Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
U818a Firmware HIGH 8.1
CVE-2017-3209

The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permissions to the anonymous user. …

Mitigation only
Fix from $1,950 2018-07-24
Lmu 3030 Obd Ii Firmware HIGH 8.1
CVE-2017-3217

CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no password is configured for this …

Mitigation only
Fix from $1,950 2018-07-24
Mobility Services Engine CRITICAL 9.8
CVE-2018-0374

A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connect directl…

Mitigation only
Fix from $2,300 2018-07-18
Mobility Services Engine CRITICAL 9.8
CVE-2018-0376

A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Pol…

Fix: 18.2.0+
Fix from $2,300 2018-07-18
Mobility Services Engine CRITICAL 9.8
CVE-2018-0377

A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, remote at…

Fix: 18.1.0+
Fix from $2,300 2018-07-18
Jboss Data Grid MEDIUM 6.5
CVE-2017-2638

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability…

Fix: 9.0.0+
Fix from $1,600 2018-07-16
Hn7740s Firmware MEDIUM 6.5
CVE-2016-9496

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP …

Mitigation only
Fix from $1,600 2018-07-13
Itrack Easy HIGH 7.5
CVE-2016-6544

getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be e…

Mitigation only
Fix from $1,950 2018-07-13
Cb3.1 Firmware CRITICAL 9.8
CVE-2018-10635EPSS 5%

In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbitrary URScript code and execu…

Mitigation only
Fix from $2,300 2018-07-11
Trackr Bravo Firmware MEDIUM 6.5
CVE-2016-6540

Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by usi…

Fix: 2.2.5 / 5.1.6+
Fix from $1,600 2018-07-06
Trackr Bravo Firmware HIGH 8.8
CVE-2016-6541

TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updat…

Fix: 2.2.5 / 5.1.6+
Fix from $1,950 2018-07-06
GitLab HIGH 7.5
CVE-2017-0919

GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import compo…

Fix: 10.1.6 / 10.2.6+
Fix from $1,950 2018-07-03
Evlink Charging Station Firmware CRITICAL 9.8
CVE-2018-7778

In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain…

Fix: 3.2.0-12_v1+
Fix from $2,300 2018-07-03
Siclock Tc400 Firmware CRITICAL 9.8
CVE-2018-4853

A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp …

Mitigation only
Fix from $2,300 2018-07-03
Siclock Tc400 Firmware HIGH 8.8
CVE-2018-4854

A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp …

Mitigation only
Fix from $1,950 2018-07-03
Cassandra CRITICAL 9.8
CVE-2018-8016

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows r…

Fix: after 3.11.1
Fix from $2,300 2018-06-28
Suse Linux Enterprise Desktop MEDIUM 5.3
CVE-2011-4190

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. Thi…

Mitigation only
Fix from $1,600 2018-06-08
Icar 2 Wi Fi Obd2 Firmware HIGH 8.8
CVE-2018-11476

An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryp…

Mitigation only
Fix from $1,950 2018-05-30
Oncommand Unified Manager HIGH 7.8
CVE-2018-5486

NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized lo…

Fix: after 7.3
Fix from $1,950 2018-04-25
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5338EPSS 9%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechani…

No fix yet
Fix from $2,300 2018-04-18
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5339EPSS 8%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.

No fix yet
Fix from $2,300 2018-04-18
Wzr 1750dhp2 Firmware HIGH 8.8
CVE-2018-0554

Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified ve…

Fix: after 2.30
Fix from $1,950 2018-04-09
Fuze Card Ble Firmware MEDIUM 6.1
CVE-2018-9119

An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the card, extract credit card number…

Mitigation only
Fix from $1,600 2018-04-04
Smart Home Firmware CRITICAL 9.8
CVE-2018-9162

Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by chang…

No fix yet
Fix from $2,300 2018-03-31
Email Encryption Gateway CRITICAL 9.8
CVE-2018-6223EPSS 10%

A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate t…

Patch available
Fix from $2,300 2018-03-15
Cg Wgr 1200 Firmware HIGH 8.8
CVE-2017-10854

Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors.

Fix: after 2.20
Fix from $1,950 2018-03-09
Wxr 1900dhp2 Firmware HIGH 8.8
CVE-2018-0521

Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspe…

Fix: after 2.48
Fix from $1,950 2018-03-09
Fedora HIGH 7.8
CVE-2014-7271

Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.

Fix: 0.10.0+
Fix from $1,950 2018-03-08
En100 Ethernet Module Iec 104 Firmware HIGH 7.5
CVE-2018-4838

A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versio…

Fix: 4.30+
Fix from $1,950 2018-03-08
Siprotec Compact 7sj80 Firmware HIGH 7.5
CVE-2018-4840

A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet m…

Fix: 4.30 / 4.77+
Fix from $1,950 2018-03-08