Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Dcs 1100 Firmware HIGH 7.5
CVE-2017-8405

An issue was discovered on D-Link DCS-1130 and DCS-1100 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections rece…

No fix yet
Fix from $1,950 2019-07-02
Flexair HIGH 8.8
CVE-2019-7666EPSS 15%

Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may …

Fix: after 2.3.38
Fix from $1,950 2019-07-01
Minimed 508 Firmware HIGH 7.1
CVE-2019-10964

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor tr…

Mitigation only
Fix from $1,950 2019-06-28
Odoo MEDIUM 6.5
CVE-2018-14868

Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the pas…

Patch available
Fix from $1,600 2019-06-28
Web6000q Firmware CRITICAL 9.8
CVE-2018-15556

The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password b…

No fix yet
Fix from $2,300 2019-06-27
Pb610 Panel Builder 600 Firmware HIGH 8.8
CVE-2019-7226EPSS 5%

The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged …

Fix: after 2.8.0.367
Fix from $1,950 2019-06-27
Spring Security HIGH 7.3
CVE-2019-11272

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an appli…

Fix: 4.2.13+
Fix from $1,950 2019-06-26
Better Together Over Ethernet Connector MEDIUM 6.5
CVE-2019-10689

VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier p…

Fix: after 5.9.2
Fix from $1,600 2019-06-24
Android HIGH 8.8
CVE-2019-2018

In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password reset protection due to an unusual root cause. Re…

No fix yet
Fix from $1,950 2019-06-19
Biyan CRITICAL 9.8
CVE-2019-11232

EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element…

Fix: after 2.8
Fix from $2,300 2019-06-19
Weather Microserver Firmware HIGH 8.8
CVE-2018-18877

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.p…

Mitigation only
Fix from $1,950 2019-06-18
Axc F 2152 Firmware MEDIUM 6.8
CVE-2019-10998

An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices…

Fix: 2019.0_lts+
Fix from $1,600 2019-06-18
Veraedge Firmware CRITICAL 9.9
CVE-2017-9383

An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are available on port 3480 and c…

Fix: after 1.7.481
Fix from $2,300 2019-06-17
Veraedge Firmware HIGH 8.8
CVE-2017-9389

An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage t…

Fix: after 1.7.481
Fix from $1,950 2019-06-17
Wrt1900acs Firmware HIGH 7.5
CVE-2019-7579

An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.…

No fix yet
Fix from $1,950 2019-06-17
Openshift Container Platform MEDIUM 5.9
CVE-2019-10150

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during…

Fix: after 4.1
Fix from $1,600 2019-06-12
Keycloak MEDIUM 5.5
CVE-2019-10157

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel l…

Fix: 4.8.3 / 7.3.2+
Fix from $1,600 2019-06-12
Serv U Ftp Server HIGH 7.8
CVE-2018-19999

The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authenticati…

Mitigation only
Fix from $1,950 2019-06-07
Ios Xr Firmware MEDIUM 5.4
CVE-2019-1842

A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfu…

Mitigation only
Fix from $1,600 2019-06-05
Xenmobile Server CRITICAL 9.1
CVE-2018-18571

An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patc…

Mitigation only
Fix from $2,300 2019-06-05
Intelligent Management Center CRITICAL 9.8
CVE-2018-7121EPSS 8%

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $2,300 2019-06-05
Intelligent Management Center HIGH 7.5
CVE-2018-7123EPSS 58%

A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $1,950 2019-06-05
Ap4050dn E Firmware MEDIUM 6.8
CVE-2019-5298

There is an improper authentication vulnerability in some Huawei AP products before version V200R009C00SPC800. Due to the improper implementation of …

Mitigation only
Fix from $1,600 2019-06-04
Douphp CRITICAL 9.8
CVE-2019-12564

In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/Dyyyymm…

No fix yet
Fix from $2,300 2019-06-03
Glpi Dashboard CRITICAL 9.8
CVE-2019-12530

Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf…

Fix: after 0.9.7
Fix from $2,300 2019-06-02
Rocks CRITICAL 9.8
CVE-2019-12440

The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore R…

Fix: 2.1.149+
Fix from $2,300 2019-05-29
Dynmap MEDIUM 5.3
CVE-2019-12395

In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without logi…

Fix: 3.0+
Fix from $1,600 2019-05-28
Mdm9206 Firmware CRITICAL 9.8
CVE-2018-11271

Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon Compute, Snapdra…

Mitigation only
Fix from $2,300 2019-05-24
Mdm9206 Firmware HIGH 7.8
CVE-2018-12013

Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Consu…

Mitigation only
Fix from $1,950 2019-05-24
Buildbot CRITICAL 9.8
CVE-2019-12300

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker…

Fix: 1.8.2 / 2.3.1+
Fix from $2,300 2019-05-23