Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Lifterlms CRITICAL 9.8
CVE-2019-15896EPSS 7%

An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is…

Fix: after 3.34.5
Fix from $2,300 2019-09-10
Librenms CRITICAL 9.1
CVE-2019-10668

An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authenticatio…

Fix: after 1.47
Fix from $2,300 2019-09-09
Search Exclude HIGH 7.5
CVE-2019-15895

search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.

Fix: 1.2.4+
Fix from $1,950 2019-09-09
Sahi Pro CRITICAL 9.8
CVE-2019-15102

An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication …

Fix: after 8.0.0
Fix from $2,300 2019-09-06
Grafana HIGH 7.5
CVE-2019-15043EPSS 63%

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack ag…

Fix: 5.4.5 / 6.3.4+
Fix from $1,950 2019-09-03
Woody Ad Snippets HIGH 8.8
CVE-2019-15858EPSS 18%

admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demons…

Fix: 2.2.5+
Fix from $1,950 2019-09-03
Restaurant Reservations CRITICAL 9.8
CVE-2019-15819

The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.

Fix: after 1.3
Fix from $2,300 2019-08-30
Vd 1 Firmware CRITICAL 9.8
CVE-2019-13405

A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to …

No fix yet
Fix from $2,300 2019-08-29
Vd 1 Firmware HIGH 7.5
CVE-2019-13406

A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to…

Fix: after 230
Fix from $1,950 2019-08-29
Hg100 Firmware HIGH 8.1
CVE-2019-11061

A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devic…

Fix: 4.00.09+
Fix from $1,950 2019-08-29
Smarthome HIGH 8.8
CVE-2019-11063

A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the sa…

Fix: 2.0.22 / 3.0.42_190515+
Fix from $1,950 2019-08-29
Cs31x Firmware MEDIUM 5.3
CVE-2019-9935

Various Lexmark products have Incorrect Access Control (issue 2 of 2).

No fix yet
Fix from $1,600 2019-08-28
Cs31x Firmware MEDIUM 5.3
CVE-2019-9934

Various Lexmark products have Incorrect Access Control (issue 1 of 2).

No fix yet
Fix from $1,600 2019-08-28
Virtual System Administrator HIGH 7.5
CVE-2019-15506

An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An una…

Fix: after 9.4.0.37
Fix from $1,950 2019-08-26
Sphinx HIGH 7.5
CVE-2019-14511

Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a fir…

No fix yet
Fix from $1,950 2019-08-22
Integrated Management Controller Supervisor HIGH 7.5
CVE-2019-12634

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D…

Fix: after 6.7.2.0
Fix from $1,950 2019-08-21
Humatrix 7 MEDIUM 5.3
CVE-2019-15129

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo…

No fix yet
Fix from $1,600 2019-08-18
Manageengine Opmanager CRITICAL 9.8
CVE-2019-15106EPSS 25%

An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on t…

Fix: after 12.4.034
Fix from $2,300 2019-08-16
Homematic Ccu2 Firmware CRITICAL 9.8
CVE-2019-9585

eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, res…

Fix: 2.47.10 / 3.47.10+
Fix from $2,300 2019-08-14
Homematic Ccu2 Firmware HIGH 8.1
CVE-2019-14984EPSS 6%

eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to t…

Fix: after 1.2.0
Fix from $1,950 2019-08-13
Dir 600m Firmware CRITICAL 9.8
CVE-2019-13101EPSS 67%

An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lea…

No fix yet
Fix from $2,300 2019-08-08
Enterprise Network Function Virtualization Infrastructure CRITICAL 9.8
CVE-2019-1895

A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an …

Fix: 3.12.1+
Fix from $2,300 2019-08-07
Satellite MEDIUM 6.5
CVE-2019-10198

An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, w…

Fix: 0.15.7+
Fix from $1,600 2019-07-31
Ip2m 841b Firmware HIGH 7.5
CVE-2019-3948EPSS 25%

The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and D…

Fix: 2018-05-18+
Fix from $1,950 2019-07-29
Gpn2.4p21 C Cn Firmware HIGH 7.5
CVE-2019-1010136

ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's …

No fix yet
Fix from $1,950 2019-07-19
Directus 7 Api CRITICAL 9.8
CVE-2019-13983

Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endp…

Fix: 2.2.2+
Fix from $2,300 2019-07-19
Tia Administrator HIGH 7.8
CVE-2019-10915

A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA Administra…

Patch available
Fix from $1,950 2019-07-11
Debian Linux CRITICAL 9.8
CVE-2019-12468

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow…

Fix: after 1.32.1
Fix from $2,300 2019-07-10
Ccu3 Firmware CRITICAL 9.8
CVE-2019-10119

eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attack…

Fix: 2.41.8 / 3.43.16+
Fix from $2,300 2019-07-10
Ccu3 Firmware CRITICAL 9.8
CVE-2019-10121

eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attack…

Fix: 2.41.8 / 3.43.15+
Fix from $2,300 2019-07-10