Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Modicon M580 Firmware CRITICAL 9.8
CVE-2018-7847

A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which…

No fix yet
Fix from $2,300 2019-05-22
Net5501 Firmware CRITICAL 9.8
CVE-2019-6814EPSS 37%

A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to con…

Fix: 2.1.9.7+
Fix from $2,300 2019-05-22
Jira HIGH 8.1
CVE-2019-8443

The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows …

Fix: 7.13.4 / 8.0.4+
Fix from $1,950 2019-05-22
Symfony HIGH 7.5
CVE-2019-10911

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker …

Fix: 2.7.51 / 2.8.50+
Fix from $1,950 2019-05-16
Banner Enterprise Identity Services HIGH 8.1
CVE-2019-8978EPSS 6%

An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 an…

No fix yet
Fix from $1,950 2019-05-14
Sharefile MEDIUM 5.9
CVE-2019-7218

Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline …

Fix: after 19.1
Fix from $1,600 2019-05-13
Elastic Services Controller CRITICAL 10.0
CVE-2019-1867EPSS 30%

A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication o…

Fix: 4.5+
Fix from $2,300 2019-05-10
Qbittorrent HIGH 7.1
CVE-2017-12778

The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorr…

No fix yet
Fix from $1,950 2019-05-09
Fl Switch 3005 Firmware CRITICAL 9.8
CVE-2018-13990

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction …

Fix: 1.35+
Fix from $2,300 2019-05-06
Rv325 Dual Wan Gigabit Vpn Router Firmware HIGH 8.8
CVE-2019-1724

A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Rout…

Mitigation only
Fix from $1,950 2019-05-03
Am 100 Firmware CRITICAL 9.8
CVE-2019-3927

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.…

No fix yet
Fix from $2,300 2019-04-30
Gitea CRITICAL 9.8
CVE-2019-11576

Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send th…

Fix: 1.8.0+
Fix from $2,300 2019-04-28
Simplybook HIGH 8.1
CVE-2019-11488

Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allows Unauthorized Attackers to R…

Fix: 2019-04-23+
Fix from $1,950 2019-04-25
405hd Firmware HIGH 8.8
CVE-2018-16219

A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same netwo…

No fix yet
Fix from $1,950 2019-04-25
Sidexis CRITICAL 9.8
CVE-2019-11081

A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative access to the application serv…

Mitigation only
Fix from $2,300 2019-04-24
Zeppelin HIGH 8.8
CVE-2018-1317

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentica…

Fix: 0.8.0+
Fix from $1,950 2019-04-23
Fedora CRITICAL 9.8
CVE-2019-11234EPSS 8%

FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.

Fix: 3.0.19+
Fix from $2,300 2019-04-22
Miui MEDIUM 6.8
CVE-2019-11015

A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscreen based authentication via t…

No fix yet
Fix from $1,600 2019-04-18
Ubuntu Linux HIGH 7.8
CVE-2018-16877

A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could us…

Fix: after 2.0.0
Fix from $1,950 2019-04-18
Wireless Lan Controller Software HIGH 7.5
CVE-2018-0382

A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software cou…

Mitigation only
Fix from $1,950 2019-04-17
Contao Cms CRITICAL 9.8
CVE-2019-10643

Contao 4.7 allows Use of a Key Past its Expiration Date.

No fix yet
Fix from $2,300 2019-04-17
Duo Network Gateway HIGH 7.5
CVE-2018-7340

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attack…

Fix: after 1.2.9
Fix from $1,950 2019-04-17
Fedora HIGH 8.1
CVE-2019-9498

The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not va…

Fix: after 11.1
Fix from $1,950 2019-04-17
Fedora HIGH 8.1
CVE-2019-9499

The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do n…

Fix: after 11.1
Fix from $1,950 2019-04-17
Capi Release HIGH 7.5
CVE-2019-3798

Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote aut…

Fix: 1.79.0+
Fix from $1,950 2019-04-17
Fedora HIGH 7.5
CVE-2019-9496

An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE conf…

Fix: after 2.7
Fix from $1,950 2019-04-17
Fedora HIGH 8.1
CVE-2019-9497

The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. Thi…

Fix: after 2.7
Fix from $1,950 2019-04-17
Pythonsaml CRITICAL 9.8
CVE-2017-11427

OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attack…

Fix: after 2.3.0
Fix from $2,300 2019-04-17
Ruby Saml CRITICAL 9.8
CVE-2017-11428

OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacke…

Fix: after 1.6.0
Fix from $2,300 2019-04-17
Saml2 Js CRITICAL 9.8
CVE-2017-11429

Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may…

Fix: after 2.0
Fix from $2,300 2019-04-17