Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.3 CVE-2019-18332 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A… Sppa T3000 Application Server Mitigation only Fix from $1,6002019-12-12 CRITICAL 9.8 CVE-2019-18314 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A… Sppa T3000 Application Server Mitigation only Fix from $2,3002019-12-12 CRITICAL 9.8 CVE-2019-18315 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A… Sppa T3000 Application Server Mitigation only Fix from $2,3002019-12-12 HIGH 7.5 CVE-2019-18317 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A… Sppa T3000 Application Server Mitigation only Fix from $1,9502019-12-12 HIGH 7.5 CVE-2019-18318 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A… Sppa T3000 Application Server Mitigation only Fix from $1,9502019-12-12 HIGH 7.5 CVE-2019-18319 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A… Sppa T3000 Application Server Mitigation only Fix from $1,9502019-12-12 HIGH 7.5 CVE-2019-18320 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A… Sppa T3000 Application Server Mitigation only Fix from $1,9502019-12-12 CRITICAL 9.1 CVE-2019-18321 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could … Sppa T3000 Ms3000 Migration Server Mitigation only Fix from $2,3002019-12-12 CRITICAL 9.1 CVE-2019-18322 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could … Sppa T3000 Ms3000 Migration Server Mitigation only Fix from $2,3002019-12-12 MEDIUM 5.3 CVE-2019-18312 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could … Sppa T3000 Ms3000 Migration Server Mitigation only Fix from $1,6002019-12-12 CRITICAL 9.8 CVE-2019-18284 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without au… Sppa T3000 Application Server No fix yet Fix from $2,3002019-12-12 MEDIUM 5.3 CVE-2019-18286 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory… Sppa T3000 Application Server No fix yet Fix from $1,6002019-12-12 MEDIUM 5.3 CVE-2019-18287 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory… Sppa T3000 Application Server No fix yet Fix from $1,6002019-12-12 HIGH 7.5 CVE-2013-4593 RubyGem omniauth-facebook has an access token security vulnerability Omniauth Facebook after 1.5.0 Fix from $1,9502019-12-11 MEDIUM 5.4 CVE-2019-14870 All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation mode… Fedora 4.9.17 / 4.10.11+ Fix from $1,6002019-12-10 CRITICAL 9.8 CVE-2013-2159 Monkey HTTP Daemon: broken user name authentication Monkey No fix yet Fix from $2,3002019-12-10 MEDIUM 6.5 CVE-2019-18380 Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow… Industrial Control System Protection 6.1.1.123+ Fix from $1,6002019-12-09 CRITICAL 9.6 CVE-2019-15897 beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not exp… Beegfs after 7.1.3 Fix from $2,3002019-12-05 CRITICAL 9.8 CVE-2019-14910 A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA… Keycloak Mitigation only Fix from $2,3002019-12-05 HIGH 7.8 CVE-2019-17437 An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate pri… Pan Os 7.1.25 / 8.0.20+ Fix from $1,9502019-12-05 HIGH 8.8 CVE-2019-19598 D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value.… Dap 1860 Firmware No fix yet Fix from $1,9502019-12-05 HIGH 7.8 CVE-2019-19519 In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main fun… OpenBSD No fix yet Fix from $1,9502019-12-05 CRITICAL 9.8 CVE-2019-19521 libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/au… OpenBSD No fix yet Fix from $2,3002019-12-05 HIGH 8.3 CVE-2019-14909 A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will… Keycloak Mitigation only Fix from $1,9502019-12-04 MEDIUM 5.3 CVE-2019-19507 In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a confli… Json Pattern Validator 2.1.1+ Fix from $1,6002019-12-02 CRITICAL 9.8 CVE-2019-12394 Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authen… Management System Mitigation only Fix from $2,3002019-12-02 HIGH 8.8 CVE-2019-5218 There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try t… Band 2 Firmware Mitigation only Fix from $1,9502019-11-29 HIGH 7.5 CVE-2019-16201EPSS 5% WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by… Ruby after 2.6.4 Fix from $1,9502019-11-26 CRITICAL 9.8 CVE-2019-6675 BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a v… Big Ip Link Controller after 15.0.1.0.48.11-eng_hotfix Fix from $2,3002019-11-26 MEDIUM 6.5 CVE-2019-14856 ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None Ansible 2.6.20 / 2.7.14+ Fix from $1,6002019-11-26