Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.4 CVE-2017-6617 A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) c… Integrated Management Controller Supervisor Mitigation only Fix from $1,6002017-04-20 CRITICAL 9.8 CVE-2016-1219 Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. Garoon after 4.2.1 Fix from $2,3002017-04-20 MEDIUM 5.5 CVE-2016-5410 firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (… Enterprise Linux Desktop after 0.4.3.2 Fix from $1,6002017-04-19 HIGH 8.8 CVE-2017-7284 An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the passw… Enterprise Backup after 9.1.1 Fix from $1,9502017-04-12 CRITICAL 9.8 CVE-2017-7588EPSS 34% On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affect… Mfc Firmware No fix yet Fix from $2,3002017-04-12 CRITICAL 9.8 CVE-2016-1908EPSS 14% The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-contr… Debian Linux Patch available Fix from $2,3002017-04-11 CRITICAL 9.8 CVE-2016-5068 Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests. Aleos Firmware No fix yet Fix from $2,3002017-04-10 HIGH 8.8 CVE-2015-2880 TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account. Tv Ip743sic No fix yet Fix from $1,9502017-04-10 CRITICAL 9.8 CVE-2007-6759 Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle a… Ibootbar Firmware after 2007-09-20 Fix from $2,3002017-04-07 CRITICAL 9.8 CVE-2007-6760 Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attac… Ibootbar Firmware after 2007-09-20 Fix from $2,3002017-04-07 CRITICAL 9.8 CVE-2017-7450 AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. It is possible to extract all… Hdmi Dongle Firmware after 2.1.1 Fix from $2,3002017-04-05 CRITICAL 9.8 CVE-2016-10309 In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value … Fibeair Ip 10 Firmware after 7.1.0 Fix from $2,3002017-03-30 HIGH 8.8 CVE-2017-2689 Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain pri… Ruggedcom Rox I after 2.9.0 Fix from $1,9502017-03-29 CRITICAL 9.8 CVE-2016-9124 Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable … Revive Adserver after 3.2.2 Fix from $2,3002017-03-28 HIGH 8.1 CVE-2016-9463 Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownC… Nextcloud Server 8.2.9 / 9.0.4+ Fix from $1,9502017-03-28 HIGH 7.5 CVE-2017-5237 Due to a lack of authentication, an unauthenticated user who knows the Eview EV-07S GPS Tracker's phone number can revert the device to a factory def… Ev 07s Gps Tracker Firmware Mitigation only Fix from $1,9502017-03-27 CRITICAL 9.8 CVE-2016-4926 Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to … Junos Space after 15.2 Fix from $2,3002017-03-20 MEDIUM 5.3 CVE-2017-3867 A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implementation of Cisco Adaptive Security Appliance (AS… Adaptive Security Appliance Software Mitigation only Fix from $1,6002017-03-17 MEDIUM 6.5 CVE-2017-3880 An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting infor… Webex Meetings Server Mitigation only Fix from $1,6002017-03-17 HIGH 7.3 CVE-2017-6967 xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with … Xrdp Patch available Fix from $1,9502017-03-17 HIGH 7.8 CVE-2017-0100 A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windo… Windows 10 Patch available Fix from $1,9502017-03-17 CRITICAL 9.8 CVE-2017-3831EPSS 5% A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass au… Aironet Access Point Software Mitigation only Fix from $2,3002017-03-15 HIGH 8.8 CVE-2017-3854 A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote attacker to impersonate a WLC… Wireless Lan Controller Firmware Mitigation only Fix from $1,9502017-03-15 HIGH 7.5 CVE-2016-8022EPSS 13% Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated… Virusscan Enterprise after 2.0.3 Fix from $1,9502017-03-14 HIGH 8.1 CVE-2016-8023EPSS 9% Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote u… Virusscan Enterprise after 2.0.3 Fix from $1,9502017-03-14 CRITICAL 9.8 CVE-2017-5619 An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g.… Zammad after 1.0.3 Fix from $2,3002017-03-13 CRITICAL 9.8 CVE-2017-6526EPSS 57% An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected adm… Dnalims No fix yet Fix from $2,3002017-03-09 HIGH 8.8 CVE-2017-6549EPSS 8% Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87… Rt Ac53 Firmware No fix yet Fix from $1,9502017-03-09 MEDIUM 6.5 CVE-2016-9729 IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. … Qradar Security Information And Event Manager Patch available Fix from $1,6002017-03-07 CRITICAL 9.8 CVE-2016-7145 The m_authenticate function in ircd/m_authenticate.c in nefarious2 allows remote attackers to spoof certificate fingerprints and consequently log in … Nefarious2 Patch available Fix from $2,3002017-03-07