Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2017-16613EPSS 8% An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and … Debian Linux after 2.15.1 Fix from $2,3002017-11-21 CRITICAL 9.8 CVE-2017-16566 On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core s… Jooan A5 Ip Camera Firmware Mitigation only Fix from $2,3002017-11-17 CRITICAL 9.8 CVE-2017-12337EPSS 6% A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an u… Emergency Responder Mitigation only Fix from $2,3002017-11-16 HIGH 7.5 CVE-2017-12316 A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform mul… Identity Services Engine Software Mitigation only Fix from $1,9502017-11-16 MEDIUM 5.3 CVE-2017-15272 The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The app… Psftpd No fix yet Fix from $1,6002017-11-15 HIGH 8.8 CVE-2017-9314 Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171… Nvr5464 16p 4ks2 Firmware Mitigation only Fix from $1,9502017-11-13 CRITICAL 9.8 CVE-2017-16562EPSS 27% The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and… Userpro 4.9.17.1+ Fix from $2,3002017-11-10 CRITICAL 9.8 CVE-2017-16634 In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method. Joomla\! after 3.8.1 Fix from $2,3002017-11-10 HIGH 8.1 CVE-2017-2914 An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token c… Circle With Disney Firmware No fix yet Fix from $1,9502017-11-07 CRITICAL 9.8 CVE-2017-2864 An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets … Circle With Disney Firmware Mitigation only Fix from $2,3002017-11-07 CRITICAL 9.8 CVE-2017-1000154 Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara'… Mahara Patch available Fix from $2,3002017-11-03 HIGH 7.5 CVE-2017-12281 A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Air… Aironet 1800 Firmware Mitigation only Fix from $1,9502017-11-02 HIGH 8.1 CVE-2017-10873 OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vul… Openam after 13.0.0-73 Fix from $1,9502017-11-02 MEDIUM 6.5 CVE-2017-1222 IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allow… Bigfix Platform Patch available Fix from $1,6002017-10-26 HIGH 7.2 CVE-2017-12160 It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit… Keycloak Mitigation only Fix from $1,9502017-10-26 HIGH 7.5 CVE-2017-9946EPSS 25% A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network … Apogee Pxc Firmware 3.5+ Fix from $1,9502017-10-23 HIGH 7.5 CVE-2017-5635 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin… Nifi Mitigation only Fix from $1,9502017-10-19 CRITICAL 9.9 CVE-2017-12251 A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciou… Cloud Services Platform 2100 Mitigation only Fix from $2,3002017-10-19 CRITICAL 9.8 CVE-2017-14322EPSS 37% The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attack… Email Marketer after 6.1.5 Fix from $2,3002017-10-18 HIGH 8.2 CVE-2017-9625 An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authenticat… Envidas Ultimate after 1.0.0.4 Fix from $1,9502017-10-17 CRITICAL 9.8 CVE-2017-15295 Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064. Point Of Sale Xpress Server Mitigation only Fix from $2,3002017-10-16 HIGH 7.5 CVE-2017-15297 SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993. Host Agent Mitigation only Fix from $1,9502017-10-16 CRITICAL 9.8 CVE-2017-15293 Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain at… Point Of Sale Xpress Server Mitigation only Fix from $2,3002017-10-16 CRITICAL 9.8 CVE-2017-10622EPSS 5% An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based a… Junos Space Mitigation only Fix from $2,3002017-10-13 HIGH 8.1 CVE-2017-10623 Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to interc… Junos Space after 16.2 Fix from $1,9502017-10-13 CRITICAL 9.8 CVE-2016-5791 An Improper Authentication issue was discovered in JanTek JTC-200, all versions. The improper authentication could provide an undocumented BusyBox Li… Jtc 200 Firmware Mitigation only Fix from $2,3002017-10-13 CRITICAL 9.8 CVE-2017-5791EPSS 69% The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via un… Intelligent Management Center Plat Mitigation only Fix from $2,3002017-10-11 CRITICAL 9.8 CVE-2017-14003 An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior vers… Ether Serial Link Firmware after 6.01.00 Fix from $2,3002017-10-11 HIGH 7.5 CVE-2017-14972 InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Mana… Mondopad No fix yet Fix from $1,9502017-10-09 CRITICAL 9.8 CVE-2016-8937 The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclo… Tivoli Storage Manager Patch available Fix from $2,3002017-10-05