Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.8 CVE-2017-10709 The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressin… Android Mitigation only Fix from $1,6002017-06-30 CRITICAL 9.8 CVE-2017-6034EPSS 5% An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted i… Modbus Firmware No fix yet Fix from $2,3002017-06-30 CRITICAL 9.8 CVE-2015-1778 The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and pass… Opendaylight Patch available Fix from $2,3002017-06-27 CRITICAL 9.8 CVE-2017-4989 In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypa… Avamar Server Mitigation only Fix from $2,3002017-06-21 CRITICAL 9.8 CVE-2017-3167EPSS 20% In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication p… HTTP Server 2.2.33 / 2.4.26+ Fix from $2,3002017-06-20 HIGH 7.8 CVE-2017-3745 In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password … Xclarity Administrator after 1.2.2 Fix from $1,9502017-06-20 HIGH 7.8 CVE-2017-9552 A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology … Photo Station Mitigation only Fix from $1,9502017-06-13 CRITICAL 9.8 CVE-2017-9542EPSS 5% D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to val… Dir 615 Firmware Mitigation only Fix from $2,3002017-06-11 CRITICAL 9.8 CVE-2016-7836 KEVEPSS 19% SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the mana… Skysea Client View after 11.221.03 Fix from $2,3002017-06-09 HIGH 7.5 CVE-2015-2800 The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH012 and S7700, S9300, and S97… S5700 Firmware Mitigation only Fix from $1,9502017-06-08 HIGH 7.5 CVE-2017-7314 An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of databa… Personify360 E Business after 7.6.1 Fix from $1,9502017-06-07 MEDIUM 5.5 CVE-2014-8180 MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can caus… MongoDB Patch available Fix from $1,6002017-06-06 HIGH 7.8 CVE-2014-9952 In the Secure File System in all Android releases from CAF using the Linux kernel, a capture-replay vulnerability could potentially exist. Android Patch available Fix from $1,9502017-06-06 CRITICAL 9.8 CVE-2017-9148 The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably … Freeradius Mitigation only Fix from $2,3002017-05-29 HIGH 7.3 CVE-2014-0097 The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows… Spring Security Mitigation only Fix from $1,9502017-05-25 CRITICAL 9.8 CVE-2014-3527 When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authent… Spring Security Mitigation only Fix from $2,3002017-05-25 HIGH 8.1 CVE-2015-6817 PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username. Pgbouncer Patch available Fix from $1,9502017-05-23 HIGH 8.8 CVE-2017-9100EPSS 85% login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the… Dir 600m Firmware No fix yet Fix from $1,9502017-05-21 MEDIUM 6.8 CVE-2017-8879 Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to ob… Dolibarr Erp\/crm No fix yet Fix from $1,6002017-05-10 CRITICAL 9.1 CVE-2017-8827 forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibl… Genixcms Patch available Fix from $2,3002017-05-08 CRITICAL 9.8 CVE-2017-7909 A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses… Mesr901 Firmware after 1.5.2 Fix from $2,3002017-05-06 CRITICAL 9.8 CVE-2017-7921 KEVEPSS 100% An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5… Ds 2cd2032 I Firmware Patch available Fix from $2,3002017-05-06 MEDIUM 5.3 CVE-2017-6624 A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthoriz… iOS Mitigation only Fix from $1,6002017-05-03 HIGH 8.8 CVE-2017-8403 360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, whi… 4k Camera Firmware Mitigation only Fix from $1,9502017-05-01 HIGH 7.3 CVE-2017-2101 Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to perform arb… Appgoat after 3.0.0 Fix from $1,9502017-04-28 HIGH 7.5 CVE-2017-8223 On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via … Wireless Ip Camera \(p2p\) Firmware No fix yet Fix from $1,9502017-04-25 HIGH 8.3 CVE-2017-2319 A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromi… Northstar Controller after 2.1.0 Fix from $1,9502017-04-24 MEDIUM 6.2 CVE-2017-2329 An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an … Northstar Controller after 2.1.0 Fix from $1,6002017-04-24 HIGH 8.8 CVE-2017-2332 An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a m… Northstar Controller after 2.1.0 Fix from $1,9502017-04-24 MEDIUM 5.3 CVE-2017-8078 On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This af… Tl Sg108e Firmware No fix yet Fix from $1,6002017-04-23