Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.8 CVE-2017-2871 Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. An attack… C1 Firmware No fix yet Fix from $1,9502018-04-17 CRITICAL 9.8 CVE-2018-6546EPSS 17% plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes c… Plays.tv 1.27.7.0+ Fix from $2,3002018-04-13 CRITICAL 9.1 CVE-2018-6547 plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, contains a… Plays.tv 1.27.7.0+ Fix from $2,3002018-04-13 MEDIUM 5.3 CVE-2016-9646 ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572),… Debian Linux 3.20161229+ Fix from $1,6002018-04-13 CRITICAL 9.8 CVE-2017-0356 A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker … Debian Linux 3.20170111+ Fix from $2,3002018-04-13 HIGH 8.1 CVE-2014-3999 The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN. Horde Ldap 2.0.6+ Fix from $1,9502018-04-10 HIGH 7.3 CVE-2016-8371EPSS 11% The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled. Ilc Plcs Firmware No fix yet Fix from $1,9502018-04-05 HIGH 7.3 CVE-2016-8380EPSS 11% The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication. Ilc Plcs Firmware No fix yet Fix from $1,9502018-04-05 HIGH 8.1 CVE-2018-1082 A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspende… Moodle after 3.4.1 Fix from $1,9502018-04-04 CRITICAL 9.8 CVE-2018-6873 The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated. Auth0.js after 8.10.1 Fix from $2,3002018-04-04 CRITICAL 9.8 CVE-2018-9248EPSS 15% FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. Vdsl2 Modem Hg 150 Ub Firmware No fix yet Fix from $2,3002018-04-04 CRITICAL 9.8 CVE-2018-9249EPSS 6% FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to a… Vdsl2 Modem Hg 150 Ub Firmware Mitigation only Fix from $2,3002018-04-04 CRITICAL 9.8 CVE-2018-3822 X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. … X Pack Mitigation only Fix from $2,3002018-03-30 CRITICAL 9.8 CVE-2018-9148 Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass… My Cloud Firmware No fix yet Fix from $2,3002018-03-30 CRITICAL 9.8 CVE-2017-14911 In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 2… Mdm9206 Firmware Mitigation only Fix from $2,3002018-03-30 CRITICAL 9.8 CVE-2018-4841 A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could… Tim 1531 Irc Firmware 1.1+ Fix from $2,3002018-03-29 HIGH 8.8 CVE-2018-0195 A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the AP… Ios Xe 16.2.2+ Fix from $1,9502018-03-28 MEDIUM 6.5 CVE-2018-0163 A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to… iOS Mitigation only Fix from $1,6002018-03-28 CRITICAL 9.8 CVE-2018-5451 In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficiently prove… Alice 6 Firmware Mitigation only Fix from $2,3002018-03-28 HIGH 8.8 CVE-2018-9105 NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privileged helper tool's implemente… Nordvpn Mitigation only Fix from $1,9502018-03-27 CRITICAL 9.8 CVE-2018-1237 Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This… Emc Scaleio 2.5+ Fix from $2,3002018-03-27 MEDIUM 6.5 CVE-2015-4987 The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified ve… Tealeaf Customer Experience after 9.0.2 Fix from $1,6002018-03-27 CRITICAL 9.8 CVE-2018-9032EPSS 28% An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version… Dir 850l Firmware after 2.06 Fix from $2,3002018-03-27 MEDIUM 6.7 CVE-2017-15534 The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can a… Norton App Lock 1.3.0.13+ Fix from $1,6002018-03-26 CRITICAL 9.8 CVE-2018-1312EPSS 16% In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g… HTTP Server Mitigation only Fix from $2,3002018-03-26 CRITICAL 9.8 CVE-2018-7532EPSS 8% Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras,… G Cam\/efd 2250 Firmware No fix yet Fix from $2,3002018-03-22 MEDIUM 6.8 CVE-2017-16242 An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data acces… Usb Memory Stick With Fingerprint Firwmare Mitigation only Fix from $1,6002018-03-22 MEDIUM 6.7 CVE-2017-17743 Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5… Wireless Appliance Firmware 4.4.20 / 5.0.19+ Fix from $1,6002018-03-22 CRITICAL 9.8 CVE-2017-14002 GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Succ… Infinia Hawkeye 4 Firmware Mitigation only Fix from $2,3002018-03-20 CRITICAL 9.8 CVE-2017-14004 GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation … Gemnet License Server Mitigation only Fix from $2,3002018-03-20