Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.1 CVE-2017-9857 An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: … Sunny Boy 3600 Firmware Mitigation only Fix from $1,9502017-08-05 CRITICAL 9.8 CVE-2017-9860 An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device f… Sunny Boy 3600 Firmware Mitigation only Fix from $2,3002017-08-05 HIGH 8.1 CVE-2017-10815 MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control" is insta… Malion after 5.2.1 Fix from $1,9502017-08-04 CRITICAL 9.8 CVE-2017-10817 MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server. Malion after 5.2.1 Fix from $2,3002017-08-04 MEDIUM 5.9 CVE-2017-9475 Comcast XFINITY WiFi Home Hotspot devices allow remote attackers to spoof the identities of Comcast customers via a forged MAC address. Xfinity Wifi Hotspot Mitigation only Fix from $1,6002017-07-31 CRITICAL 9.8 CVE-2017-11645 NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 do not require authentication for logfile.html, status.… 4gt101w Software Mitigation only Fix from $2,3002017-07-28 CRITICAL 9.8 CVE-2017-2126 WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access t… Wapm 1166d Firmware after 1.16.1 Fix from $2,3002017-07-22 CRITICAL 9.8 CVE-2017-6530 Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 do not check password.shtml authorization, leading to Arbitrary password change. Coaxdata Gateway 1gbps Firmware Mitigation only Fix from $2,3002017-07-20 MEDIUM 5.9 CVE-2017-8006 In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as… Rsa Authentication Manager after 8.2 Fix from $1,6002017-07-17 HIGH 8.8 CVE-2017-2341 An insufficient authentication vulnerability on platforms where Junos OS instances are run in a virtualized environment, may allow unprivileged users… Junos Mitigation only Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-1000068 TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resulting in the ability to disab… Testtrack after 1.0 Fix from $1,9502017-07-17 HIGH 8.1 CVE-2017-1000071 Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS… Phpcas Mitigation only Fix from $1,9502017-07-17 CRITICAL 9.8 CVE-2017-10601 A specific device configuration can result in a commit failure condition. When this occurs, a user is logged in without being prompted for a password… Junos Mitigation only Fix from $2,3002017-07-17 CRITICAL 9.8 CVE-2017-1000020 SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by … Embedded Web Servers after 1.3.1 Fix from $2,3002017-07-17 CRITICAL 9.8 CVE-2017-1000030 Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possib… Glassfish Server Mitigation only Fix from $2,3002017-07-17 HIGH 7.5 CVE-2016-8951 IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vu… Emptoris Strategic Supply Management Patch available Fix from $1,9502017-07-13 HIGH 7.5 CVE-2017-8495 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… Windows 10 Patch available Fix from $1,9502017-07-11 CRITICAL 9.8 CVE-2017-5640 It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to ski… Impala Mitigation only Fix from $2,3002017-07-10 HIGH 7.5 CVE-2017-7660EPSS 6% Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node… Solr Mitigation only Fix from $1,9502017-07-07 HIGH 8.1 CVE-2017-6868 An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attacker may … Simatic Cp 44x 1 Redundant Network Access Modules after 1.4.0 Fix from $1,9502017-07-07 HIGH 8.8 CVE-2017-2186 HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to bypass authentication to load malicious firmware via WebUI. Home Spot Cube 2 Firmware Mitigation only Fix from $1,9502017-07-07 CRITICAL 9.8 CVE-2017-7405 On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the… Dir 615 after 20.12ptb01 Fix from $2,3002017-07-07 CRITICAL 9.1 CVE-2017-6711 A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain u… Ultra Services Framework after 5.0.2 Fix from $2,3002017-07-06 HIGH 7.5 CVE-2017-1264 IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or fun… Security Guardium Mitigation only Fix from $1,9502017-07-05 MEDIUM 6.5 CVE-2017-1258 IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access… Security Guardium Mitigation only Fix from $1,6002017-07-05 CRITICAL 9.8 CVE-2017-10807 JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enable… Jabberd2 after 2.6.0 Fix from $2,3002017-07-04 MEDIUM 5.9 CVE-2017-6703 A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack a… Prime Collaboration Provisioning Mitigation only Fix from $1,6002017-07-04 MEDIUM 6.1 CVE-2017-6722 A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauth… Unified Contact Center Express Mitigation only Fix from $1,6002017-07-04 CRITICAL 9.8 CVE-2017-7919 An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific uniform r… Xps Cx Firmware Mitigation only Fix from $2,3002017-07-03 MEDIUM 6.5 CVE-2017-10796 On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:… Nc250 Firmware after 1.2.1 Fix from $1,6002017-07-02