Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Streaming Engine HIGH 8.8
CVE-2020-9004

A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to …

Fix: after 4.8.0
Fix from $1,950 2020-04-14
Responsive Poll CRITICAL 9.8
CVE-2020-11673

An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clon…

Fix: after 1.3.4
Fix from $2,300 2020-04-13
Vcenter Server CRITICAL 9.8
CVE-2020-3952 KEVEPSS 90%

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does no…

Mitigation only
Fix from $2,300 2020-04-10
Webaccess\/nms CRITICAL 9.8
CVE-2020-10625

WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account.

Fix: 3.0.2+
Fix from $2,300 2020-04-09
Xiaomi Xiaoai Speaker Pro Lx06 Firmware MEDIUM 6.8
CVE-2020-10263

An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART interface and then they can (i) …

No fix yet
Fix from $1,600 2020-04-08
Android HIGH 7.5
CVE-2018-21041

An issue was discovered on Samsung mobile devices with O(8.x) software. Access to Gallery in the Secure Folder can occur without authentication. The …

Mitigation only
Fix from $1,950 2020-04-08
Cipace CRITICAL 9.8
CVE-2020-11598

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and exe…

Fix: 9.1+
Fix from $2,300 2020-04-06
Cipace HIGH 7.5
CVE-2020-11599

An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the username and password of the SM…

Fix: 9.1+
Fix from $1,950 2020-04-06
Sg 150 0 Firmware MEDIUM 6.6
CVE-2020-9473

The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, an attacker with access to the…

Fix: 1.2.4+
Fix from $1,600 2020-04-06
Ur Software HIGH 8.8
CVE-2020-10264

CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Data Exchange) interface on por…

Fix: after 3.3.3.292
Fix from $1,950 2020-04-06
Ur Software CRITICAL 9.4
CVE-2020-10265

Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a s…

Fix: after 3.3.3.292
Fix from $2,300 2020-04-06
Prtg Network Monitor MEDIUM 5.3
CVE-2020-11547EPSS 52%

PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU…

Fix: 20.1.57.1745+
Fix from $1,600 2020-04-05
Tv 288zd 2mp Firmware HIGH 7.5
CVE-2020-9349

The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service without a password.

No fix yet
Fix from $1,950 2020-04-02
Manageengine Desktop Central HIGH 7.5
CVE-2020-8509EPSS 11%

Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information discl…

Fix: 10.0.483+
Fix from $1,950 2020-03-30
Ultralog Express Firmware HIGH 8.1
CVE-2020-3920

UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access th…

Mitigation only
Fix from $1,950 2020-03-27
Pcoip Management Console HIGH 8.1
CVE-2020-10965

Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default ad…

Patch available
Fix from $1,950 2020-03-25
Android MEDIUM 5.3
CVE-2019-20624

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words via the lock screen. The Sams…

Mitigation only
Fix from $1,600 2020-03-24
Android MEDIUM 5.5
CVE-2019-20550

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a lo…

Mitigation only
Fix from $1,600 2020-03-24
Android HIGH 7.5
CVE-2020-10833

An issue was discovered on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows attackers to access the quick panel and notificati…

Mitigation only
Fix from $1,950 2020-03-24
Android MEDIUM 5.3
CVE-2019-20532

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the Developer options without authe…

Mitigation only
Fix from $1,600 2020-03-24
Fx9500 41324d41 Us Firmware HIGH 7.5
CVE-2020-10874

Motorola FX9500 devices allow remote attackers to read database files.

No fix yet
Fix from $1,950 2020-03-23
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7479

A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which cou…

Fix: 14.0.0.20009+
Fix from $1,950 2020-03-23
Pandora Fms MEDIUM 5.3
CVE-2020-8497EPSS 5%

In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, use…

Fix: after 7.42
Fix from $1,600 2020-03-23
Brain Cube Core MEDIUM 6.8
CVE-2019-16258

The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environ…

Fix: after 2.23.0
Fix from $1,600 2020-03-20
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12125

In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker g…

Fix: 4.0.0+
Fix from $2,300 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12126

In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gain…

Fix: 4.0.0+
Fix from $2,300 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12127

In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains…

Fix: 4.0.0+
Fix from $2,300 2020-03-19
Ac2400 Firmware HIGH 7.5
CVE-2019-15654

Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web mana…

No fix yet
Fix from $1,950 2020-03-19
Dsl 2875al Firmware HIGH 7.5
CVE-2019-15655

D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. Th…

Fix: after 1.00.05
Fix from $1,950 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12128

In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains …

Fix: after 4.0.0
Fix from $2,300 2020-03-19