Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.8 CVE-2018-11478 An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the ca… Icar 2 Wi Fi Obd2 Firmware Mitigation only Fix from $1,9502018-05-30 MEDIUM 5.9 CVE-2014-10067 paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal … Paypal Ipn 3.0.0+ Fix from $1,6002018-05-29 CRITICAL 9.8 CVE-2016-10525 When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authenticati… Hapi Auth Jwt2 after 5.1.1 Fix from $2,3002018-05-29 MEDIUM 6.5 CVE-2017-9421 Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web … Kiteworks 2017.01.00+ Fix from $1,6002018-05-24 CRITICAL 9.8 CVE-2018-8898EPSS 13% A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer… Dsl 3782 Firmware No fix yet Fix from $2,3002018-05-23 CRITICAL 9.8 CVE-2018-0271 A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass a… Digital Network Architecture Center 1.1.2+ Fix from $2,3002018-05-17 MEDIUM 5.3 CVE-2018-10825 Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows… Mimo Baby 2 Firmware Mitigation only Fix from $1,6002018-05-15 HIGH 7.8 CVE-2018-6617 Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by le… Easy Hosting Control Panel No fix yet Fix from $1,9502018-05-11 MEDIUM 6.2 CVE-2018-7940 Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authenti… Mate 9 Firmware 8.0.0.129+ Fix from $1,6002018-05-10 HIGH 8.8 CVE-2018-7941 Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authe… Ch121 V3 Firmware Mitigation only Fix from $1,9502018-05-10 MEDIUM 6.5 CVE-2018-6020 In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, whi… Sd 320an Firmware after 2.01 Fix from $1,6002018-05-09 CRITICAL 9.8 CVE-2018-10682EPSS 8% An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authe… Wildfly No fix yet Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2018-10683 An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful… Wildfly No fix yet Fix from $2,3002018-05-09 MEDIUM 6.4 CVE-2017-3775 Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code … Flex System X240 M5 Bios 2.23 / 2.61+ Fix from $1,6002018-05-04 CRITICAL 9.8 CVE-2018-10561 KEVEPSS 93% An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device th… Gpon Router Firmware Mitigation only Fix from $2,3002018-05-04 HIGH 8.1 CVE-2018-10641 D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext. Dir 601 Firmware No fix yet Fix from $1,9502018-05-04 CRITICAL 9.8 CVE-2018-10544 Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface. Mss110 Firmware after 1.1.24 Fix from $2,3002018-05-02 HIGH 7.8 CVE-2018-9232 Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and … Be126 Firmware No fix yet Fix from $1,9502018-05-01 HIGH 7.8 CVE-2018-10576 An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native A… Ap200 Firmware 1.2.9.15+ Fix from $1,9502018-04-30 HIGH 8.8 CVE-2018-1418EPSS 52% IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824. Qradar Security Information And Event Manager 7.2.8+ Fix from $1,9502018-04-26 HIGH 8.8 CVE-2017-12712 The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stam… Accent Firmware Mitigation only Fix from $1,9502018-04-25 HIGH 8.8 CVE-2018-1112 glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to conne… Glusterfs 3.10.12+ Fix from $1,9502018-04-25 CRITICAL 9.8 CVE-2018-10362 An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for th… Phpliteadmin after 1.9.7.1 Fix from $2,3002018-04-25 MEDIUM 5.5 CVE-2018-1106 An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed package… Enterprise Linux Desktop Mitigation only Fix from $1,6002018-04-23 HIGH 8.1 CVE-2014-0927 The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass … Sterling B2b Integrator Patch available Fix from $1,9502018-04-20 HIGH 8.8 CVE-2018-6960 VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication.… Horizon Daas 8.0.0+ Fix from $1,9502018-04-20 CRITICAL 9.9 CVE-2018-0238EPSS 5% A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, … Unified Computing System Director Mitigation only Fix from $2,3002018-04-19 CRITICAL 9.8 CVE-2018-7760 An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI … Bmxnor0200 Firmware Mitigation only Fix from $2,3002018-04-18 HIGH 7.5 CVE-2016-10434 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 820 and SD 820A, the input to… Sd 820 Firmware Mitigation only Fix from $1,9502018-04-18 MEDIUM 5.9 CVE-2017-12196 undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that… Undertow after 1.4.18 Fix from $1,6002018-04-18