Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.8 CVE-2014-1295 Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.… Iphone Os after 7.1 Fix from $1,6002014-04-23 MEDIUM 6.8 CVE-2014-2341EPSS 6% Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter. Cubecart after 5.2.8 Fix from $1,6002014-04-22 MEDIUM 6.8 CVE-2014-1984 Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers t… Remote Service Manager after 3.1.0 Fix from $1,6002014-04-19 MEDIUM 6.4 CVE-2014-2338 IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authent… Strongswan Mitigation only Fix from $1,6002014-04-16 MEDIUM 6.4 CVE-2014-0138EPSS 5% The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8)… Curl Mitigation only Fix from $1,6002014-04-15 HIGH 7.8 CVE-2014-2828 The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of serv… Keystone Mitigation only Fix from $1,9502014-04-15 MEDIUM 5.0 CVE-2014-0357 Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modi… Misecuremessages Mitigation only Fix from $1,6002014-04-15 MEDIUM 6.1 CVE-2014-0353 The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to bypass authentication by using %2F sequences in… N300 Netusb Nbg 419n Firmware Mitigation only Fix from $1,6002014-04-15 MEDIUM 5.0 CVE-2013-7366 The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors relate… Software Deployment Manager No fix yet Fix from $1,6002014-04-10 MEDIUM 5.0 CVE-2014-2128 The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 be… Adaptive Security Appliance Software Mitigation only Fix from $1,6002014-04-10 MEDIUM 6.4 CVE-2014-0166EPSS 9% The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the va… WordPress after 3.7.1 Fix from $1,6002014-04-10 HIGH 7.5 CVE-2014-0635 Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vector… Vplex Geosynchrony Mitigation only Fix from $1,9502014-04-01 HIGH 10.0 CVE-2014-1982EPSS 10% The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmwa… Img646bd Firmware Mitigation only Fix from $1,9502014-03-31 MEDIUM 6.5 CVE-2014-0132 The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and … 389 Directory Server after 1.2.11.25 Fix from $1,6002014-03-18 MEDIUM 6.8 CVE-2014-2047 Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote att… Owncloud after 6.0.1 Fix from $1,6002014-03-14 MEDIUM 6.4 CVE-2013-4966 The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attack… Puppet Enterprise after 3.1.1 Fix from $1,6002014-03-09 HIGH 7.8 CVE-2014-1911 The Foscam FI8910W camera with firmware before 11.37.2.55 allows remote attackers to obtain sensitive video and image data via a blank username and p… Fi8919w Firmware after 11.37.2.54 Fix from $1,9502014-03-06 HIGH 10.0 CVE-2014-2075 TIBCO Enterprise Administrator 1.0.0 and Enterprise Administrator SDK 1.0.0 do not properly enforce administrative authentication requirements, which… Enterprise Administrator Mitigation only Fix from $1,9502014-02-27 MEDIUM 5.0 CVE-2014-0743 The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote atta… Unified Communications Manager after 10.0 Fix from $1,6002014-02-27 MEDIUM 5.0 CVE-2014-0733 The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce aut… Unified Communications Manager after 10.0 Fix from $1,6002014-02-20 MEDIUM 5.0 CVE-2014-0732 The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enfor… Unified Communications Manager after 10.0 Fix from $1,6002014-02-20 MEDIUM 5.8 CVE-2012-0062 Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration… Jboss Operations Network after 2.4.1 Fix from $1,6002014-02-14 MEDIUM 5.8 CVE-2012-1100 Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credenti… Jboss Operations Network after 2.4.1 Fix from $1,6002014-02-14 MEDIUM 5.0 CVE-2014-0722 The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers … Unified Communications Manager Mitigation only Fix from $1,6002014-02-13 MEDIUM 5.0 CVE-2014-0725 Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive i… Unified Communications Manager Mitigation only Fix from $1,6002014-02-13 MEDIUM 5.0 CVE-2011-4091 The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows … Opensuse after 1.3.13 Fix from $1,6002014-02-10 HIGH 10.0 CVE-2013-6035 The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE… Gatehouse Mitigation only Fix from $1,9502014-02-04 HIGH 7.8 CVE-2013-7183 cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) via a default_reboot action or… Swc 9100 Mitigation only Fix from $1,9502014-02-04 HIGH 7.5 CVE-2013-4304 The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in… Centralauth Extension Patch available Fix from $1,9502014-01-26 CRITICAL 9.8 CVE-2013-7137EPSS 16% The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting t… Burden 1.8.1+ Fix from $2,3002014-01-26