Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Omniauth Saml CRITICAL 9.8
CVE-2017-11430

OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an at…

Fix: after 1.9.0
Fix from $2,300 2019-04-17
Netweaver Process Integration MEDIUM 5.3
CVE-2019-0282

Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed w…

Mitigation only
Fix from $1,600 2019-04-10
Activematrix Businessworks HIGH 8.1
CVE-2019-8990

The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthentic…

Fix: after 6.4.2
Fix from $1,950 2019-04-09
Thinkadmin CRITICAL 9.8
CVE-2019-11018

application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a passwo…

No fix yet
Fix from $2,300 2019-04-08
Srn 4000 Firmware CRITICAL 9.8
CVE-2017-7912

Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attac…

Fix: 2.16_170401+
Fix from $2,300 2019-04-08
Password Manager HIGH 8.8
CVE-2019-10884

Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerabilit…

Mitigation only
Fix from $1,950 2019-04-05
Detcon Sitewatch Gateway CRITICAL 9.8
CVE-2017-6047

Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessible without authentication.

Mitigation only
Fix from $2,300 2019-04-02
Detcon Sitewatch Gateway HIGH 7.5
CVE-2017-6049

Detcon Sitewatch Gateway, all versions without cellular, an attacker can edit settings on the device using a specially crafted URL.

Mitigation only
Fix from $1,950 2019-04-02
Emc Networker CRITICAL 9.8
CVE-2017-8023EPSS 6%

EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsre…

Fix: 8.2.4.11 / 9.1.1.5+
Fix from $2,300 2019-04-01
Geocall HIGH 8.8
CVE-2019-5890

An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtai…

Mitigation only
Fix from $1,950 2019-04-01
Gxv3611ir Hd Firmware CRITICAL 9.8
CVE-2019-10661

On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

Fix: 1.0.3.23+
Fix from $2,300 2019-03-30
Crowd HIGH 7.5
CVE-2017-18106

The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or…

Fix: 2.9.1+
Fix from $1,950 2019-03-29
Blur HIGH 7.5
CVE-2019-6481

Abine Blur 7.8.2431 allows remote attackers to conduct "Second-Factor Auth Bypass" attacks by using the "Perform a right-click operation to access a …

No fix yet
Fix from $1,950 2019-03-29
Ios Xe MEDIUM 5.3
CVE-2019-1759

A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unaut…

Patch available
Fix from $1,600 2019-03-28
Mosquitto HIGH 8.1
CVE-2018-12551

When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password f…

Fix: after 1.5.5
Fix from $1,950 2019-03-27
Mod Auth Mellon HIGH 8.1
CVE-2019-3878

A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let…

Fix: 0.14.2+
Fix from $1,950 2019-03-26
Sigma Spectrum Infusion System Firmware CRITICAL 9.8
CVE-2014-5432

Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/…

Mitigation only
Fix from $2,300 2019-03-26
Rt3050 Firmware CRITICAL 9.8
CVE-2019-6441EPSS 54%

An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The pass…

No fix yet
Fix from $2,300 2019-03-21
Multisensor Lan Firmware CRITICAL 9.8
CVE-2018-19783

Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel.

Fix: after 5.63.00
Fix from $2,300 2019-03-21
Dropbear Ssh HIGH 7.5
CVE-2017-2659

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, th…

Fix: 2013.59+
Fix from $1,950 2019-03-21
Satcom Sailor 250 Firmware CRITICAL 9.8
CVE-2018-19392

Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any …

Fix: 1.25+
Fix from $2,300 2019-03-15
Access Manager HIGH 7.8
CVE-2018-18255

An issue was discovered in CapMon Access Manager 5.4.1.1005. The client applications of AccessManagerCoreService.exe communicate with this server thr…

Fix: after 5.4.1.1005
Fix from $1,950 2019-03-15
Access Manager HIGH 7.8
CVE-2018-18256

An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted app…

No fix yet
Fix from $1,950 2019-03-15
Converged Security Management Engine Firmware MEDIUM 6.8
CVE-2018-12192

Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versio…

Fix: 11.8.60 / 11.11.60+
Fix from $1,600 2019-03-14
Uaa Release MEDIUM 6.5
CVE-2019-3775

Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different …

Fix: 70.0+
Fix from $1,600 2019-03-07
Privileged Access Manager CRITICAL 9.1
CVE-2019-7392

An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensiti…

Fix: after 3.2.1
Fix from $2,300 2019-02-26
Dir 878 Firmware CRITICAL 9.8
CVE-2019-9124

An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.

No fix yet
Fix from $2,300 2019-02-25
Hyperflex Hx Data Platform HIGH 7.8
CVE-2019-1664

A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in …

Mitigation only
Fix from $1,950 2019-02-21
Hyperflex Hx Data Platform MEDIUM 5.3
CVE-2019-1666

A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphit…

Mitigation only
Fix from $1,600 2019-02-21
Prime Collaboration Assurance CRITICAL 9.1
CVE-2019-1662

A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated…

Fix: 12.1+
Fix from $2,300 2019-02-21