Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.6 CVE-2017-12549 A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. System Management Homepage 7.6.1+ Fix from $1,6002018-02-15 CRITICAL 9.8 CVE-2011-4973 Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and en… Mod Nss Mitigation only Fix from $2,3002018-02-15 MEDIUM 6.8 CVE-2017-17161 The 'Find Phone' function in some Huawei smart phones with software earlier than Duke-L09C10B186 versions, earlier than Duke-L09C432B187 versions, ea… Duke L09 Firmware Mitigation only Fix from $1,6002018-02-15 MEDIUM 6.8 CVE-2017-15351 The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an authentication bypass vulnerabili… Honor V9 Play Firmware Mitigation only Fix from $1,6002018-02-15 HIGH 7.5 CVE-2018-7034 TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demon… Tew 751dr Firmware No fix yet Fix from $1,9502018-02-14 CRITICAL 9.8 CVE-2018-5459 An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different … Pfc200 Firmware 02.07.07+ Fix from $2,3002018-02-13 HIGH 8.8 CVE-2017-18179 Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termina… Sitefinity No fix yet Fix from $1,9502018-02-12 MEDIUM 5.4 CVE-2017-0911 Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to… Twitter Kit after 3.2.1 Fix from $1,6002018-02-09 CRITICAL 9.8 CVE-2018-3601 A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication o… Control Manager Patch available Fix from $2,3002018-02-09 CRITICAL 9.8 CVE-2018-6180 A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts. Online Voting Platform No fix yet Fix from $2,3002018-02-08 CRITICAL 9.8 CVE-2018-1163EPSS 16% This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw… Netvault Backup Mitigation only Fix from $2,3002018-02-08 HIGH 7.2 CVE-2018-0116 A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subsc… Mobility Services Engine Mitigation only Fix from $1,9502018-02-08 CRITICAL 9.8 CVE-2017-6199 A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field. Sandstorm 0.203+ Fix from $2,3002018-02-06 HIGH 8.8 CVE-2018-6569 West Wind Web Server 6.x does not require authentication for /ADMIN.ASP. Web Connection Mitigation only Fix from $1,9502018-02-06 MEDIUM 5.3 CVE-2018-5794 An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is No Authentication for the Aero… Wing 5.8.6.9 / 5.9.1.3+ Fix from $1,6002018-02-05 HIGH 7.5 CVE-2017-2297 Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issu… Puppet Enterprise 2016.4.5+ Fix from $1,9502018-02-01 CRITICAL 9.8 CVE-2011-4068 The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty passwor… Packetfence after 3.0.1 Fix from $2,3002018-02-01 MEDIUM 6.8 CVE-2017-16858 The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an … Crowd 3.1.2+ Fix from $1,6002018-01-31 HIGH 8.8 CVE-2017-1000354 Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user. T… Jenkins after 2.56 Fix from $1,9502018-01-29 CRITICAL 9.8 CVE-2017-14698 ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N… Dsl Ac51 Firmware Patch available Fix from $2,3002018-01-29 MEDIUM 5.3 CVE-2018-4835 A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's port 8000/t… Telecontrol Server Basic 3.1+ Fix from $1,6002018-01-25 HIGH 8.8 CVE-2018-4836 A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleControl Se… Telecontrol Server Basic 3.1+ Fix from $1,9502018-01-25 HIGH 8.1 CVE-2017-15135 It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during th… 389 Directory Server after 1.4.0.3 Fix from $1,9502018-01-24 CRITICAL 9.8 CVE-2017-15531 Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users.… Reporter 9.5.4.1+ Fix from $2,3002018-01-23 HIGH 8.8 CVE-2017-16590 This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.699 build 1… Enterprise Manager Mitigation only Fix from $1,9502018-01-23 HIGH 7.5 CVE-2015-6926 The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address … Eshop after 4.4.8 Fix from $1,9502018-01-19 CRITICAL 9.8 CVE-2018-5328 ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can… Contractorweb.net No fix yet Fix from $2,3002018-01-15 HIGH 7.5 CVE-2014-6435EPSS 13% cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attacker… Adsl Dsl5018en \(1t1r\) Firmware No fix yet Fix from $1,9502018-01-12 CRITICAL 9.8 CVE-2014-6436EPSS 42% Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opp… Adsl Dsl5018en \(1t1r\) Firmware No fix yet Fix from $2,3002018-01-12 MEDIUM 6.2 CVE-2018-0008 An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain in… Junos Mitigation only Fix from $1,6002018-01-10