Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Modicon Premium Firmware CRITICAL 9.8
CVE-2019-6808EPSS 8%

A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which…

Fix: 2.90 / 3.10+
Fix from $2,300 2019-05-22
Modicon M100 Firmware HIGH 8.2
CVE-2019-6820

A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address,…

Mitigation only
Fix from $1,950 2019-05-22
Logo\!8 Bm Firmware CRITICAL 9.4
CVE-2019-10919

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp could perfor…

Fix: 8.3+
Fix from $2,300 2019-05-14
Simatic Pcs 7 CRITICAL 9.8
CVE-2019-10922

A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2…

Fix: after 8.0
Fix from $2,300 2019-05-14
Ccu3 Firmware HIGH 7.5
CVE-2019-9727

Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retri…

Fix: after 3.43.15
Fix from $1,950 2019-05-13
Gamp 7100 Firmware HIGH 7.5
CVE-2019-7404

An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing…

No fix yet
Fix from $1,950 2019-05-13
Fw 1007 Firmware MEDIUM 6.5
CVE-2019-5014

An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An att…

Mitigation only
Fix from $1,600 2019-05-08
Rt3052 Firmware CRITICAL 9.8
CVE-2019-7564

An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require…

No fix yet
Fix from $2,300 2019-05-07
Cr Ir 357 Fcr Carbon X Firmware CRITICAL 9.8
CVE-2019-10950

Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure teln…

Mitigation only
Fix from $2,300 2019-04-30
Activematrix Bpm CRITICAL 9.8
CVE-2019-8993

The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric,…

Fix: after 4.2.0
Fix from $2,300 2019-04-24
Engage CRITICAL 9.8
CVE-2019-7727

In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting regis…

Fix: after 6.5
Fix from $2,300 2019-04-23
Openshift Container Platform CRITICAL 9.8
CVE-2019-3899

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i…

Mitigation only
Fix from $2,300 2019-04-22
Photo Sharing Plus MEDIUM 5.9
CVE-2019-10886

An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other a…

No fix yet
Fix from $1,600 2019-04-19
Cx2 Firmware MEDIUM 5.3
CVE-2019-11321

An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentic…

No fix yet
Fix from $1,600 2019-04-18
Ap Cos HIGH 7.8
CVE-2019-1654

A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating sy…

Fix: 8.3.150.0 / 8.5.135.0+
Fix from $1,950 2019-04-17
H660rm Firmware CRITICAL 9.1
CVE-2019-9974

diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command…

No fix yet
Fix from $2,300 2019-04-11
Joomla\! HIGH 7.5
CVE-2019-10946

An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unaut…

Fix: after 3.9.4
Fix from $1,950 2019-04-10
Webaccess HIGH 7.5
CVE-2019-3941

Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.

No fix yet
Fix from $1,950 2019-04-09
Fusion HIGH 8.8
CVE-2019-5514

VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An a…

Fix: 11.0.3+
Fix from $1,950 2019-04-01
Datagate Mk2 Firmware HIGH 7.5
CVE-2019-6542

ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows an unauthenticated user to ini…

Fix: 70044_update_05032019-482 / 70050_update_05032019-482+
Fix from $1,950 2019-03-28
Mycarelink Monitor Firmware MEDIUM 6.5
CVE-2019-6538

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 P…

Mitigation only
Fix from $1,600 2019-03-25
Dir 817lw Firmware HIGH 7.5
CVE-2019-7642

D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS quer…

No fix yet
Fix from $1,950 2019-03-25
Dir 816 Firmware CRITICAL 9.8
CVE-2019-10039

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a…

No fix yet
Fix from $2,300 2019-03-25
Dir 816 Firmware CRITICAL 9.8
CVE-2019-10040

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a…

No fix yet
Fix from $2,300 2019-03-25
Dir 816 Firmware CRITICAL 9.8
CVE-2019-10041

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a…

No fix yet
Fix from $2,300 2019-03-25
Dir 816 Firmware HIGH 7.5
CVE-2019-10042

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a…

No fix yet
Fix from $1,950 2019-03-25
Enc 400 Hdmi Firmware HIGH 7.5
CVE-2018-20220EPSS 15%

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be int…

Fix: after 2.56
Fix from $1,950 2019-03-21
I 240w Q Gpon Ont Firmware HIGH 7.5
CVE-2019-3917

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router …

No fix yet
Fix from $1,950 2019-03-05
Supportutils HIGH 7.8
CVE-2018-19636

Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides…

Fix: 3.1-5.7.1+
Fix from $1,950 2019-03-05
Pcoweb Card Firmware HIGH 7.5
CVE-2019-9484

The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session …

Mitigation only
Fix from $1,950 2019-03-01