Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.0 CVE-2017-3765 In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoo… Enterprise Network Operating System 8.4.6.0+ Fix from $1,9502018-01-10 HIGH 8.8 CVE-2017-12695 An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this … Shanghai Onstar Mitigation only Fix from $1,9502018-01-09 CRITICAL 9.8 CVE-2017-15883 Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of servic… Sitefinity Mitigation only Fix from $2,3002018-01-08 MEDIUM 5.7 CVE-2018-3815 The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS… Communigate Pro No fix yet Fix from $1,6002018-01-08 CRITICAL 9.8 CVE-2017-15548 An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Inte… Avamar Server Mitigation only Fix from $2,3002018-01-05 HIGH 8.1 CVE-2017-1000489 Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address Mautic Mitigation only Fix from $1,9502018-01-03 HIGH 8.1 CVE-2017-1000433 pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without k… Debian Linux after 4.4.0 Fix from $1,9502018-01-02 CRITICAL 9.8 CVE-2018-3810EPSS 91% Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to inse… Smart Google Code Inserter 3.5+ Fix from $2,3002018-01-01 CRITICAL 9.8 CVE-2014-0121 The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter. Jboss Fuse after 1.2.2 Fix from $2,3002017-12-29 CRITICAL 9.8 CVE-2015-6237 The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerat… Ip360 Mitigation only Fix from $2,3002017-12-27 CRITICAL 9.8 CVE-2015-7224 puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password … Puppetlabs Mysql after 3.6.0 Fix from $2,3002017-12-21 CRITICAL 9.8 CVE-2017-17777 Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parame… Paid To Read Script No fix yet Fix from $2,3002017-12-20 CRITICAL 9.8 CVE-2017-17560EPSS 73% An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.ph… My Cloud Pr4100 Firmware Patch available Fix from $2,3002017-12-12 CRITICAL 9.8 CVE-2017-16684 SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionaliti… Business Intelligence Promotion Management Application Mitigation only Fix from $2,3002017-12-12 HIGH 8.8 CVE-2017-16689 A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT, 7.22, 7.22EXT; SAP KERNEL f… Sap Kernel Mitigation only Fix from $1,9502017-12-12 CRITICAL 9.8 CVE-2017-17430 Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface. Netborder\/vega Session Firmware Mitigation only Fix from $2,3002017-12-07 HIGH 8.8 CVE-2017-17435 An issue was discovered in the software on Vaultek Gun Safe VT20i products, aka BlueSteal. An attacker can remotely unlock any safe in this product l… Vt20i Firmware Mitigation only Fix from $1,9502017-12-07 HIGH 7.5 CVE-2017-16953EPSS 11% connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration … Zxdsl 831cii Firmware No fix yet Fix from $1,9502017-12-01 CRITICAL 9.8 CVE-2017-10903 Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device with root privileges and conduct… Ptw Wms1 Firmware Mitigation only Fix from $2,3002017-12-01 CRITICAL 9.8 CVE-2017-14377 EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Bu… Authentication Agent For Web Mitigation only Fix from $2,3002017-11-29 HIGH 8.1 CVE-2017-13872EPSS 37% An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory U… Mac Os X Patch available Fix from $1,9502017-11-29 MEDIUM 6.5 CVE-2017-9316 Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal D… Nvr11hs Firmware Patch available Fix from $1,6002017-11-27 HIGH 8.8 CVE-2017-0910 In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the … Zulip Server 1.7.1+ Fix from $1,9502017-11-27 HIGH 8.1 CVE-2017-8028 In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP Bind… Debian Linux Mitigation only Fix from $1,9502017-11-27 MEDIUM 6.2 CVE-2017-8214 Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, … Honor 8 Firmware Mitigation only Fix from $1,6002017-11-22 HIGH 8.8 CVE-2017-8194 The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authen… Fusionsphere Openstack Mitigation only Fix from $1,9502017-11-22 HIGH 8.8 CVE-2017-8195 The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authen… Fusionsphere Openstack Mitigation only Fix from $1,9502017-11-22 MEDIUM 6.8 CVE-2017-8151 Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design… Honor 5s Firmware Mitigation only Fix from $1,6002017-11-22 CRITICAL 9.8 CVE-2017-2738 VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability. This is due to improper implementation of… Vcm5010 Firmware Mitigation only Fix from $2,3002017-11-22 CRITICAL 9.8 CVE-2017-8861 Missing authentication for the remote configuration port 1236/tcp on the Cohu 3960HD allows an attacker to change configuration parameters such as IP… 3960hd Firmware Mitigation only Fix from $2,3002017-11-22