Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Opmon CRITICAL 9.8
CVE-2020-8636

An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

No fix yet
Fix from $2,300 2020-02-06
Manageengine Applications Manager MEDIUM 5.3
CVE-2019-19800

Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

Mitigation only
Fix from $1,600 2020-02-06
Security Directory Server MEDIUM 5.3
CVE-2019-4551

IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access…

Fix: 6.4.0.20+
Fix from $1,600 2020-02-04
Tp Sg105e Firmware HIGH 7.5
CVE-2019-16893EPSS 38%

The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi requ…

Patch available
Fix from $1,950 2020-02-03
Tl Wr849n Firmware MEDIUM 6.1
CVE-2019-19143

TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.

No fix yet
Fix from $1,600 2020-01-27
A3002ru Firmware HIGH 7.5
CVE-2019-19822EPSS 9%

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configurati…

Fix: after 2019-12-12
Fix from $1,950 2020-01-27
Webex Meetings Online HIGH 7.5
CVE-2020-3142

A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a p…

Fix: 39.11.5 / 40.1.3+
Fix from $1,950 2020-01-26
Ucs Director MEDIUM 5.3
CVE-2019-16003

A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to download system log fi…

Fix: 6.7.3.1+
Fix from $1,600 2020-01-26
Saleor MEDIUM 5.3
CVE-2020-7964

An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to atta…

Fix: 2.9.1+
Fix from $1,600 2020-01-24
Apexpro Telemetry Server Firmware HIGH 8.6
CVE-2020-6964

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, …

Fix: after 4.2
Fix from $1,950 2020-01-24
Websitebaker HIGH 7.5
CVE-2011-4322

websitebaker prior to and including 2.8.1 has an authentication error in backup module.

Fix: after 2.8.1
Fix from $1,950 2020-01-21
Wrn 240 Firmware HIGH 7.5
CVE-2019-19142EPSS 8%

Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.

No fix yet
Fix from $1,950 2020-01-17
Wp Database Reset CRITICAL 9.1
CVE-2020-7048EPSS 23%

The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the …

Fix: after 3.1
Fix from $2,300 2020-01-16
Scalance X 200rna Firmware HIGH 8.6
CVE-2019-13933

A vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRP), SCALAN…

Fix: 4.1.3+
Fix from $1,950 2020-01-16
GitLab MEDIUM 5.3
CVE-2019-20143

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.

No fix yet
Fix from $1,600 2020-01-13
Bss Continuty Cms CRITICAL 9.8
CVE-2014-3449

BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability

No fix yet
Fix from $2,300 2020-01-09
Platinum 4410 Firmware CRITICAL 9.8
CVE-2020-6170EPSS 7%

An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the …

No fix yet
Fix from $2,300 2020-01-08
Dcs 935l Firmware CRITICAL 9.8
CVE-2019-17146EPSS 10%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not re…

Fix: after 1.12.101
Fix from $2,300 2020-01-07
D5 Firmware MEDIUM 5.3
CVE-2019-16271

DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emulated/0/Notes/PDF on TCP port…

Fix: 1.3.2+
Fix from $1,600 2020-01-06
GitLab MEDIUM 5.3
CVE-2018-20507

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Inc…

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
Pfc 200 Firmware CRITICAL 9.1
CVE-2019-5078

An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13)…

Mitigation only
Fix from $2,300 2019-12-18
Pfc 200 Firmware CRITICAL 9.1
CVE-2019-5080

An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13…

Mitigation only
Fix from $2,300 2019-12-18
Rsa Identity Governance And Lifecycle CRITICAL 9.8
CVE-2019-18572

The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnera…

Mitigation only
Fix from $2,300 2019-12-18
Pfc 200 Firmware CRITICAL 9.1
CVE-2019-5077

An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(1…

Mitigation only
Fix from $2,300 2019-12-18
Mac Os X MEDIUM 5.5
CVE-2019-8522

A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4. An encrypted volume may be unmounted and rem…

Fix: 10.14.4+
Fix from $1,600 2019-12-18
Shadowsocks Libev HIGH 7.4
CVE-2019-5152

An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a …

No fix yet
Fix from $1,950 2019-12-18
Petalk Ai Firmware HIGH 7.5
CVE-2019-16731

The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter …

No fix yet
Fix from $1,950 2019-12-13
Sinvr 3 Central Control Server CRITICAL 9.8
CVE-2019-18339

A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR …

Mitigation only
Fix from $2,300 2019-12-12
Sppa T3000 Ms3000 Migration Server HIGH 7.5
CVE-2019-18311

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could …

Mitigation only
Fix from $1,950 2019-12-12
Sppa T3000 Application Server CRITICAL 9.8
CVE-2019-18284

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without au…

No fix yet
Fix from $2,300 2019-12-12