Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2019-12664 A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs… Ios Xe Mitigation only Fix from $1,9502019-09-25 MEDIUM 6.6 CVE-2019-14239 On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can… Kinetis Kv1x Firmware No fix yet Fix from $1,6002019-09-24 MEDIUM 6.6 CVE-2019-14238 On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug pr… Stm32l0 Firmware No fix yet Fix from $1,6002019-09-24 CRITICAL 10.0 CVE-2019-16649 On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows c… X11dai N Firmware Mitigation only Fix from $2,3002019-09-21 HIGH 8.3 CVE-2019-6832 A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known… Wiser For Knx Firmware 2.4.0+ Fix from $1,9502019-09-17 MEDIUM 6.5 CVE-2016-10983 The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data. Ghost 0.5.6+ Fix from $1,6002019-09-17 CRITICAL 9.1 CVE-2019-16261 Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by chang… Pdumh15at Firmware No fix yet Fix from $2,3002019-09-12 HIGH 7.5 CVE-2019-16250 includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading … Ocean Extra after 1.5.8 Fix from $1,9502019-09-11 CRITICAL 9.8 CVE-2019-16190 SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication B… Dir 868l Firmware after 2.03 Fix from $2,3002019-09-09 HIGH 7.2 CVE-2019-5473 An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4. GitLab No fix yet Fix from $1,9502019-09-09 CRITICAL 9.8 CVE-2019-12405 Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.… Traffic Control Mitigation only Fix from $2,3002019-09-09 CRITICAL 9.8 CVE-2019-13188 In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application. Knowage 6.4+ Fix from $2,3002019-09-05 MEDIUM 5.3 CVE-2019-13190 In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page. Knowage after 6.1.1 Fix from $1,6002019-09-05 MEDIUM 6.5 CVE-2019-13361 Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network. W100 Firmware No fix yet Fix from $1,6002019-09-05 HIGH 8.8 CVE-2019-13526 Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker to remotely… Av7000 Firmware 4.6.0.0+ Fix from $1,9502019-08-30 CRITICAL 9.8 CVE-2019-11064 A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration… Vd 1 Firmware after 230 Fix from $2,3002019-08-29 CRITICAL 10.0 CVE-2019-12643EPSS 5% A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass a… Ios Xe Mitigation only Fix from $2,3002019-08-28 MEDIUM 6.5 CVE-2019-15648 The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a … Insert Or Embed Articulate Content 4.29991+ Fix from $1,6002019-08-27 HIGH 8.8 CVE-2019-13423 Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserv… Search Guard 5.6.8-7 / 6.2.3-12+ Fix from $1,9502019-08-23 CRITICAL 9.8 CVE-2014-10389 The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. Wp Support Plus Responsive Ticket System 4.2+ Fix from $2,3002019-08-22 CRITICAL 9.8 CVE-2019-1937EPSS 76% A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D… Integrated Management Controller Supervisor after 6.7.1.0 Fix from $2,3002019-08-21 CRITICAL 9.8 CVE-2019-1938 A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticate… Ucs Director Mitigation only Fix from $2,3002019-08-21 CRITICAL 9.8 CVE-2019-1974 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D… Integrated Management Controller Supervisor after 6.7.2.0 Fix from $2,3002019-08-21 CRITICAL 9.1 CVE-2019-6143 Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vul… Next Generation Firewall 6.4.7 / 6.5.4+ Fix from $2,3002019-08-20 CRITICAL 9.8 CVE-2019-11187 Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t… Debian Linux after 2019-04-11 Fix from $2,3002019-08-15 MEDIUM 6.5 CVE-2018-14008 Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled. Eos after 4.21.0f Fix from $1,6002019-08-15 HIGH 7.5 CVE-2019-15046EPSS 5% Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, a… Manageengine Servicedesk Plus 10509+ Fix from $1,9502019-08-14 HIGH 7.8 CVE-2019-5223 PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation of user-mo… Pcmanager Mitigation only Fix from $1,9502019-08-13 CRITICAL 9.8 CVE-2019-14985EPSS 8% eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,… Homematic Ccu2 Firmware No fix yet Fix from $2,3002019-08-13 HIGH 7.5 CVE-2018-20954 The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys. Mailpile Patch available Fix from $1,9502019-08-08