Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12129

In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains…

Fix: after 4.0.0
Fix from $2,300 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12130

In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains…

Fix: after 4.0.0
Fix from $2,300 2020-03-19
Frappe HIGH 7.5
CVE-2019-20529

In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (…

Patch available
Fix from $1,950 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12114

An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already …

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12115

An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has acces…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12116

An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated attacker (who already has acces…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12117

An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who alread…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12118

An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has a…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12119

An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has a…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12120

An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has acc…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Tiff Server HIGH 7.5
CVE-2020-9325

Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.

No fix yet
Fix from $1,950 2020-03-18
Apex One CRITICAL 9.8
CVE-2020-8598EPSS 13%

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could…

Patch available
Fix from $2,300 2020-03-18
Ads 2400n Firmware HIGH 7.5
CVE-2019-13194

Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive infor…

No fix yet
Fix from $1,950 2020-03-13
Ecosys M5526cdw Firmware HIGH 7.5
CVE-2019-13205

All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. Thi…

Mitigation only
Fix from $1,950 2020-03-13
Manageengine Applications Manager MEDIUM 5.3
CVE-2019-19799EPSS 6%

Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedSer…

Fix: 14.5+
Fix from $1,600 2020-03-13
GitLab MEDIUM 5.3
CVE-2020-10079

GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authe…

Fix: after 12.8.1
Fix from $1,600 2020-03-13
Solution Manager CRITICAL 9.8
CVE-2020-6207 KEVEPSS 98%

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a servic…

Mitigation only
Fix from $2,300 2020-03-10
Solution Manager CRITICAL 9.8
CVE-2020-6198

SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to contro…

Mitigation only
Fix from $2,300 2020-03-10
Emc Isilon Onefs CRITICAL 9.8
CVE-2020-5328

Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ…

Fix: 8.2.0+
Fix from $2,300 2020-03-06
Dsl 2640b Firmware HIGH 7.5
CVE-2020-9544

An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-upd…

No fix yet
Fix from $1,950 2020-03-05
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19224

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to download the confi…

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19225

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers…

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19226

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to enable or disable …

No fix yet
Fix from $1,950 2020-03-04
Enterprise Virtualization HIGH 7.5
CVE-2015-5201

VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as pack…

Fix: 3.5.6 / 6-6.7-20151117.0+
Fix from $1,950 2020-02-25
Workcentre 3655 Firmware HIGH 8.8
CVE-2020-9330

Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDA…

Fix: 073.060.000.02300 / 073.091.000.02300+
Fix from $1,950 2020-02-21
Chengming 3980 Firmware MEDIUM 5.3
CVE-2020-5326

Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Te…

Fix: 1.4.3 / 1.8.0+
Fix from $1,600 2020-02-21
Host Agent HIGH 7.5
CVE-2020-6186

SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host…

Mitigation only
Fix from $1,950 2020-02-12
Video Streaming Gateway CRITICAL 9.1
CVE-2020-6769

Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set…

Fix: after 6.45.08
Fix from $2,300 2020-02-07
Opmon HIGH 7.5
CVE-2020-7953

An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of …

Mitigation only
Fix from $1,950 2020-02-06
Opmon HIGH 7.8
CVE-2020-7954

An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the …

Mitigation only
Fix from $1,950 2020-02-06