Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
X Server HIGH 7.0
CVE-2020-25697

A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take co…

Mitigation only
Fix from $1,950 2021-05-26
750 893 Firmware CRITICAL 9.8
CVE-2021-30190

CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.

Mitigation only
Fix from $2,300 2021-05-25
Planning Analytics Cloud CRITICAL 9.1
CVE-2020-4670

IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not p…

Patch available
Fix from $2,300 2021-05-17
0852 0303 Firmware CRITICAL 9.8
CVE-2021-20998

In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.

Fix: after 1.2.3.s0
Fix from $2,300 2021-05-13
Emote Remote Mouse MEDIUM 5.3
CVE-2021-27569

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a running process by sending the proc…

Fix: after 4.0.0.0
Fix from $1,600 2021-05-07
Emote Remote Mouse MEDIUM 5.3
CVE-2021-27570

An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the process name in a specially craft…

Fix: after 3.015
Fix from $1,600 2021-05-07
Emote Remote Mouse MEDIUM 5.3
CVE-2021-27571

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their …

Fix: after 4.0.0.0
Fix from $1,600 2021-05-07
Paxstore HIGH 7.1
CVE-2020-36125

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive operations c…

Fix: after 7.0.8_20200511171508
Fix from $1,950 2021-05-07
Edgeline Infrastructure Manager CRITICAL 9.8
CVE-2021-29203EPSS 68%

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Softwar…

Fix: 1.22+
Fix from $2,300 2021-05-06
Wdb 20 Firmware HIGH 7.5
CVE-2021-31793

An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams fr…

Mitigation only
Fix from $1,950 2021-05-06
Hyperflex Hx Data Platform MEDIUM 5.3
CVE-2021-1499EPSS 80%

A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload f…

Fix: 4.0 / 4.5+
Fix from $1,600 2021-05-06
Themegrill Demo Importer CRITICAL 9.1
CVE-2020-36333

themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

Fix: 1.6.2+
Fix from $2,300 2021-05-05
Ls9 Firmware HIGH 7.5
CVE-2020-35755

An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_servi…

No fix yet
Fix from $1,950 2021-05-03
Ls9 Firmware HIGH 7.5
CVE-2020-35756

An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_…

No fix yet
Fix from $1,950 2021-05-03
Ls9 Firmware CRITICAL 9.8
CVE-2020-35757

An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides …

No fix yet
Fix from $2,300 2021-05-03
Ls9 Firmware CRITICAL 9.8
CVE-2020-35758

An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not pro…

No fix yet
Fix from $2,300 2021-05-03
Hybrid Client HIGH 7.8
CVE-2021-21535

Dell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local unauthenticated attacker may…

Fix: 1.5+
Fix from $1,950 2021-04-30
Home Easy Firmware HIGH 7.5
CVE-2020-21997

Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vulnerability. An attacker could…

Fix: after 1.0.9
Fix from $1,950 2021-04-29
Dominaplus HIGH 7.5
CVE-2020-21996

AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scena…

Fix: after 1.10.77
Fix from $1,950 2021-04-28
P2r8852e2 Firmware CRITICAL 9.8
CVE-2021-30167

The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend …

Fix: 7.1.94.8908+
Fix from $2,300 2021-04-28
Nacos HIGH 7.5
CVE-2021-29442EPSS 65%

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsCont…

Fix: 1.4.1+
Fix from $1,950 2021-04-27
Ozone HIGH 7.5
CVE-2020-17517

The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allo…

Fix: 1.1.0+
Fix from $1,950 2021-04-27
Openvpn HIGH 7.5
CVE-2020-15078

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with defe…

Fix: 2.4.11 / 2.5.2+
Fix from $1,950 2021-04-26
Dap 1880ac Firmware CRITICAL 9.8
CVE-2021-20697

Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an au…

Fix: after 1.21
Fix from $2,300 2021-04-26
Home Center 2 Firmware HIGH 7.5
CVE-2021-20990

In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API…

Fix: after 4.600
Fix from $1,950 2021-04-19
Focusblog MEDIUM 5.3
CVE-2021-24219

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin be…

Fix: 2.0.0+
Fix from $1,600 2021-04-12
Vesta Control Panel HIGH 7.2
CVE-2021-30462

VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/…

Fix: after 0.9.8-24
Fix from $1,950 2021-04-08
Cohesity Dataplatform MEDIUM 5.9
CVE-2021-28124

A man-in-the-middle vulnerability in Cohesity DataPlatform support channel in version 6.3 up to 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. Mi…

Fix: after 6.5.1b
Fix from $1,600 2021-04-02
Big Iq Centralized Management HIGH 7.5
CVE-2021-22997

On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transp…

Fix: 8.0.0+
Fix from $1,950 2021-03-31
Big Iq Centralized Management HIGH 7.5
CVE-2021-22995

On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic failover does not implement any …

Fix: after 7.1.0
Fix from $1,950 2021-03-31