Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.8 CVE-2015-1330 unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in… Ubuntu Linux after 0.86 Fix from $1,6002015-07-01 HIGH 7.5 CVE-2014-4882 Aptexx Resident Anywhere does not require authentication, which allows remote attackers to obtain sensitive information or modify data via a direct r… Resident Anywhere Mitigation only Fix from $1,9502015-06-23 HIGH 7.5 CVE-2015-2117EPSS 9% HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1… Tippingpoint Security Management System after 4.2 Fix from $1,9502015-04-27 MEDIUM 6.8 CVE-2015-2823 Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Up… Wincc after 13.0 Fix from $1,6002015-04-08 HIGH 10.0 CVE-2015-0198 IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows … General Parallel File System Patch available Fix from $1,9502015-03-24 MEDIUM 6.4 CVE-2015-0670 The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows re… Spa500 Firmware Mitigation only Fix from $1,6002015-03-21 HIGH 10.0 CVE-2015-0653 The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before… Expressway Software Mitigation only Fix from $1,9502015-03-13 HIGH 10.0 CVE-2015-2033 Anyterm Daemon in Infoblox Network Automation NetMRI before NETMRI-23483 allows remote attackers to execute arbitrary commands with root privileges v… Netmri after 6.8.2.11 Fix from $1,9502015-02-20 MEDIUM 5.0 CVE-2014-9045 The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requ… Owncloud after 5.0.17 Fix from $1,6002015-02-04 MEDIUM 5.0 CVE-2014-9043 The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers… Owncloud after 5.0.17 Fix from $1,6002015-02-04 MEDIUM 5.0 CVE-2014-8033 The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID… Webex Meetings Server Mitigation only Fix from $1,6002015-01-09 MEDIUM 5.0 CVE-2014-9578 VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain l… Vdg Sense No fix yet Fix from $1,6002015-01-08 HIGH 7.5 CVE-2013-4793 The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require… Umbraco Cms after 6.0.3 Fix from $1,9502014-12-27 HIGH 8.5 CVE-2014-7879 HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configuration includes libpam_updbe, allows remote authenticated users to bypass authentication,… Hp Ux Patch available Fix from $1,9502014-12-10 MEDIUM 5.0 CVE-2014-7807 Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, … Cloudstack Mitigation only Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-9217 Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards. Graylog2 after 0.91.3 Fix from $1,6002014-12-08 MEDIUM 5.0 CVE-2014-4631 RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authent… Rsa Adaptive Authentication On Premise Mitigation only Fix from $1,6002014-12-08 MEDIUM 5.0 CVE-2014-9184 ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) … Zxdsl No fix yet Fix from $1,6002014-12-02 HIGH 7.8 CVE-2014-8424EPSS 60% ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication. Vap2500 Firmware after 08.41 Fix from $1,9502014-11-28 MEDIUM 5.8 CVE-2014-4831 IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2… Qradar Risk Manager Patch available Fix from $1,6002014-11-28 HIGH 7.5 CVE-2014-2373 The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors… Axm Net Patch available Fix from $1,9502014-11-05 MEDIUM 6.8 CVE-2014-8472 CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assi… Cloud Service Management after 2014 Fix from $1,6002014-11-04 MEDIUM 5.0 CVE-2014-3623EPSS 9% Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does … Wss4j 1.6.17 / 2.0.2+ Fix from $1,6002014-10-30 HIGH 7.5 CVE-2014-8522 The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers t… Network Data Loss Prevention after 9.2.2 Fix from $1,9502014-10-29 MEDIUM 5.0 CVE-2014-8763 DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password sta… Dokuwiki after 2014-05-05a Fix from $1,6002014-10-22 MEDIUM 5.0 CVE-2014-8764 DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user na… Mageia after 2013-12-08 Fix from $1,6002014-10-22 MEDIUM 5.0 CVE-2014-8088 The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to … Zend Framework after 1.12.7 Fix from $1,6002014-10-22 MEDIUM 5.0 CVE-2014-6387 gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers a… Mantisbt after 1.2.17 Fix from $1,6002014-10-22 HIGH 10.0 CVE-2014-8329 Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which… Technik Microcontrol Firmware after 1.7.0 Fix from $1,9502014-10-20 MEDIUM 6.5 CVE-2014-2062 Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to reta… Jenkins after 1.550 Fix from $1,6002014-10-17