Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.8 CVE-2016-6434 Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CL… Secure Firewall Management Center No fix yet Fix from $1,9502016-10-06 CRITICAL 9.8 CVE-2016-5686 Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a … Onetouch Ping Firmware Mitigation only Fix from $2,3002016-10-05 CRITICAL 9.8 CVE-2016-5086 Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks. Onetouch Ping Firmware Mitigation only Fix from $2,3002016-10-05 HIGH 7.5 CVE-2016-7141EPSS 8% curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authen… Leap after 7.50.1 Fix from $1,9502016-10-03 HIGH 8.1 CVE-2016-7191EPSS 29% The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize th… Azure Active Directory Passport Patch available Fix from $1,9502016-09-28 HIGH 7.5 CVE-2016-6159 The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and… Ws331a Router Firmware Mitigation only Fix from $1,9502016-09-21 MEDIUM 6.5 CVE-2016-4966 The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via v… Fortiwan after 4.2.4 Fix from $1,6002016-09-21 HIGH 7.3 CVE-2016-4860 Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers… Stardom Fcn\/fcj Mitigation only Fix from $1,9502016-09-19 CRITICAL 9.8 CVE-2016-0883 Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installa… Operations Manager after 1.5.13 Fix from $2,3002016-09-18 CRITICAL 9.8 CVE-2016-1279 J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 1… Junos after 12.1x46 Fix from $2,3002016-09-09 HIGH 8.8 CVE-2016-7114 A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP … En100 Ethernet Module Firmware Mitigation only Fix from $1,9502016-09-06 CRITICAL 9.8 CVE-2016-7112 A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP … En100 Ethernet Module Firmware after 4.28 Fix from $2,3002016-09-06 HIGH 8.1 CVE-2016-6377 Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and ma… Media Origination System Suite Mitigation only Fix from $1,9502016-09-03 HIGH 8.8 CVE-2015-6397 Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obt… Rv110w Wireless N Vpn Firewall Firmware Mitigation only Fix from $1,9502016-08-08 HIGH 7.8 CVE-2016-1278 Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a… Junos after 12.1x46 Fix from $1,9502016-08-05 MEDIUM 5.3 CVE-2016-5133 Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a prox… Chrome after 51.0.2704.106 Fix from $1,6002016-07-23 CRITICAL 9.8 CVE-2016-4503 Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings and data, via vectors relate… Device Server Web Console 5232 N Firmware Mitigation only Fix from $2,3002016-07-12 HIGH 7.5 CVE-2016-4953EPSS 17% ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypt… Ntp 4.2.8 / 4.3.93+ Fix from $1,9502016-07-05 HIGH 7.5 CVE-2016-1427 The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remo… Prime Network Registrar Mitigation only Fix from $1,9502016-06-18 MEDIUM 6.5 CVE-2016-3085 Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl… Cloudstack No fix yet Fix from $1,6002016-06-10 CRITICAL 9.8 CVE-2016-0916EPSS 8% EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary… Networker 8.2.2.6 / 9.0.0.6+ Fix from $2,3002016-06-10 CRITICAL 9.1 CVE-2016-4510EPSS 20% The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbit… Vtscada Mitigation only Fix from $2,3002016-06-09 CRITICAL 9.1 CVE-2016-4432EPSS 8% The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons… Qpid Broker J 6.0.3+ Fix from $2,3002016-06-01 MEDIUM 5.9 CVE-2016-3094EPSS 8% PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a… Qpid Broker J after 6.0.2 Fix from $1,6002016-06-01 HIGH 7.5 CVE-2016-2286 Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 … Miineport E2 1242 Firmware Mitigation only Fix from $1,9502016-05-31 HIGH 7.5 CVE-2016-1402 The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorizati… Identity Services Engine Software Mitigation only Fix from $1,9502016-05-21 MEDIUM 6.5 CVE-2016-2012 HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors. Network Node Manager I Patch available Fix from $1,6002016-05-07 CRITICAL 9.8 CVE-2016-4422 The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg… Debian Linux Mitigation only Fix from $2,3002016-05-06 CRITICAL 9.8 CVE-2016-1387 The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8… Telepresence Tc Software Mitigation only Fix from $2,3002016-05-05 MEDIUM 6.5 CVE-2016-2300 Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors. Integraxor after 4.2.4502 Fix from $1,6002016-04-22