Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.6 CVE-2016-2076 Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Iden… Vcenter Server after 6.0 Fix from $1,9502016-04-15 CRITICAL 9.8 CVE-2016-0733 The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to by… Ranger after 0.5.0 Fix from $2,3002016-04-12 CRITICAL 9.8 CVE-2016-2245EPSS 6% HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors. Support Assistant after 8.1.40.3 Fix from $2,3002016-03-19 CRITICAL 9.8 CVE-2016-1329 Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardc… X14j Firmware 2.50+ Fix from $2,3002016-03-03 MEDIUM 5.4 CVE-2016-1307 The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it e… Gs1900 10hp Firmware 2.50+ Fix from $1,6002016-02-07 HIGH 8.1 CVE-2015-7914 Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without k… Moduweb Vision after 1.5.5 Fix from $1,9502016-02-06 HIGH 7.5 CVE-2015-8269 The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 80… Smart Toy Bear Mitigation only Fix from $1,9502016-02-04 HIGH 7.3 CVE-2016-0755EPSS 9% The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow … Curl after 7.46.0 Fix from $1,9502016-01-29 HIGH 8.3 CVE-2015-7521EPSS 6% The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, … Hive No fix yet Fix from $1,9502016-01-29 HIGH 7.7 CVE-2015-7974EPSS 6% NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remot… Debian Linux 4.2.8 / 4.3.90+ Fix from $1,9502016-01-26 CRITICAL 9.8 CVE-2015-6314 Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change conf… Wireless Lan Controller Software Mitigation only Fix from $2,3002016-01-15 CRITICAL 9.8 CVE-2015-7938 Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors. Eki 1321 Series Firmware after 2015-10-06 Fix from $2,3002016-01-09 HIGH 8.3 CVE-2015-6480 The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain a… Oncell Central Manager after 2.0 Fix from $1,9502015-12-21 HIGH 7.3 CVE-2015-1772EPSS 7% The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.… Hive Mitigation only Fix from $1,9502015-12-21 CRITICAL 9.8 CVE-2015-7755 KEVEPSS 61% Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15… Screenos Mitigation only Fix from $2,3002015-12-19 HIGH 7.5 CVE-2015-6401EPSS 8% Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspeci… Epc3928 Docsis 3.0 8x4 Wireless Residential Gateway With Embedded Digital Voice Adapter No fix yet Fix from $1,9502015-12-14 HIGH 9.0 CVE-2015-6389 Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH… Prime Collaboration Assurance Mitigation only Fix from $1,9502015-12-13 MEDIUM 5.8 CVE-2015-7285 CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allo… Gprs Cs2300 R Firmware No fix yet Fix from $1,6002015-11-25 HIGH 9.3 CVE-2015-7361 FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for a… Fortios Mitigation only Fix from $1,9502015-10-15 HIGH 7.0 CVE-2015-5649 Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP inj… Garoon Mitigation only Fix from $1,9502015-10-08 MEDIUM 5.0 CVE-2015-5372 The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 c… Nevisauth after 4.18.3.0 Fix from $1,6002015-09-28 HIGH 9.3 CVE-2015-6280 The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S before 3.10.6S, 3.11S before… iOS Mitigation only Fix from $1,9502015-09-28 HIGH 10.0 CVE-2015-5998 Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remote attackers to execute arbitr… Impero Education Pro after 5008 Fix from $1,9502015-09-14 HIGH 9.4 CVE-2014-9605 WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a syst… Netsweeper 3.1.10 / 4.0.9+ Fix from $1,9502015-09-04 MEDIUM 5.0 CVE-2015-6266 The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote att… Identity Services Engine Software Mitigation only Fix from $1,6002015-08-28 HIGH 7.5 CVE-2014-3612EPSS 7% The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att… Activemq Mitigation only Fix from $1,9502015-08-24 HIGH 7.2 CVE-2015-3775 Apple OS X before 10.10.5 does not properly implement authentication, which allows local users to obtain admin privileges via unspecified vectors. Mac Os X after 10.10.4 Fix from $1,9502015-08-16 HIGH 7.5 CVE-2015-1486EPSS 68% The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a… Endpoint Protection Manager No fix yet Fix from $1,9502015-08-01 MEDIUM 5.0 CVE-2015-2978 Webservice-DIC yoyaku_v41 allows remote attackers to bypass authentication and complete a conference-room reservation via unspecified vectors, as dem… Yoyaku No fix yet Fix from $1,6002015-07-29 MEDIUM 5.0 CVE-2015-4453 interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive informa… Openemr Patch available Fix from $1,6002015-07-05