Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
C More Hmi Ea9 Firmware CRITICAL 9.8
CVE-2020-10921

This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. A…

Mitigation only
Fix from $2,300 2020-07-23
Dir 816l Firmware HIGH 7.5
CVE-2020-15894

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can…

Patch available
Fix from $1,950 2020-07-22
Factorytalk View HIGH 8.1
CVE-2020-12028EPSS 53%

In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the re…

No fix yet
Fix from $1,950 2020-07-20
Cim 500 Firmware HIGH 7.5
CVE-2020-10605

Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.

Fix: 06.16.00+
Fix from $1,950 2020-07-17
Microweber HIGH 7.5
CVE-2020-13405EPSS 14%

userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /mo…

Fix: 1.1.20+
Fix from $1,950 2020-07-16
Iview CRITICAL 9.8
CVE-2020-14501

Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulner…

Fix: after 5.6
Fix from $2,300 2020-07-15
Emc Omimssc For Sccm HIGH 7.5
CVE-2020-5373

Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an improper authentication v…

Fix: 7.2.1+
Fix from $1,950 2020-07-14
Sicam Mmu Firmware HIGH 7.5
CVE-2020-10044

A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with a…

Fix: 2.05 / 2.18+
Fix from $1,950 2020-07-14
Sicam Mmu Firmware CRITICAL 9.8
CVE-2020-10038

A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with a…

Fix: 2.05 / 2.18+
Fix from $2,300 2020-07-14
Netweaver Application Server Java CRITICAL 10.0
CVE-2020-6287 KEVEPSS 95%

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker…

Mitigation only
Fix from $2,300 2020-07-14
Micro Air Vehicle Link CRITICAL 9.8
CVE-2020-10282

The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety o…

Mitigation only
Fix from $2,300 2020-07-03
Nginx Controller HIGH 7.5
CVE-2020-5910

In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do no…

Fix: after 3.5.0
Fix from $1,950 2020-07-02
Unified Customer Voice Portal HIGH 7.5
CVE-2020-3402

A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, rem…

Fix: after 12.5
Fix from $1,950 2020-07-02
Opensis CRITICAL 9.1
CVE-2020-13382EPSS 53%

openSIS through 7.4 has Incorrect Access Control.

Fix: after 7.4
Fix from $2,300 2020-07-01
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15335

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.

Mitigation only
Fix from $1,950 2020-06-26
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15336

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.

Mitigation only
Fix from $1,950 2020-06-26
Xiaomi R3600 Firmware HIGH 7.5
CVE-2020-11961

Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authen…

Fix: 1.0.20+
Fix from $1,950 2020-06-24
Mir100 Firmware CRITICAL 9.8
CVE-2020-10272

MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authen…

Fix: after 2.8.1.1
Fix from $2,300 2020-06-24
Spark CRITICAL 9.8
CVE-2020-9480EPSS 29%

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…

Fix: after 2.4.5
Fix from $2,300 2020-06-23
Tomee CRITICAL 9.8
CVE-2020-11969

If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP…

Fix: after 8.0.1
Fix from $2,300 2020-06-15
Dsl 2750u Firmware HIGH 7.8
CVE-2020-13150

D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filterin…

Mitigation only
Fix from $1,950 2020-06-15
P30 Firmware MEDIUM 6.8
CVE-2020-1813

HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. Due to improper authenticat…

Fix: 10.1.0.135+
Fix from $1,600 2020-06-15
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-4471

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a…

Fix: after 10.1.5
Fix from $1,600 2020-06-15
Manageengine Servicedesk Plus HIGH 7.5
CVE-2020-14048

Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agen…

Mitigation only
Fix from $1,950 2020-06-12
Logo\! 8 Bm Firmware CRITICAL 9.1
CVE-2020-7589

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker reading and mod…

Mitigation only
Fix from $2,300 2020-06-10
Netweaver Application Server Java CRITICAL 9.8
CVE-2020-6263

Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40…

Mitigation only
Fix from $2,300 2020-06-10
Ignition Gateway HIGH 7.5
CVE-2020-12004EPSS 14%

The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gat…

Fix: 7.9.14 / 8.0.10+
Fix from $1,950 2020-06-09
Wf 1000x Firmware HIGH 8.8
CVE-2020-5589

SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with…

Mitigation only
Fix from $1,950 2020-06-09
Application Policy Infrastructure Controller MEDIUM 5.3
CVE-2020-3333

A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on …

Fix: 1.1.2.20+
Fix from $1,600 2020-06-03
Application Policy Infrastructure Controller MEDIUM 5.5
CVE-2020-3335

A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive informa…

Fix: 1.1.2.20+
Fix from $1,600 2020-06-03