Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Am 100 Firmware MEDIUM 5.3
CVE-2019-3934EPSS 8%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST requ…

No fix yet
Fix from $1,600 2019-04-30
Am 100 Firmware CRITICAL 9.1
CVE-2019-3935

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requ…

No fix yet
Fix from $2,300 2019-04-30
Am 100 Firmware HIGH 7.5
CVE-2019-3936

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The …

Mitigation only
Fix from $1,950 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3927

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.…

No fix yet
Fix from $2,300 2019-04-30
Am 100 Firmware MEDIUM 5.3
CVE-2019-3928

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcode via the iso.3.6.1.4.1.3212.…

Mitigation only
Fix from $1,600 2019-04-30
Am 100 Firmware MEDIUM 5.3
CVE-2019-3933EPSS 6%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/bro…

No fix yet
Fix from $1,600 2019-04-30
Cr Ir 357 Fcr Carbon X Firmware CRITICAL 9.8
CVE-2019-10950

Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure teln…

Mitigation only
Fix from $2,300 2019-04-30
Global Management System HIGH 8.1
CVE-2019-7476

A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnera…

Fix: after 8.3
Fix from $1,950 2019-04-26
Snapweb HIGH 7.5
CVE-2016-1587

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, no…

Fix: 0.21.2+
Fix from $1,950 2019-04-22
Ios Xr HIGH 8.6
CVE-2019-1686

A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 9000 Series Aggregation Services Routers could allow…

Fix: 6.5.2 / 6.6.1+
Fix from $1,950 2019-04-17
Satellite HIGH 8.0
CVE-2019-3845

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite…

Fix: 6.2+
Fix from $1,950 2019-04-11
Junos CRITICAL 9.8
CVE-2019-0036

When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silen…

Mitigation only
Fix from $2,300 2019-04-10
Junos HIGH 8.6
CVE-2019-0041

On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The devic…

Mitigation only
Fix from $1,950 2019-04-10
Email Security CRITICAL 9.8
CVE-2019-6140

A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid regis…

Fix: after 8.5.3
Fix from $2,300 2019-04-09
Ipsec Vpn MEDIUM 5.9
CVE-2019-8456EPSS 20%

Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setu…

No fix yet
Fix from $1,600 2019-04-09
Odoo MEDIUM 6.5
CVE-2018-15631

Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attac…

Fix: after 12.0
Fix from $1,600 2019-04-09
Odoo HIGH 8.8
CVE-2018-15640EPSS 8%

Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges …

Fix: after 12.0
Fix from $1,950 2019-04-09
Srn 4000 Firmware CRITICAL 9.8
CVE-2017-7912

Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attac…

Fix: 2.16_170401+
Fix from $2,300 2019-04-08
Webaccess HIGH 7.5
CVE-2019-6554

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service cond…

Fix: after 8.3.5
Fix from $1,950 2019-04-05
Sonicosv CRITICAL 9.8
CVE-2019-7475

A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivileged user to access advanced…

Fix: after 5.9.1.10
Fix from $2,300 2019-04-02
Ios Xe MEDIUM 5.3
CVE-2019-1759

A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unaut…

Patch available
Fix from $1,600 2019-03-28
Pluto1203 CRITICAL 9.8
CVE-2017-9626

Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based application…

Mitigation only
Fix from $2,300 2019-03-27
Mosquitto MEDIUM 6.5
CVE-2018-12546

In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoke…

Fix: after 1.5.5
Fix from $1,600 2019-03-27
Rslogix CRITICAL 9.8
CVE-2010-5305EPSS 6%

The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5…

Mitigation only
Fix from $2,300 2019-03-26
Mycarelink Monitor Firmware MEDIUM 6.5
CVE-2019-6538

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 P…

Mitigation only
Fix from $1,600 2019-03-25
Elasticsearch HIGH 8.1
CVE-2019-7611

A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and…

Fix: 5.6.15 / 6.6.1+
Fix from $1,950 2019-03-25
Enterprise Linux MEDIUM 5.4
CVE-2018-16838

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the ser…

Mitigation only
Fix from $1,600 2019-03-25
Ip Phone 8821 Firmware HIGH 7.5
CVE-2019-1763

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an una…

Fix: 11.0 / 12.5+
Fix from $1,950 2019-03-22
Application Policy Infrastructure Controller MEDIUM 6.5
CVE-2019-1690

A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adj…

Fix: 4.2+
Fix from $1,600 2019-03-11
Nx Os HIGH 7.8
CVE-2019-1601

A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a…

Fix: 6.0 / 6.2+
Fix from $1,950 2019-03-08