Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.0 CVE-2018-13446 An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipu… Line No fix yet Fix from $1,9502018-08-16 MEDIUM 6.3 CVE-2018-13434 An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentica… Line No fix yet Fix from $1,6002018-08-16 CRITICAL 9.1 CVE-2018-15152EPSS 26% Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) porta… Openemr 5.0.1.4+ Fix from $2,3002018-08-15 HIGH 8.6 CVE-2018-2449 SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid reposito… Supplier Relationship Management Mdm Catalog Mitigation only Fix from $1,9502018-08-14 MEDIUM 5.3 CVE-2018-14781 Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), ar… 508 Minimed Insulin Pump Firmware Mitigation only Fix from $1,6002018-08-13 HIGH 8.8 CVE-2018-3775 Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Aut… Nextcloud Server 12.0.3+ Fix from $1,9502018-08-12 CRITICAL 9.8 CVE-2018-10630EPSS 11% For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, a… Tsw X60 Firmware 1.502.0047.001 / 2.001.0037.001+ Fix from $2,3002018-08-10 HIGH 7.5 CVE-2018-14782 NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and pr… Nwl 25 Firmware after 2.0.29.11 Fix from $1,9502018-08-10 CRITICAL 9.8 CVE-2018-7058 Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerabi… Aruba Clearpass Policy Manager 6.6.9+ Fix from $2,3002018-08-06 HIGH 7.5 CVE-2018-7069 HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This … Centralview Fraud Risk Management 6.1+ Fix from $1,9502018-08-06 HIGH 8.1 CVE-2016-8609 It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing … Keycloak 2.3.0+ Fix from $1,9502018-08-01 CRITICAL 9.8 CVE-2018-10603 Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, whi… Telem Gwm Firmware after 2018.04.18-linux_4-01-601cb47 Fix from $2,3002018-07-31 HIGH 8.1 CVE-2018-1638 IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for… Api Connect after 5.0.8.3 Fix from $1,9502018-07-31 HIGH 8.8 CVE-2018-10847 prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user… Prosody 0.9.14+ Fix from $1,9502018-07-30 HIGH 8.8 CVE-2017-2652 It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the d… Distributed Fork after 1.5.0 Fix from $1,9502018-07-27 MEDIUM 6.6 CVE-2018-6686 Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically proximate attackers to bypass … Drive Encryption Mitigation only Fix from $1,6002018-07-27 MEDIUM 6.5 CVE-2017-7562 An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at… Enterprise Linux 1.16.1+ Fix from $1,6002018-07-26 MEDIUM 6.8 CVE-2017-12610 In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol mess… Kafka after 0.11.0.1 Fix from $1,6002018-07-26 CRITICAL 9.8 CVE-2018-11491EPSS 7% ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution. Hg100 Firmware 1.05.12+ Fix from $2,3002018-07-25 CRITICAL 9.8 CVE-2018-8859 Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An atta… Smartserver 1 Firmware 4.11.007+ Fix from $2,3002018-07-24 HIGH 7.5 CVE-2018-5387 Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to ma… Samlbase 1.4.2+ Fix from $1,9502018-07-24 CRITICAL 9.8 CVE-2018-12804EPSS 11% Adobe Connect versions 9.7.5 and earlier have an Authentication Bypass vulnerability. Successful exploitation could lead to session hijacking. Connect after 9.7.5 Fix from $2,3002018-07-20 HIGH 7.5 CVE-2018-14345 An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing … Sddm after 0.17.0 Fix from $1,9502018-07-17 MEDIUM 6.5 CVE-2017-2638 It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability… Jboss Data Grid 9.0.0+ Fix from $1,6002018-07-16 CRITICAL 9.8 CVE-2016-9482 Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by… Php Formmail Generator Mitigation only Fix from $2,3002018-07-13 HIGH 8.8 CVE-2016-9497 Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate pa… Hn7740s Firmware Mitigation only Fix from $1,9502018-07-13 HIGH 7.5 CVE-2016-6544 getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be e… Itrack Easy Mitigation only Fix from $1,9502018-07-13 HIGH 7.5 CVE-2018-8171EPSS 10% A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature… Asp.net Core Patch available Fix from $1,9502018-07-11 HIGH 8.1 CVE-2018-10861 A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po… Ceph Storage Patch available Fix from $1,9502018-07-10 HIGH 7.5 CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access… Ceph Storage after 13.2.1 Fix from $1,9502018-07-10