Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2018-7847 A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which… Modicon M580 Firmware No fix yet Fix from $2,3002019-05-22 CRITICAL 9.8 CVE-2019-6814EPSS 37% A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to con… Net5501 Firmware 2.1.9.7+ Fix from $2,3002019-05-22 HIGH 8.1 CVE-2019-8443 The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows … Jira 7.13.4 / 8.0.4+ Fix from $1,9502019-05-22 HIGH 7.5 CVE-2019-10911 In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker … Symfony 2.7.51 / 2.8.50+ Fix from $1,9502019-05-16 HIGH 8.1 CVE-2019-8978EPSS 6% An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 an… Banner Enterprise Identity Services No fix yet Fix from $1,9502019-05-14 MEDIUM 5.9 CVE-2019-7218 Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline … Sharefile after 19.1 Fix from $1,6002019-05-13 CRITICAL 10.0 CVE-2019-1867EPSS 30% A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication o… Elastic Services Controller 4.5+ Fix from $2,3002019-05-10 HIGH 7.1 CVE-2017-12778 The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorr… Qbittorrent No fix yet Fix from $1,9502019-05-09 CRITICAL 9.8 CVE-2018-13990 The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction … Fl Switch 3005 Firmware 1.35+ Fix from $2,3002019-05-06 HIGH 8.8 CVE-2019-1724 A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Rout… Rv325 Dual Wan Gigabit Vpn Router Firmware Mitigation only Fix from $1,9502019-05-03 CRITICAL 9.8 CVE-2019-3927 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.… Am 100 Firmware No fix yet Fix from $2,3002019-04-30 CRITICAL 9.8 CVE-2019-11576 Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send th… Gitea 1.8.0+ Fix from $2,3002019-04-28 HIGH 8.1 CVE-2019-11488 Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allows Unauthorized Attackers to R… Simplybook 2019-04-23+ Fix from $1,9502019-04-25 HIGH 8.8 CVE-2018-16219 A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same netwo… 405hd Firmware No fix yet Fix from $1,9502019-04-25 CRITICAL 9.8 CVE-2019-11081 A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative access to the application serv… Sidexis Mitigation only Fix from $2,3002019-04-24 HIGH 8.8 CVE-2018-1317 In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentica… Zeppelin 0.8.0+ Fix from $1,9502019-04-23 CRITICAL 9.8 CVE-2019-11234EPSS 8% FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. Fedora 3.0.19+ Fix from $2,3002019-04-22 MEDIUM 6.8 CVE-2019-11015 A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscreen based authentication via t… Miui No fix yet Fix from $1,6002019-04-18 HIGH 7.8 CVE-2018-16877 A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could us… Ubuntu Linux after 2.0.0 Fix from $1,9502019-04-18 HIGH 7.5 CVE-2018-0382 A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software cou… Wireless Lan Controller Software Mitigation only Fix from $1,9502019-04-17 CRITICAL 9.8 CVE-2019-10643 Contao 4.7 allows Use of a Key Past its Expiration Date. Contao Cms No fix yet Fix from $2,3002019-04-17 HIGH 7.5 CVE-2018-7340 Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attack… Duo Network Gateway after 1.2.9 Fix from $1,9502019-04-17 HIGH 8.1 CVE-2019-9498 The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not va… Fedora after 11.1 Fix from $1,9502019-04-17 HIGH 8.1 CVE-2019-9499 The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do n… Fedora after 11.1 Fix from $1,9502019-04-17 HIGH 7.5 CVE-2019-3798 Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote aut… Capi Release 1.79.0+ Fix from $1,9502019-04-17 HIGH 7.5 CVE-2019-9496 An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE conf… Fedora after 2.7 Fix from $1,9502019-04-17 HIGH 8.1 CVE-2019-9497 The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. Thi… Fedora after 2.7 Fix from $1,9502019-04-17 CRITICAL 9.8 CVE-2017-11427 OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attack… Pythonsaml after 2.3.0 Fix from $2,3002019-04-17 CRITICAL 9.8 CVE-2017-11428 OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacke… Ruby Saml after 1.6.0 Fix from $2,3002019-04-17 CRITICAL 9.8 CVE-2017-11429 Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may… Saml2 Js after 2.0 Fix from $2,3002019-04-17