Vulnerabilities (CVE)

Filtered by CWE-287
Total 3712 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-3096 1 Dlink 2 Dir865l, Dir865l Firmware 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.
CVE-2013-3091 1 Belkin 2 N300, N300 Firmware 2024-11-21 10.0 HIGH 9.8 CRITICAL
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
CVE-2013-3088 1 Belkin 2 N900, N900 Firmware 2024-11-21 9.3 HIGH 9.8 CRITICAL
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
CVE-2013-3085 1 Belkin 2 F5d8236-4, F5d8236-4 Firmware 2024-11-21 7.5 HIGH 9.8 CRITICAL
An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.
CVE-2013-3072 1 Netgear 2 Wndr4700, Wndr4700 Firmware 2024-11-21 7.5 HIGH 9.8 CRITICAL
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.
CVE-2013-3071 1 Netgear 2 Wndr4700, Wndr4700 Firmware 2024-11-21 7.5 HIGH 9.8 CRITICAL
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
CVE-2013-2681 1 Cisco 2 Linksys E4200, Linksys E4200 Firmware 2024-11-21 4.3 MEDIUM 9.8 CRITICAL
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.
CVE-2013-2569 1 Zavio 4 F3105, F3105 Firmware, F312a and 1 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream.
CVE-2013-2159 1 Monkey-project 1 Monkey 2024-11-21 7.5 HIGH 9.8 CRITICAL
Monkey HTTP Daemon: broken user name authentication
CVE-2013-2120 1 Kde 1 Paste Applet 2024-11-21 2.1 LOW 8.4 HIGH
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.
CVE-2013-1600 1 Dlink 4 Dcs-2102, Dcs-2102 Firmware, Dcs-2121 and 1 more 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-2121 1.06_FR, 1.06, and 1.05_RU, DCS-2102 1.06_FR. 1.06, and 1.05_RU, which could let a malicious user obtain sensitive information.
CVE-2013-1596 1 Vivotek 2 Pt7135, Pt7135 Firmware 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554.
CVE-2013-1391 5 Capturecctv, Hachi, Huntcctv and 2 more 40 Cdr 0410ve, Cdr 0410ve Firmware, Cdr 0820vde and 37 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.
CVE-2013-1360 1 Sonicwall 4 Analyzer, Global Management System, Universal Management Appliance and 1 more 2024-11-21 10.0 HIGH 9.8 CRITICAL
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.
CVE-2013-1359 1 Sonicwall 4 Analyzer, Global Management System, Universal Management Appliance and 1 more 2024-11-21 10.0 HIGH 9.8 CRITICAL
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.
CVE-2013-10004 1 Telecomsoftware 2 Samwin Agent, Samwin Contact Center 2024-11-21 5.0 MEDIUM 6.5 MEDIUM
A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the function passwordScramble in the library SAMwinLIBVB.dll of the component Password Handler. Incorrect implementation of a hashing function leads to predictable authentication possibilities. Upgrading to version 6.2 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2012-6710 1 Extplorer 1 Extplorer 2024-11-21 7.5 HIGH 9.8 CRITICAL
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.
CVE-2012-6451 1 Lorextechnology 4 Lnc104, Lnc104 Firmware, Lnc116 and 1 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
CVE-2012-6340 1 Netgear 4 Wgr614v7, Wgr614v7 Firmware, Wgr614v9 and 1 more 2024-11-21 2.1 LOW 4.6 MEDIUM
An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002.
CVE-2012-3824 1 Arialsoftware 1 Campaign Enterprise 2024-11-21 5.0 MEDIUM 7.5 HIGH
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.