Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Enterprise Network Function Virtualization Infrastructure MEDIUM 6.5
CVE-2019-1946

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote …

Fix: 3.10.1+
Fix from $1,600 2019-08-08
Loom HIGH 8.8
CVE-2019-14432

Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious…

Fix: after 0.16.0
Fix from $1,950 2019-08-07
Mdc N4090 Firmware HIGH 7.2
CVE-2019-14705

An Incorrect Access Control issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5 because any valid cookie can be us…

Fix: after 6400.0.8.5
Fix from $1,950 2019-08-06
Shield Experience HIGH 7.8
CVE-2019-5679

NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authe…

Fix: 8.0+
Fix from $1,950 2019-08-06
Alcatel Linkzone Firmware CRITICAL 9.8
CVE-2019-7163

The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated u…

No fix yet
Fix from $2,300 2019-08-02
Data Protection HIGH 7.8
CVE-2018-1987

IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed i…

Fix: after 8.1.6.0
Fix from $1,950 2019-08-02
Cpanel HIGH 8.8
CVE-2016-10826

cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).

Fix: 11.50.5.2 / 11.52.4.1+
Fix from $1,950 2019-08-01
Cpanel HIGH 7.2
CVE-2016-10831

cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).

Fix: 11.54.0.20 / 55.9999.141+
Fix from $1,950 2019-08-01
Cpanel MEDIUM 6.5
CVE-2016-10832

cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).

Fix: 11.50.5.2 / 11.52.4.1+
Fix from $1,600 2019-08-01
Cpanel HIGH 7.5
CVE-2016-10833

cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).

Fix: 11.50.5.2 / 11.52.4.1+
Fix from $1,950 2019-08-01
Cpanel MEDIUM 5.5
CVE-2018-20924

cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).

Fix: 62.0.42 / 68.0.33+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 6.5
CVE-2016-10836

cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).

Fix: 11.50.5.2 / 11.52.4.1+
Fix from $1,600 2019-08-01
Openshift MEDIUM 5.4
CVE-2019-3884

A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namesp…

Mitigation only
Fix from $1,600 2019-08-01
Cpanel MEDIUM 5.5
CVE-2018-20888

cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).

Fix: 70.0.53 / 72.0.10+
Fix from $1,600 2019-08-01
Nextcloud MEDIUM 6.1
CVE-2019-5453

Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and sw…

Fix: after 3.2.4
Fix from $1,600 2019-07-30
Nextcloud MEDIUM 6.8
CVE-2019-5455

Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.

No fix yet
Fix from $1,600 2019-07-30
Rancher CRITICAL 9.8
CVE-2019-11202

An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When…

Fix: after 2.2.1
Fix from $2,300 2019-07-30
Central Print Services HIGH 8.8
CVE-2018-17213

An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication proce…

Fix: after 4.1.4
Fix from $1,950 2019-07-29
Discourse HIGH 7.3
CVE-2019-1020018

Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.

Fix: 2.3.0+
Fix from $1,950 2019-07-29
Mdm9206 Firmware HIGH 7.8
CVE-2018-13927

Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon A…

Mitigation only
Fix from $1,950 2019-07-22
MongoDB HIGH 8.1
CVE-2015-7882

Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

Fix: after 3.0.6
Fix from $1,950 2019-07-19
Vision Dynamic Signage Director CRITICAL 9.8
CVE-2019-1917EPSS 5%

A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authenti…

Fix: after 6.1
Fix from $2,300 2019-07-17
Ssd Dc S4500 Firmware MEDIUM 6.8
CVE-2018-18095

Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 may allow an unprivileged user …

Patch available
Fix from $1,600 2019-07-11
Aestiva 7100 Firmware MEDIUM 5.3
CVE-2019-10966

In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to…

Mitigation only
Fix from $1,600 2019-07-10
Nexus Repository Manager CRITICAL 9.8
CVE-2019-9629

Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).

Fix: 3.17.0+
Fix from $2,300 2019-07-08
Central Wifimanager CRITICAL 9.8
CVE-2019-13372EPSS 82%

/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PH…

Fix: after 1.03
Fix from $2,300 2019-07-06
Idoors Reader HIGH 8.8
CVE-2019-5964

iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the management console and operat…

Fix: after 2.10.17
Fix from $1,950 2019-07-05
School Erp CRITICAL 9.8
CVE-2019-13294EPSS 19%

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthentic…

No fix yet
Fix from $2,300 2019-07-04
Teamcity MEDIUM 5.3
CVE-2019-12845

The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.…

Fix: 2018.2.3+
Fix from $1,600 2019-07-03
Oncell G3150 Hspa Firmware CRITICAL 9.8
CVE-2018-11426

A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute f…

Fix: after 1.4
Fix from $2,300 2019-07-03