Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Solismed CRITICAL 9.8
CVE-2019-15932

Intesync Solismed 3.3sp has Incorrect Access Control.

No fix yet
Fix from $2,300 2019-12-12
Smartcloud Analytics Log Analysis CRITICAL 9.1
CVE-2019-4244

IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper i…

Fix: after 1.3.5
Fix from $2,300 2019-12-10
Openstack HIGH 7.5
CVE-2013-1793

openstack-utils openstack-db has insecure password creation

Mitigation only
Fix from $1,950 2019-12-10
Shadowsocks Libev HIGH 7.5
CVE-2019-5163

An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a …

No fix yet
Fix from $1,950 2019-12-03
Shadowsocks Libev HIGH 7.8
CVE-2019-5164

An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-…

No fix yet
Fix from $1,950 2019-12-03
Bcst 60 Firmware CRITICAL 9.8
CVE-2019-12503

Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus…

No fix yet
Fix from $2,300 2019-12-02
Anviz Firmware HIGH 7.5
CVE-2019-12389

Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via …

Mitigation only
Fix from $1,950 2019-12-02
Anviz Firmware MEDIUM 5.3
CVE-2019-12390

Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credential…

Mitigation only
Fix from $1,600 2019-12-02
Anviz Firmware CRITICAL 9.8
CVE-2019-12392

Anviz access control devices allow remote attackers to issue commands without a password.

No fix yet
Fix from $2,300 2019-12-02
Debian Linux HIGH 7.8
CVE-2011-2187

xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows loc…

Fix: 5.14+
Fix from $1,950 2019-11-27
Cingular Flip 2 Firmware MEDIUM 6.1
CVE-2019-16243

On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running wi…

No fix yet
Fix from $1,600 2019-11-26
Galaxy HIGH 7.8
CVE-2019-15511

An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an…

Fix: 1.2.60+
Fix from $1,950 2019-11-21
Taolight Smart Wi Fi Wiz Connected Led Bulb 9290022656 Firmware HIGH 7.5
CVE-2019-18980

On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation.…

No fix yet
Fix from $1,950 2019-11-14
Scriptparser CRITICAL 9.8
CVE-2019-18937EPSS 34%

eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attack…

No fix yet
Fix from $2,300 2019-11-14
Hm Email CRITICAL 9.8
CVE-2019-18938EPSS 34%

eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers…

No fix yet
Fix from $2,300 2019-11-14
Hm Print CRITICAL 9.8
CVE-2019-18939EPSS 41%

eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers …

No fix yet
Fix from $2,300 2019-11-14
Igniteup HIGH 7.5
CVE-2019-17234

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.

Fix: after 3.4
Fix from $1,950 2019-11-12
Igniteup MEDIUM 5.3
CVE-2019-17235

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.

Fix: after 3.4
Fix from $1,600 2019-11-12
Iris Webforms CRITICAL 9.8
CVE-2019-18925

Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.

Mitigation only
Fix from $2,300 2019-11-12
Computing For Good\'s Basic Laboratory Information System CRITICAL 9.8
CVE-2019-5617

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Impro…

Fix: after 3.4
Fix from $2,300 2019-11-06
Computing For Good\'s Basic Laboratory Information System MEDIUM 5.3
CVE-2019-5643

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Impro…

Fix: after 3.5
Fix from $1,600 2019-11-06
Computing For Good\'s Basic Laboratory Information System CRITICAL 9.8
CVE-2019-5644

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Impro…

Fix: after 3.5
Fix from $2,300 2019-11-06
Xlockmore CRITICAL 9.8
CVE-2006-0062

xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.

Patch available
Fix from $2,300 2019-11-06
Xlockmore CRITICAL 9.8
CVE-2006-0061

xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X sessio…

Patch available
Fix from $2,300 2019-11-06
H4d8pr1 Firmware HIGH 7.5
CVE-2019-18230

Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access…

Fix: 1.000.hw01.1.20190822 / 1.000.hw01.3.20190820+
Fix from $1,950 2019-10-31
In App \& Desktop Notifications HIGH 7.5
CVE-2019-16906

An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?usern…

No fix yet
Fix from $1,950 2019-10-31
In App \& Desktop Notifications MEDIUM 5.3
CVE-2019-16907

An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira u…

No fix yet
Fix from $1,600 2019-10-31
Wise Paas\/rmm CRITICAL 9.8
CVE-2019-13547

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the functi…

Fix: after 3.3.29
Fix from $2,300 2019-10-31
Moveit Transfer CRITICAL 9.8
CVE-2019-18465

In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via t…

Fix: 11.1.3+
Fix from $2,300 2019-10-31
Routeros HIGH 7.5
CVE-2019-3978EPSS 10%

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries…

Fix: after 6.45.6
Fix from $1,950 2019-10-29