Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.5 CVE-2019-1946 A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote … Enterprise Network Function Virtualization Infrastructure 3.10.1+ Fix from $1,6002019-08-08 HIGH 8.8 CVE-2019-14432 Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious… Loom after 0.16.0 Fix from $1,9502019-08-07 HIGH 7.2 CVE-2019-14705 An Incorrect Access Control issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5 because any valid cookie can be us… Mdc N4090 Firmware after 6400.0.8.5 Fix from $1,9502019-08-06 HIGH 7.8 CVE-2019-5679 NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authe… Shield Experience 8.0+ Fix from $1,9502019-08-06 CRITICAL 9.8 CVE-2019-7163 The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated u… Alcatel Linkzone Firmware No fix yet Fix from $2,3002019-08-02 HIGH 7.8 CVE-2018-1987 IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed i… Data Protection after 8.1.6.0 Fix from $1,9502019-08-02 HIGH 8.8 CVE-2016-10826 cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93). Cpanel 11.50.5.2 / 11.52.4.1+ Fix from $1,9502019-08-01 HIGH 7.2 CVE-2016-10831 cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101). Cpanel 11.54.0.20 / 55.9999.141+ Fix from $1,9502019-08-01 MEDIUM 6.5 CVE-2016-10832 cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102). Cpanel 11.50.5.2 / 11.52.4.1+ Fix from $1,6002019-08-01 HIGH 7.5 CVE-2016-10833 cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104). Cpanel 11.50.5.2 / 11.52.4.1+ Fix from $1,9502019-08-01 MEDIUM 5.5 CVE-2018-20924 cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378). Cpanel 62.0.42 / 68.0.33+ Fix from $1,6002019-08-01 MEDIUM 6.5 CVE-2016-10836 cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). Cpanel 11.50.5.2 / 11.52.4.1+ Fix from $1,6002019-08-01 MEDIUM 5.4 CVE-2019-3884 A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namesp… Openshift Mitigation only Fix from $1,6002019-08-01 MEDIUM 5.5 CVE-2018-20888 cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424). Cpanel 70.0.53 / 72.0.10+ Fix from $1,6002019-08-01 MEDIUM 6.1 CVE-2019-5453 Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and sw… Nextcloud after 3.2.4 Fix from $1,6002019-07-30 MEDIUM 6.8 CVE-2019-5455 Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process. Nextcloud No fix yet Fix from $1,6002019-07-30 CRITICAL 9.8 CVE-2019-11202 An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When… Rancher after 2.2.1 Fix from $2,3002019-07-30 HIGH 8.8 CVE-2018-17213 An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication proce… Central Print Services after 4.1.4 Fix from $1,9502019-07-29 HIGH 7.3 CVE-2019-1020018 Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link. Discourse 2.3.0+ Fix from $1,9502019-07-29 HIGH 7.8 CVE-2018-13927 Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon A… Mdm9206 Firmware Mitigation only Fix from $1,9502019-07-22 HIGH 8.1 CVE-2015-7882 Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access. MongoDB after 3.0.6 Fix from $1,9502019-07-19 CRITICAL 9.8 CVE-2019-1917EPSS 5% A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authenti… Vision Dynamic Signage Director after 6.1 Fix from $2,3002019-07-17 MEDIUM 6.8 CVE-2018-18095 Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 may allow an unprivileged user … Ssd Dc S4500 Firmware Patch available Fix from $1,6002019-07-11 MEDIUM 5.3 CVE-2019-10966 In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to… Aestiva 7100 Firmware Mitigation only Fix from $1,6002019-07-10 CRITICAL 9.8 CVE-2019-9629 Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials). Nexus Repository Manager 3.17.0+ Fix from $2,3002019-07-08 CRITICAL 9.8 CVE-2019-13372EPSS 82% /web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PH… Central Wifimanager after 1.03 Fix from $2,3002019-07-06 HIGH 8.8 CVE-2019-5964 iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the management console and operat… Idoors Reader after 2.10.17 Fix from $1,9502019-07-05 CRITICAL 9.8 CVE-2019-13294EPSS 19% AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthentic… School Erp No fix yet Fix from $2,3002019-07-04 MEDIUM 5.3 CVE-2019-12845 The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.… Teamcity 2018.2.3+ Fix from $1,6002019-07-03 CRITICAL 9.8 CVE-2018-11426 A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute f… Oncell G3150 Hspa Firmware after 1.4 Fix from $2,3002019-07-03