Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2019-5909EPSS 5% License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4… B\/m 9000 Vp Mitigation only Fix from $2,3002019-02-13 CRITICAL 9.8 CVE-2018-19645 An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. Solutions Business Manager 11.5+ Fix from $2,3002019-02-12 CRITICAL 9.8 CVE-2019-6527 PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an … Pr100088 Modbus Gateway Firmware Mitigation only Fix from $2,3002019-02-12 MEDIUM 6.4 CVE-2019-3825 A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by select… Ubuntu Linux 3.31.4+ Fix from $1,6002019-02-06 CRITICAL 10.0 CVE-2018-18505 An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and… Firefox 60.5.0 / 65.0+ Fix from $2,3002019-02-05 CRITICAL 9.8 CVE-2019-6519 WebAccess/SCADA, Version 8.3. An improper authentication vulnerability exists that could allow a possible authentication bypass allowing an attacker … Webaccess\/scada Mitigation only Fix from $2,3002019-02-05 HIGH 8.6 CVE-2019-6521 WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and mani… Webaccess\/scada Mitigation only Fix from $1,9502019-02-05 MEDIUM 5.3 CVE-2018-19000EPSS 9% LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data. Laquis Scada 4.1.0.4150+ Fix from $1,6002019-02-05 MEDIUM 6.5 CVE-2018-17928 The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user au… Cms 770 Firmware after 1.7.1 Fix from $1,6002019-01-31 CRITICAL 9.8 CVE-2018-17431EPSS 84% Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL. Unified Threat Management Firewall 2.7.0+ Fix from $2,3002019-01-30 HIGH 7.5 CVE-2018-1668 IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "n… Datapower Gateway after 7.6.0.11 Fix from $1,9502019-01-29 HIGH 8.8 CVE-2018-19023 Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of … Nova M Firmware Mitigation only Fix from $1,9502019-01-25 MEDIUM 6.0 CVE-2019-3584 Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated… Mvision Endpoint 18.11.31.62+ Fix from $1,6002019-01-23 HIGH 7.8 CVE-2018-20735EPSS 7% An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalatio… Patrol Agent after 11.3.01 Fix from $1,9502019-01-17 CRITICAL 9.8 CVE-2018-18814 The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server… Spotfire Analytics Platform For Aws after 10.0.0 Fix from $2,3002019-01-16 HIGH 8.1 CVE-2018-16886 etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is… Enterprise Linux Desktop 3.2.26 / 3.3.11+ Fix from $1,9502019-01-14 CRITICAL 9.8 CVE-2017-13889 In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validatio… Mac Os X 10.13.3+ Fix from $2,3002019-01-11 HIGH 8.1 CVE-2018-5403 Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authenti… Securesphere No fix yet Fix from $1,9502019-01-10 CRITICAL 9.8 CVE-2018-0669 INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. Th… Inplc Rt after 3.08 Fix from $2,3002019-01-09 CRITICAL 9.8 CVE-2018-0670 INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. Th… Inplc Rt after 3.08 Fix from $2,3002019-01-09 HIGH 8.8 CVE-2018-0676 BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to bypass authentication to access to the management scre… Bn Sdwbp3 Firmware after 1.0.9 Fix from $1,9502019-01-09 CRITICAL 9.8 CVE-2018-20675 D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-8… Dir 822 Firmware after 3.10b06 Fix from $2,3002019-01-09 HIGH 7.8 CVE-2019-0543 KEV An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege… Windows 10 1507 Patch available Fix from $1,9502019-01-08 HIGH 7.5 CVE-2018-19249 The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing … Stripe Api Mitigation only Fix from $1,9502019-01-03 MEDIUM 6.5 CVE-2018-19505 Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act … Remedy Action Request System Server No fix yet Fix from $1,6002019-01-03 MEDIUM 6.6 CVE-2018-19937 A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the ph… Vlc For Mobile 3.1.5+ Fix from $1,6002018-12-31 HIGH 8.1 CVE-2018-19616EPSS 30% An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because ac… Powermonitor 1000 Firmware No fix yet Fix from $1,9502018-12-26 HIGH 7.8 CVE-2018-17957 The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, a… Repository Mirroring Tool 1.1.2+ Fix from $1,9502018-12-26 HIGH 8.1 CVE-2018-20422 Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_w… Discuzx No fix yet Fix from $1,9502018-12-24 MEDIUM 6.8 CVE-2018-20342 The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This allows attackers with physical a… Sp012 No fix yet Fix from $1,6002018-12-21