Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Netweaver System Landscape Directory CRITICAL 9.8
CVE-2018-2368

SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that r…

Mitigation only
Fix from $2,300 2018-03-01
Homematic Central Control Unit Ccu2 Firmware CRITICAL 9.8
CVE-2018-7301

eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests …

Mitigation only
Fix from $2,300 2018-02-22
P 870h 51 Firmware CRITICAL 9.8
CVE-2018-1164

This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.…

Mitigation only
Fix from $2,300 2018-02-21
Medfusion 4000 Wireless Syringe Infusion Pump HIGH 8.1
CVE-2017-12720

An Improper Access Control issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP s…

Mitigation only
Fix from $1,950 2018-02-15
Rv132w Firmware CRITICAL 9.8
CVE-2018-0127EPSS 77%

A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unau…

Mitigation only
Fix from $2,300 2018-02-08
Pxc12\/22\/36 E.d Firmware CRITICAL 9.8
CVE-2018-4834

A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), Desigo PX…

Fix: 6.00.204+
Fix from $2,300 2018-01-24
Sap Kernel HIGH 7.5
CVE-2018-2360

SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that require user identity and cause con…

Mitigation only
Fix from $1,950 2018-01-09
Secure Web Gateway CRITICAL 9.8
CVE-2017-18001EPSS 14%

Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys da…

Fix: after 11.8.0.27
Fix from $2,300 2017-12-31
Tl Sg108e Firmware MEDIUM 6.8
CVE-2017-17746

Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device w…

No fix yet
Fix from $1,600 2017-12-20
Tl Sg108e Firmware MEDIUM 6.5
CVE-2017-17747

Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, trig…

No fix yet
Fix from $1,600 2017-12-20
Camera Firmware CRITICAL 9.8
CVE-2017-3184EPSS 6%

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset pag…

No fix yet
Fix from $2,300 2017-12-16
Ceph MEDIUM 6.3
CVE-2017-12155

A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable…

Patch available
Fix from $1,600 2017-12-12
En 1dbc Firmware HIGH 7.5
CVE-2017-16241

Incorrect access control in AMAG Symmetry Door Edge Network Controllers (EN-1DBC Boot App 23611 03.60 and STD App 23603 03.60; EN-2DBC Boot App 24451…

No fix yet
Fix from $1,950 2017-12-10
B2338 168 Firmware HIGH 8.4
CVE-2017-8155

The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on a certain port. After acc…

Mitigation only
Fix from $1,950 2017-11-22
B2338 168 Firmware MEDIUM 6.8
CVE-2017-8156

The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attac…

Mitigation only
Fix from $1,600 2017-11-22
Infosphere Master Data Management HIGH 7.5
CVE-2017-1523

IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X…

Mitigation only
Fix from $1,950 2017-10-24
Weblogic Server HIGH 7.5
CVE-2017-10271 KEVEPSS 100%

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected …

Patch available
Fix from $1,950 2017-10-19
Zookeeper HIGH 7.5
CVE-2017-5637EPSS 73%

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which lead…

Mitigation only
Fix from $1,950 2017-10-10
Sentinel Ldk Rte Firmware CRITICAL 9.9
CVE-2017-12822

Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 l…

Fix: after 7.50
Fix from $2,300 2017-10-04
Wonderware Indusoft Web Studio CRITICAL 9.8
CVE-2017-13997EPSS 5%

A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine …

Fix: after 8.0
Fix from $2,300 2017-10-03
Application Performance Management CRITICAL 9.8
CVE-2017-14350EPSS 7%

A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulner…

No fix yet
Fix from $2,300 2017-09-30
Security Identity Governance And Intelligence HIGH 8.6
CVE-2017-1483

IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymo…

Patch available
Fix from $1,950 2017-09-28
Dir 850l Firmware CRITICAL 9.8
CVE-2017-14417

register_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, which can result in unintende…

No fix yet
Fix from $2,300 2017-09-13
Sitesentinel Isite Atg Firmware CRITICAL 9.8
CVE-2017-12733

A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500…

Fix: after 175
Fix from $2,300 2017-09-09
Openstack HIGH 7.5
CVE-2017-12440

Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that tr…

Patch available
Fix from $1,950 2017-08-18
Ozw772 Firmware MEDIUM 6.5
CVE-2017-6872

A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to …

Mitigation only
Fix from $1,600 2017-08-08
Ozw772 Firmware HIGH 7.4
CVE-2017-6873

A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in…

Mitigation only
Fix from $1,950 2017-08-08
Vcenter Server CRITICAL 9.0
CVE-2017-4919

VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating System…

Mitigation only
Fix from $2,300 2017-07-28
Advanced Threat Defense CRITICAL 9.8
CVE-2017-4052

Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated us…

Patch available
Fix from $2,300 2017-07-12
Advanced Threat Defense HIGH 7.5
CVE-2017-4055

Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthent…

Patch available
Fix from $1,950 2017-07-12