Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 10.0 CVE-2017-13995 An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not proper… Ininet Webserver after 2.02.0000 Fix from $2,3002017-10-05 CRITICAL 9.4 CVE-2017-14000 An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a specific unifo… Skyrouter Z4200 Firmware after 6.00.05 Fix from $2,3002017-10-05 HIGH 8.5 CVE-2017-1000106 Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing … Blue Ocean after 1.1.5 Fix from $1,9502017-10-05 CRITICAL 9.8 CVE-2017-12819 Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK produ… Sentinel Ldk Rte Firmware after 7.50 Fix from $2,3002017-10-04 CRITICAL 9.8 CVE-2017-13983EPSS 6% An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows rem… Bsm Platform Application Performance Management System Health Mitigation only Fix from $2,3002017-09-30 MEDIUM 6.5 CVE-2017-13984 An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows rem… Bsm Platform Application Performance Management System Health Mitigation only Fix from $1,6002017-09-30 CRITICAL 9.8 CVE-2017-12229EPSS 5% A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote atta… Ios Xe Mitigation only Fix from $2,3002017-09-29 CRITICAL 9.8 CVE-2017-12236 A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, r… Ios Xe Mitigation only Fix from $2,3002017-09-29 HIGH 7.5 CVE-2017-14766 The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function an… Simple Student Result after 1.6.3 Fix from $1,9502017-09-27 HIGH 7.2 CVE-2017-14602 A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 … Application Delivery Controller Firmware Patch available Fix from $1,9502017-09-26 HIGH 8.8 CVE-2017-5192 When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, externa… Salt after 2015.8.12 Fix from $1,9502017-09-26 CRITICAL 9.8 CVE-2017-14706EPSS 28% DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservice… I Suite Patch available Fix from $2,3002017-09-22 CRITICAL 9.8 CVE-2017-14080 Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific par… Mobile Security Patch available Fix from $2,3002017-09-22 CRITICAL 9.8 CVE-2015-1187 KEVEPSS 83% The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. Dir 626l Firmware Mitigation only Fix from $2,3002017-09-21 HIGH 8.1 CVE-2017-14623 In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application… Ldap after 2.5.0 Fix from $1,9502017-09-20 HIGH 8.8 CVE-2017-10784EPSS 16% The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject … Ruby after 2.2.7 Fix from $1,9502017-09-19 CRITICAL 9.8 CVE-2014-9611EPSS 13% Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/i… Netsweeper after 4.0.4 Fix from $2,3002017-09-19 CRITICAL 9.8 CVE-2014-9618EPSS 73% The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authenticati… Netsweeper after 3.1.9 Fix from $2,3002017-09-19 HIGH 7.5 CVE-2017-9803 Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or a… Solr Mitigation only Fix from $1,9502017-09-18 CRITICAL 9.8 CVE-2017-14243EPSS 15% An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administr… Wa3002g4 Firmware No fix yet Fix from $2,3002017-09-17 HIGH 8.1 CVE-2017-14337 When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST A… Misp after 2.4.79 Fix from $1,9502017-09-12 HIGH 7.5 CVE-2014-9624 CAPTCHA bypass vulnerability in MantisBT before 1.2.19. Mantisbt after 1.2.18 Fix from $1,9502017-09-12 CRITICAL 9.8 CVE-2017-7649 The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be con… Kura after 2.0.2 Fix from $2,3002017-09-11 MEDIUM 6.5 CVE-2017-7650 In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or rem… Debian Linux 1.4.12+ Fix from $1,6002017-09-11 MEDIUM 6.5 CVE-2017-12225 A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another u… Prime Lan Management Solution Mitigation only Fix from $1,6002017-09-07 CRITICAL 9.8 CVE-2017-14147EPSS 66% An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its … Adsl An1020 25 Firmware No fix yet Fix from $2,3002017-09-07 CRITICAL 9.8 CVE-2015-3442 Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API call. Xpert.line No fix yet Fix from $2,3002017-09-07 MEDIUM 5.9 CVE-2017-14117EPSS 8% The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures an unauthenticated pro… U Verse Firmware No fix yet Fix from $1,6002017-09-03 CRITICAL 9.8 CVE-2015-7746 NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtain sensitive information from … Data Ontap after 8.2.3 Fix from $2,3002017-09-01 HIGH 8.1 CVE-2017-14032 ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via … Mbed Tls Patch available Fix from $1,9502017-08-30