-11 HIGH 7.5 CVE-2018-18061 An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them wit… Responsive Filemanager No fix yet Fix from $1,9502018-10-10 HIGH 8.1 CVE-2018-12455EPSS 6% Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interface just by… Nplug Firmware No fix yet Fix from $1,9502018-10-10 HIGH 7.5 CVE-2018-13789 An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on re… Infocad Fm 3.1.0.0+ Fix from $1,9502018-10-10 MEDIUM 5.3 CVE-2018-16737 tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation. Tinc 1.0.30+ Fix from $1,6002018-10-10 HIGH 8.1 CVE-2018-0052 If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the devi… Junos Mitigation only Fix from $1,9502018-10-10 MEDIUM 6.8 CVE-2018-0053 An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full co… Junos Mitigation only Fix from $1,6002018-10-10 HIGH 8.1 CVE-2018-0044 An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if a… Junos after 18.1r3 Fix from $1,9502018-10-10 MEDIUM 6.4 CVE-2018-15542 An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime m… Telegram Mitigation only Fix from $1,6002018-10-09 MEDIUM 6.8 CVE-2018-15543 An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows au… Telegram Mitigation only Fix from $1,6002018-10-09 HIGH 7.5 CVE-2018-14080 An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechan… Dir 809 A1 Firmware after 1.11 Fix from $1,9502018-10-09 CRITICAL 9.8 CVE-2012-6710EPSS 25% ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login r… Extplorer after 2.1.2 Fix from $2,3002018-10-07 MEDIUM 6.7 CVE-2018-15371 A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication … Ios Xe Mitigation only Fix from $1,6002018-10-05 CRITICAL 9.1 CVE-2018-0435 A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other o… Umbrella Mitigation only Fix from $2,3002018-10-05 CRITICAL 9.8 CVE-2013-7465 Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote attackers to execute arbitrary … Servers Ultimate No fix yet Fix from $2,3002018-10-05 MEDIUM 6.5 CVE-2018-0505 Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock Debian Linux 1.31.1+ Fix from $1,6002018-10-04 CRITICAL 9.1 CVE-2018-12472 A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux… Subscription Management Tool 3.0.37+ Fix from $2,3002018-10-04 HIGH 7.8 CVE-2018-6689 Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 all… Data Loss Prevention Endpoint 10.0.510 / 11.0.600+ Fix from $1,9502018-10-03 CRITICAL 9.8 CVE-2018-14826EPSS 8% Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a special… Emg 12 Firmware after 2.57 Fix from $2,3002018-10-02 CRITICAL 9.8 CVE-2018-17786 On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, whic… Dir 823g Firmware No fix yet Fix from $2,3002018-10-02 MEDIUM 6.3 CVE-2018-1672 IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to ac… Websphere Portal Patch available Fix from $1,6002018-10-01 MEDIUM 5.9 CVE-2018-9080 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into … Storcenter Px12 450r Firmware Mitigation only Fix from $1,6002018-09-28 MEDIUM 5.9 CVE-2018-7108 HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerabili… Storageworks Xp7 Automation Director 8.6.1-00+ Fix from $1,6002018-09-27 MEDIUM 6.5 CVE-2018-1539 IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct … Rational Engineering Lifecycle Manager after 6.0.6 Fix from $1,6002018-09-25 HIGH 8.1 CVE-2018-17341 BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, … Bigtree Cms No fix yet Fix from $1,9502018-09-23 HIGH 7.6 CVE-2018-12169 Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th G… Core I3 Mitigation only Fix from $1,9502018-09-21