Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2009-4801 EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts. Ez Blog No fix yet Fix from $1,9502010-04-23 HIGH 7.5 CVE-2009-4806 admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to re… Digital Interchange Document Library No fix yet Fix from $1,9502010-04-23 MEDIUM 5.8 CVE-2010-0744 aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's C… Alvaros Messenger after 0.98.3 Fix from $1,6002010-04-20 MEDIUM 5.0 CVE-2010-1221 CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request. Xosoft Content Distribution Patch available Fix from $1,6002010-04-07 MEDIUM 5.0 CVE-2010-1222 CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP reques… Xosoft Content Distribution Patch available Fix from $1,6002010-04-07 HIGH 7.5 CVE-2009-2936EPSS 64% The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 doe… Varnish Mitigation only Fix from $1,9502010-04-05 MEDIUM 6.4 CVE-2010-1191 Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable ad… Sahana Mitigation only Fix from $1,6002010-03-31 MEDIUM 5.0 CVE-2010-0521 Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to … Mac Os X after 10.6.2 Fix from $1,6002010-03-30 HIGH 7.2 CVE-2010-0498 Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local user… Mac Os X after 10.6.2 Fix from $1,9502010-03-30 MEDIUM 6.8 CVE-2010-1097 include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain adminis… Dedecms No fix yet Fix from $1,6002010-03-24 MEDIUM 5.8 CVE-2010-1040 The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device su… Openpne Mitigation only Fix from $1,6002010-03-23 HIGH 7.5 CVE-2010-1022 The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication … T3sec Saltedpw after 0.2.12 Fix from $1,9502010-03-19 HIGH 10.0 CVE-2010-0447EPSS 5% The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate reque… Openview Performance Insight after 5.4 Fix from $1,9502010-03-10 HIGH 7.5 CVE-2009-4670 admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user par… Roomphplanning No fix yet Fix from $1,9502010-03-05 HIGH 7.5 CVE-2009-4671 Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cook… Roomphplanning No fix yet Fix from $1,9502010-03-05 HIGH 7.5 CVE-2009-4675 admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows… Gastro Portal \(restaurant Directory\) Script No fix yet Fix from $1,9502010-03-05 HIGH 7.5 CVE-2009-4657 The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting … Xerver No fix yet Fix from $1,9502010-03-03 MEDIUM 5.8 CVE-2010-0756 Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.… Wikyblog No fix yet Fix from $1,6002010-02-27 HIGH 7.5 CVE-2010-0554 The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attacker… Geo\+\+ Gncaster after 1.4.0.7 Fix from $1,9502010-02-04 HIGH 7.5 CVE-2009-4584 admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain administrative access via a certai… Db Masters Multimedia Links Directory No fix yet Fix from $1,9502010-01-06 HIGH 7.5 CVE-2009-4447 Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.… Jax Guestbook No fix yet Fix from $1,9502009-12-29 MEDIUM 6.8 CVE-2009-4367EPSS 6% The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers … Staging Module after 5.4.0 Fix from $1,6002009-12-21 HIGH 10.0 CVE-2009-3027EPSS 11% VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0… Backup Exec Continuous Protection Server Patch available Fix from $1,9502009-12-11 MEDIUM 5.0 CVE-2009-4232 The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages wit… Com Kide Mitigation only Fix from $1,6002009-12-08 MEDIUM 5.8 CVE-2009-3585 Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows … Rt Patch available Fix from $1,6002009-12-02 MEDIUM 5.8 CVE-2009-4151 Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows … Rt Patch available Fix from $1,6002009-12-02 HIGH 7.2 CVE-2009-4128 GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for phys… Grub 2 Patch available Fix from $1,9502009-12-01 HIGH 7.5 CVE-2009-4095 myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party info… Myphile Patch available Fix from $1,9502009-11-29 MEDIUM 5.0 CVE-2009-4089EPSS 7% telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to aj… Telepark.wiki No fix yet Fix from $1,6002009-11-29 HIGH 7.5 CVE-2009-3966 Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true. Arcade Trade Script No fix yet Fix from $1,9502009-11-18