Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ios Xe HIGH 7.5
CVE-2019-12664

A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs…

Mitigation only
Fix from $1,950 2019-09-25
Kinetis Kv1x Firmware MEDIUM 6.6
CVE-2019-14239

On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can…

No fix yet
Fix from $1,600 2019-09-24
Stm32l0 Firmware MEDIUM 6.6
CVE-2019-14238

On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug pr…

No fix yet
Fix from $1,600 2019-09-24
X11dai N Firmware CRITICAL 10.0
CVE-2019-16649

On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows c…

Mitigation only
Fix from $2,300 2019-09-21
Wiser For Knx Firmware HIGH 8.3
CVE-2019-6832

A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known…

Fix: 2.4.0+
Fix from $1,950 2019-09-17
Ghost MEDIUM 6.5
CVE-2016-10983

The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.

Fix: 0.5.6+
Fix from $1,600 2019-09-17
Pdumh15at Firmware CRITICAL 9.1
CVE-2019-16261

Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by chang…

No fix yet
Fix from $2,300 2019-09-12
Ocean Extra HIGH 7.5
CVE-2019-16250

includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading …

Fix: after 1.5.8
Fix from $1,950 2019-09-11
Dir 868l Firmware CRITICAL 9.8
CVE-2019-16190

SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication B…

Fix: after 2.03
Fix from $2,300 2019-09-09
GitLab HIGH 7.2
CVE-2019-5473

An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

No fix yet
Fix from $1,950 2019-09-09
Traffic Control CRITICAL 9.8
CVE-2019-12405

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.…

Mitigation only
Fix from $2,300 2019-09-09
Knowage CRITICAL 9.8
CVE-2019-13188

In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.

Fix: 6.4+
Fix from $2,300 2019-09-05
Knowage MEDIUM 5.3
CVE-2019-13190

In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.

Fix: after 6.1.1
Fix from $1,600 2019-09-05
W100 Firmware MEDIUM 6.5
CVE-2019-13361

Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.

No fix yet
Fix from $1,600 2019-09-05
Av7000 Firmware HIGH 8.8
CVE-2019-13526

Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker to remotely…

Fix: 4.6.0.0+
Fix from $1,950 2019-08-30
Vd 1 Firmware CRITICAL 9.8
CVE-2019-11064

A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration…

Fix: after 230
Fix from $2,300 2019-08-29
Ios Xe CRITICAL 10.0
CVE-2019-12643EPSS 5%

A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass a…

Mitigation only
Fix from $2,300 2019-08-28
Insert Or Embed Articulate Content MEDIUM 6.5
CVE-2019-15648

The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a …

Fix: 4.29991+
Fix from $1,600 2019-08-27
Search Guard HIGH 8.8
CVE-2019-13423

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserv…

Fix: 5.6.8-7 / 6.2.3-12+
Fix from $1,950 2019-08-23
Wp Support Plus Responsive Ticket System CRITICAL 9.8
CVE-2014-10389

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

Fix: 4.2+
Fix from $2,300 2019-08-22
Integrated Management Controller Supervisor CRITICAL 9.8
CVE-2019-1937EPSS 76%

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D…

Fix: after 6.7.1.0
Fix from $2,300 2019-08-21
Ucs Director CRITICAL 9.8
CVE-2019-1938

A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticate…

Mitigation only
Fix from $2,300 2019-08-21
Integrated Management Controller Supervisor CRITICAL 9.8
CVE-2019-1974

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D…

Fix: after 6.7.2.0
Fix from $2,300 2019-08-21
Next Generation Firewall CRITICAL 9.1
CVE-2019-6143

Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vul…

Fix: 6.4.7 / 6.5.4+
Fix from $2,300 2019-08-20
Debian Linux CRITICAL 9.8
CVE-2019-11187

Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t…

Fix: after 2019-04-11
Fix from $2,300 2019-08-15
Eos MEDIUM 6.5
CVE-2018-14008

Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.

Fix: after 4.21.0f
Fix from $1,600 2019-08-15
Manageengine Servicedesk Plus HIGH 7.5
CVE-2019-15046EPSS 5%

Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, a…

Fix: 10509+
Fix from $1,950 2019-08-14
Pcmanager HIGH 7.8
CVE-2019-5223

PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation of user-mo…

Mitigation only
Fix from $1,950 2019-08-13
Homematic Ccu2 Firmware CRITICAL 9.8
CVE-2019-14985EPSS 8%

eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,…

No fix yet
Fix from $2,300 2019-08-13
Mailpile HIGH 7.5
CVE-2018-20954

The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys.

Patch available
Fix from $1,950 2019-08-08