Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2017-12698 An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible a… Webaccess after 8.2 Fix from $2,3002017-08-30 HIGH 8.8 CVE-2015-8332 Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows r… Vcm5010 Firmware Mitigation only Fix from $1,9502017-08-28 CRITICAL 9.8 CVE-2015-1401 Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3. Ldap \/ Sso Authentication Mitigation only Fix from $2,3002017-08-28 HIGH 7.4 CVE-2017-7930 An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws … Pi Data Archive after 3.4.410.1256 Fix from $1,9502017-08-25 MEDIUM 5.9 CVE-2017-7934 An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older prot… Pi Data Archive after 3.4.410.1256 Fix from $1,6002017-08-25 CRITICAL 9.8 CVE-2014-7857EPSS 15% D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and … Dns 322l Firmware after 2.00b07 Fix from $2,3002017-08-25 CRITICAL 9.8 CVE-2014-7858EPSS 15% The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username c… Dnr 326 Firmware after 1.40b03 Fix from $2,3002017-08-25 MEDIUM 5.3 CVE-2014-7860EPSS 10% The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which … Dns 327l Firmware after 1.03b04 Fix from $1,6002017-08-25 HIGH 8.1 CVE-2015-3206 The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a… Pykerberos Patch available Fix from $1,9502017-08-25 HIGH 7.8 CVE-2015-8308 LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections. Lxdm after 0.5.1 Fix from $1,9502017-08-24 MEDIUM 5.3 CVE-2016-2102 HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network. Haproxy No fix yet Fix from $1,6002017-08-22 CRITICAL 9.8 CVE-2016-4460EPSS 6% Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication. Pony Mail Patch available Fix from $2,3002017-08-22 HIGH 8.8 CVE-2017-7557 dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack. Dnsdist Patch available Fix from $1,9502017-08-22 CRITICAL 9.8 CVE-2017-7420 An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterpr… Enterprise Developer after 2.3 Fix from $2,3002017-08-21 CRITICAL 9.8 CVE-2015-4464 Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server. Kg Sha104 Firmware No fix yet Fix from $2,3002017-08-18 MEDIUM 5.3 CVE-2017-6781 A vulnerability in the management of shell user accounts for Cisco Policy Suite (CPS) Software for CPS appliances could allow an authenticated, local… Policy Suite Mitigation only Fix from $1,6002017-08-17 CRITICAL 9.8 CVE-2017-7546EPSS 62% PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain … PostgreSQL Mitigation only Fix from $2,3002017-08-16 CRITICAL 9.8 CVE-2015-6816 ganglia-web before 3.7.1 allows remote attackers to bypass authentication. Fedora after 3.7.0 Fix from $2,3002017-08-09 HIGH 8.8 CVE-2017-9370 An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legi… Workspaces Mitigation only Fix from $1,9502017-08-09 CRITICAL 9.8 CVE-2012-0803 The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as pa… Cxf Patch available Fix from $2,3002017-08-08 CRITICAL 9.8 CVE-2017-11151EPSS 16% A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files wi… Photo Station after 6.7.2-3429 Fix from $2,3002017-08-08 CRITICAL 9.8 CVE-2017-6869 A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user … Viewport For Web Office Portal Mitigation only Fix from $2,3002017-08-08 MEDIUM 5.4 CVE-2017-6871 A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Andr… Simatic Wincc Sm\@rtclient after 1.0.2.1 Fix from $1,6002017-08-08 CRITICAL 9.8 CVE-2017-9939 A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPas… Sipass Integrated after 2.65 Fix from $2,3002017-08-08 CRITICAL 9.8 CVE-2015-7871EPSS 82% Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. Debian Linux 4.2.8 / 4.3.77+ Fix from $2,3002017-08-07 CRITICAL 9.8 CVE-2017-12477EPSS 68% It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which it… Unitrends Backup 10.0+ Fix from $2,3002017-08-07 CRITICAL 9.8 CVE-2017-12478EPSS 78% It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not… Unitrends Backup 10.0+ Fix from $2,3002017-08-07 HIGH 7.5 CVE-2017-7920 An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versi… Vsn300 Firmware after 1.8.15 Fix from $1,9502017-08-07 CRITICAL 9.4 CVE-2017-9630 An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash… Laserwash G5 Firmware Mitigation only Fix from $2,3002017-08-07 CRITICAL 9.8 CVE-2017-6747EPSS 5% A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local … Identity Services Engine Mitigation only Fix from $2,3002017-08-07