Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Growi HIGH 7.5
CVE-2019-13338

In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for…

Fix: 3.5.0+
Fix from $1,950 2019-07-09
Dashcom Live Firmware HIGH 7.5
CVE-2019-11020

Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easi…

Mitigation only
Fix from $1,950 2019-07-09
Dashcom Live Firmware HIGH 7.5
CVE-2019-11019

Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely access all claim details by vis…

Fix: after 2019-05-08
Fix from $1,950 2019-07-09
Hide.me HIGH 7.8
CVE-2019-12174

hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configFilePath:configFileName method…

Fix: 2.4.4+
Fix from $1,950 2019-07-08
Wp Like Button MEDIUM 5.3
CVE-2019-13344EPSS 45%

An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change se…

Fix: after 1.6.0
Fix from $1,600 2019-07-05
Superdoctor 5 CRITICAL 9.8
CVE-2019-13131

Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.

No fix yet
Fix from $2,300 2019-07-01
Robotic Process Automation With Automation Anywhere MEDIUM 5.3
CVE-2019-4337

IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in I…

Fix: 11.0.0.4+
Fix from $1,600 2019-07-01
Clever Dog Smart Camera Panorama Dog 2w Firmware MEDIUM 5.5
CVE-2019-12919

On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal S…

No fix yet
Fix from $1,600 2019-06-20
Wide Area Application Services MEDIUM 5.3
CVE-2019-1876

A vulnerability in the HTTPS proxy feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to…

Mitigation only
Fix from $1,600 2019-06-20
Rv110w Firmware MEDIUM 5.3
CVE-2019-1897

A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to …

No fix yet
Fix from $1,600 2019-06-20
Integrated Management Controller MEDIUM 5.3
CVE-2019-1629

A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker t…

Mitigation only
Fix from $1,600 2019-06-20
Integrated Management Controller MEDIUM 5.3
CVE-2019-1631

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker…

Mitigation only
Fix from $1,600 2019-06-20
Redwoodhq CRITICAL 9.8
CVE-2019-12890EPSS 6%

RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automation…

No fix yet
Fix from $2,300 2019-06-19
Netweaver Process Integration MEDIUM 5.3
CVE-2019-0312

Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to…

Mitigation only
Fix from $1,600 2019-06-12
Cloudforms Management Engine MEDIUM 5.3
CVE-2017-15123

A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users onl…

Fix: after 5.10
Fix from $1,600 2019-06-12
Mf920 Firmware HIGH 7.5
CVE-2019-3411

All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login…

Mitigation only
Fix from $1,950 2019-06-11
Wpgraphql CRITICAL 9.8
CVE-2019-9879EPSS 47%

The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are al…

No fix yet
Fix from $2,300 2019-06-10
Wpgraphql CRITICAL 9.1
CVE-2019-9880EPSS 35%

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attack…

No fix yet
Fix from $2,300 2019-06-10
Wpgraphql MEDIUM 5.3
CVE-2019-9881EPSS 19%

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow…

No fix yet
Fix from $1,600 2019-06-10
Wp1001 Firmware HIGH 8.8
CVE-2019-12505

Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keystroke injection attacks. Thus,…

No fix yet
Fix from $1,950 2019-06-07
R700 Laser Presentation Remote Firmware HIGH 8.8
CVE-2019-12506

Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystro…

No fix yet
Fix from $1,950 2019-06-07
M3 Firmware CRITICAL 9.8
CVE-2019-11523

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully …

No fix yet
Fix from $2,300 2019-06-06
Ar 727h Firmware HIGH 7.5
CVE-2019-6451

On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.

No fix yet
Fix from $1,950 2019-06-06
Pydio MEDIUM 5.3
CVE-2019-10046

An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.

No fix yet
Fix from $1,600 2019-05-31
Tebe Small Firmware HIGH 7.5
CVE-2019-9105

The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of AP…

No fix yet
Fix from $1,950 2019-05-31
Fm K75 Firmware CRITICAL 9.8
CVE-2019-9871EPSS 6%

Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.

No fix yet
Fix from $2,300 2019-05-31
M365 Firmware MEDIUM 6.5
CVE-2019-12500

The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands …

Fix: 1.5.1+
Fix from $1,600 2019-05-31
Access Professional Edition CRITICAL 9.1
CVE-2019-6958

A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7…

Fix: 1.7.6.079 / 6.10+
Fix from $2,300 2019-05-29
C7824iwp Firmware CRITICAL 9.8
CVE-2019-12288

An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network…

Mitigation only
Fix from $2,300 2019-05-23
C7824wip Firmware CRITICAL 9.8
CVE-2019-12289

An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices.…

Mitigation only
Fix from $2,300 2019-05-23