Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2018-14643EPSS 6% An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely exec… Foreman Patch available Fix from $2,3002018-09-21 CRITICAL 9.8 CVE-2018-12242 The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allo… Messaging Gateway 10.6.6+ Fix from $2,3002018-09-19 HIGH 7.8 CVE-2017-3912 Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbit… Application And Change Control Mitigation only Fix from $1,9502018-09-18 MEDIUM 5.3 CVE-2018-16670EPSS 25% An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html. Circarlife Scada 4.3+ Fix from $1,6002018-09-18 MEDIUM 5.3 CVE-2018-16668EPSS 10% An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /ht… Circarlife Scada 4.3+ Fix from $1,6002018-09-18 CRITICAL 9.8 CVE-2018-17153EPSS 87% It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated … My Cloud Wdbctl0020hwt Firmware 2.30.196+ Fix from $2,3002018-09-18 HIGH 8.1 CVE-2018-11787 In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re… Karaf 3.0.9 / 4.0.9+ Fix from $1,9502018-09-18 HIGH 7.2 CVE-2017-2872 Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A HTTP re… C1 Firmware No fix yet Fix from $1,9502018-09-17 CRITICAL 9.8 CVE-2018-16286EPSS 22% LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is lim… Supersign Cms No fix yet Fix from $2,3002018-09-14 MEDIUM 6.8 CVE-2018-7572 Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windo… Pulse Secure Desktop Mitigation only Fix from $1,6002018-09-12 CRITICAL 9.8 CVE-2018-16947 An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not… Debian Linux 1.6.23 / 1.8.2+ Fix from $2,3002018-09-12 CRITICAL 9.1 CVE-2018-15485 An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or authorization, aka KONE-03. Group Controller Firmware 4.6.5+ Fix from $2,3002018-09-07 CRITICAL 9.8 CVE-2018-16590 FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication. Felcom 250 Firmware No fix yet Fix from $2,3002018-09-06 HIGH 7.5 CVE-2017-14026 In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allow an att… Thermal Management Center Firmware 4.13+ Fix from $1,9502018-09-06 HIGH 8.1 CVE-2018-15478 An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LE… Wifi Switch Firmware 2.58 / 2.66+ Fix from $1,9502018-08-30 MEDIUM 6.5 CVE-2018-15479 An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LE… Wifi Switch Firmware 2.58 / 2.66+ Fix from $1,6002018-08-30 CRITICAL 9.8 CVE-2018-13821 A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, inc… Unified Infrastructure Management Patch available Fix from $2,3002018-08-30 CRITICAL 9.8 CVE-2018-7791 A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior t… Modicon M221 Firmware 1.6.2.0+ Fix from $2,3002018-08-29 CRITICAL 9.8 CVE-2018-14805 ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values withi… Esoms Mitigation only Fix from $2,3002018-08-29 CRITICAL 9.8 CVE-2018-15727EPSS 64% Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cooki… Grafana 4.6.4 / 5.2.3+ Fix from $2,3002018-08-29 CRITICAL 9.8 CVE-2017-9819 The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier … Bharat Interface For Money \(bhim\) Mitigation only Fix from $2,3002018-08-24 CRITICAL 9.8 CVE-2017-9820 The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Acce… Bharat Interface For Money \(bhim\) Mitigation only Fix from $2,3002018-08-24 CRITICAL 9.4 CVE-2018-14786 Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and pri… Alaris Gs Firmware after 2.3.6 Fix from $2,3002018-08-23 MEDIUM 5.4 CVE-2018-1999045 A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2… Jenkins after 2.137 Fix from $1,6002018-08-23 HIGH 7.5 CVE-2017-16348 An exploitable denial of service vulnerability exists in Insteon Hub running firmware version 1012. Leftover demo functionality allows for arbitraril… Insteon Hub Firmware No fix yet Fix from $1,9502018-08-23 HIGH 7.5 CVE-2018-15667 An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send" command in the URL scheme all… Airmail Mitigation only Fix from $1,9502018-08-21 HIGH 7.5 CVE-2018-15598 Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is pu… Traefik 1.6.6+ Fix from $1,9502018-08-21 CRITICAL 9.8 CVE-2017-16748EPSS 5% An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using… Niagara after 4.4 Fix from $2,3002018-08-20 CRITICAL 9.8 CVE-2018-14078 Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL … Smart Hp Wmt Mitigation only Fix from $2,3002018-08-20 HIGH 7.0 CVE-2018-13435 An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulati… Line No fix yet Fix from $1,9502018-08-16