Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Ilc 131 Eth Firmware CRITICAL 9.8
CVE-2019-9201

Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as d…

No fix yet
Fix from $2,300 2019-02-26
Dir 878 Firmware CRITICAL 9.8
CVE-2019-9125

An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does…

No fix yet
Fix from $2,300 2019-02-25
Thinkphp HIGH 8.8
CVE-2019-9082 KEVEPSS 97%

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefu…

Fix: 3.2.4+
Fix from $1,950 2019-02-24
Wf2411 Firmware CRITICAL 9.8
CVE-2019-8985EPSS 13%

On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that …

No fix yet
Fix from $2,300 2019-02-21
Landscape Management CRITICAL 9.8
CVE-2019-0261

Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for…

Mitigation only
Fix from $2,300 2019-02-15
Indusoft Web Studio CRITICAL 9.8
CVE-2019-6543EPSS 17%

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update…

No fix yet
Fix from $2,300 2019-02-13
Pr100088 Modbus Gateway Firmware CRITICAL 9.1
CVE-2019-6533

Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions p…

Mitigation only
Fix from $2,300 2019-02-12
Dir 823g Firmware HIGH 7.5
CVE-2019-7389

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attac…

No fix yet
Fix from $1,950 2019-02-05
Dir 823g Firmware HIGH 8.6
CVE-2019-7390

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers…

No fix yet
Fix from $1,950 2019-02-05
Es File Explorer File Manager HIGH 8.1
CVE-2019-6447EPSS 64%

The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications v…

Fix: after 4.1.9.7.4
Fix from $1,950 2019-01-16
Cisco Policy Suite Diameter Routing Agent CRITICAL 9.8
CVE-2018-0181

A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could al…

Mitigation only
Fix from $2,300 2019-01-10
Cloud Connector CRITICAL 9.8
CVE-2019-0246

SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity.

Fix: 2.11.3+
Fix from $2,300 2019-01-08
Gate E1 Firmware CRITICAL 9.8
CVE-2018-18995

Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet …

Mitigation only
Fix from $2,300 2019-01-03
Dashboard HIGH 7.5
CVE-2018-18264EPSS 70%

Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the clust…

Fix: 1.10.1+
Fix from $1,950 2019-01-03
Epson Workforce Wf 2861 Firmware CRITICAL 9.1
CVE-2018-19248

The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attacker…

No fix yet
Fix from $2,300 2018-12-24
Micrologix 1400 Firmware HIGH 8.6
CVE-2018-17924

Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP…

Fix: after 10.10
Fix from $1,950 2018-12-07
Intellispace Pacs HIGH 8.8
CVE-2018-17906

Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within …

No fix yet
Fix from $1,950 2018-11-19
Zxhn H168n Firmware HIGH 8.8
CVE-2018-7357EPSS 88%

ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, wh…

No fix yet
Fix from $1,950 2018-11-14
I5 Application Firmware HIGH 7.5
CVE-2018-19079

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemRe…

No fix yet
Fix from $1,950 2018-11-07
Ypc99 Firmware CRITICAL 9.8
CVE-2018-13114

Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a l…

No fix yet
Fix from $2,300 2018-10-22
Security Key Lifecycle Manager HIGH 7.5
CVE-2018-1745

IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Fo…

Fix: after 3.0.0.1
Fix from $1,950 2018-10-11
Debian Linux MEDIUM 5.9
CVE-2018-16758

Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryptio…

Fix: after 1.0.34
Fix from $1,600 2018-10-10
Dir 823g Firmware HIGH 7.5
CVE-2018-17880

On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication to trigger a reboot.

No fix yet
Fix from $1,950 2018-10-03
Eap Controller CRITICAL 9.8
CVE-2018-5393EPSS 13%

The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation …

Fix: after 2.5.3
Fix from $2,300 2018-09-28
Smartcooler Firmware HIGH 7.5
CVE-2018-14796

Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be used to perfo…

Fix: 180806+
Fix from $1,950 2018-09-20
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2018-1757

IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentica…

Patch available
Fix from $1,600 2018-09-07
Wg2600hp2 Firmware HIGH 7.5
CVE-2017-12575

An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some…

Mitigation only
Fix from $1,950 2018-08-24
Bwise CRITICAL 9.8
CVE-2018-11247

The JMX/RMI interface in Nasdaq BWise 5.0 does not require authentication for an SAP BO Component, which allows remote attackers to execute arbitrary…

Mitigation only
Fix from $2,300 2018-08-15
Telem Gwm Firmware CRITICAL 9.8
CVE-2018-10603

Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, whi…

Fix: after 2018.04.18-linux_4-01-601cb47
Fix from $2,300 2018-07-31
Openstack CRITICAL 10.0
CVE-2017-2637

A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed…

Mitigation only
Fix from $2,300 2018-07-26