Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Smartrtu Firmware HIGH 7.5
CVE-2019-14927EPSS 42%

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote…

Fix: after 3.0
Fix from $1,950 2019-10-28
Ip Ak2 Firmware MEDIUM 5.3
CVE-2019-13525

In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain we…

Fix: 1.04.07+
Fix from $1,600 2019-10-25
Pcoweb Firmware HIGH 7.5
CVE-2019-13549

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems doe…

Mitigation only
Fix from $1,950 2019-10-25
Gpon Firmware CRITICAL 9.8
CVE-2019-15064

HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication.

Mitigation only
Fix from $2,300 2019-10-17
Dir 412 Firmware CRITICAL 9.1
CVE-2019-17512

There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file vi…

No fix yet
Fix from $2,300 2019-10-16
Identity Services Engine Software MEDIUM 5.3
CVE-2019-15282

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacke…

Fix: 2.4+
Fix from $1,600 2019-10-16
Dir 412 Firmware HIGH 7.5
CVE-2019-17511

There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via …

No fix yet
Fix from $1,950 2019-10-14
Wemo Switch 28b Firmware HIGH 7.5
CVE-2019-17532

An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persi…

No fix yet
Fix from $1,950 2019-10-12
Dir 868l B1 Firmware CRITICAL 9.8
CVE-2019-17506EPSS 56%

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the r…

No fix yet
Fix from $2,300 2019-10-11
Dap 1320 A2 Firmware HIGH 7.5
CVE-2019-17505

D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can re…

No fix yet
Fix from $1,950 2019-10-11
Explorer 710 Firmware MEDIUM 5.5
CVE-2019-9529

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, …

Mitigation only
Fix from $1,600 2019-10-10
Inspector HIGH 7.5
CVE-2019-15018

A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector …

Fix: after 1.280
Fix from $1,950 2019-10-09
Dir 615 Firmware HIGH 8.2
CVE-2019-17353

An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which c…

Mitigation only
Fix from $1,950 2019-10-09
Nbg 418n V2 Firmware CRITICAL 9.4
CVE-2019-17354

wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure…

Mitigation only
Fix from $2,300 2019-10-09
Process Integration MEDIUM 5.3
CVE-2019-0379

SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security pro…

Mitigation only
Fix from $1,600 2019-10-08
Hg2201t Firmware HIGH 8.8
CVE-2019-17186EPSS 6%

/var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution.

No fix yet
Fix from $1,950 2019-10-08
Ultimate Faq HIGH 7.5
CVE-2019-17232

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

Fix: after 1.8.24
Fix from $1,950 2019-10-07
Combi Stream Mslq Firmware HIGH 8.8
CVE-2019-17219

An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authen…

Mitigation only
Fix from $1,950 2019-10-06
Online Store System MEDIUM 5.3
CVE-2019-8292

Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product del…

No fix yet
Fix from $1,600 2019-10-01
Pc530 Firmware CRITICAL 9.8
CVE-2019-15940

Victure PC530 devices allow unauthenticated TELNET access as root.

No fix yet
Fix from $2,300 2019-10-01
Hbd3pr2 Firmware MEDIUM 5.3
CVE-2019-13523

In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain we…

Mitigation only
Fix from $1,600 2019-09-26
Smart Battery A4 Firmware CRITICAL 9.8
CVE-2019-15068

A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/…

Mitigation only
Fix from $2,300 2019-09-25
Big Iq Centralized Management MEDIUM 6.5
CVE-2019-6652

In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).

Fix: after 6.1.0
Fix from $1,600 2019-09-25
Ontap Select Deploy Administration Utility CRITICAL 9.8
CVE-2019-5504

ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote atta…

Patch available
Fix from $2,300 2019-09-24
Publisure MEDIUM 6.5
CVE-2019-14253

An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and perform a query on PHP forms …

No fix yet
Fix from $1,600 2019-09-18
Homematic Ccu2 Firmware CRITICAL 9.8
CVE-2019-16199EPSS 9%

eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface …

Fix: 2.47.18 / 3.47.18+
Fix from $2,300 2019-09-17
Jira MEDIUM 5.3
CVE-2019-8449EPSS 85%

The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosu…

Fix: 8.4.0+
Fix from $1,600 2019-09-11
Couchbase Server MEDIUM 5.3
CVE-2019-11466

In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on…

Mitigation only
Fix from $1,600 2019-09-10
Couchbase Server CRITICAL 9.1
CVE-2019-11496

In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authenticati…

Fix: after 5.0.0
Fix from $2,300 2019-09-10
Supervisor HIGH 8.2
CVE-2019-12105

In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected compon…

Fix: after 4.0.2
Fix from $1,950 2019-09-10