Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Odoo CRITICAL 9.8
CVE-2017-10804

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain …

Patch available
Fix from $2,300 2017-07-04
Hg100r Firmware CRITICAL 9.8
CVE-2017-7315

An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router cred…

No fix yet
Fix from $2,300 2017-07-04
Airlink Raven Xe Firmware CRITICAL 9.8
CVE-2017-6044

An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions …

Mitigation only
Fix from $2,300 2017-06-30
Ox350 Firmware CRITICAL 9.8
CVE-2017-3216EPSS 5%

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthe…

No fix yet
Fix from $2,300 2017-06-20
Kibana MEDIUM 6.5
CVE-2016-10364

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any …

Mitigation only
Fix from $1,600 2017-06-16
Android HIGH 7.8
CVE-2015-9030

In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication.

No fix yet
Fix from $1,950 2017-06-13
Pcs Xg100 Firmware HIGH 8.8
CVE-2016-7830

Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firm…

Fix: after 1.21
Fix from $1,950 2017-06-09
Lightify Home CRITICAL 9.8
CVE-2016-5053

OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000.

Fix: after 1.6.1
Fix from $2,300 2017-04-10
Baby Zoom Wifi Monitor Firmware CRITICAL 9.8
CVE-2015-2888

Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the MySnapCam web service.

Mitigation only
Fix from $2,300 2017-04-10
Asr 5000 Series Software HIGH 8.8
CVE-2017-3819

A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 Series, A…

Mitigation only
Fix from $1,950 2017-03-15
Netbackup CRITICAL 9.8
CVE-2017-6409

An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Unauthenticated CORBA interfaces permit inappro…

Fix: after 8.0
Fix from $2,300 2017-03-02
Cadd Solis Medication Safety Software CRITICAL 9.9
CVE-2016-8355

An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-Solis Medication Safety Softwar…

Mitigation only
Fix from $2,300 2017-02-13
Nport 5100 Series Firmware CRITICAL 9.8
CVE-2016-9369EPSS 9%

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2…

Fix: after 3.10
Fix from $2,300 2017-02-13
Universal Multifunctional Electric Power Quality Meter Firmware CRITICAL 9.8
CVE-2017-5162EPSS 13%

An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to a…

Mitigation only
Fix from $2,300 2017-02-13
Netweaver Application Server Java CRITICAL 10.0
CVE-2010-5326 KEVEPSS 17%

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote att…

Fix: after 7.30
Fix from $2,300 2016-05-13
Data Protector CRITICAL 9.8
CVE-2016-2004EPSS 94%

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors rel…

Fix: 7.03_108 / 8.15+
Fix from $2,300 2016-04-21
Etg3000 Factorycast Hmi Gateway Firmware HIGH 7.8
CVE-2014-9197

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access con…

Patch available
Fix from $1,950 2015-01-27
Multiprog HIGH 7.5
CVE-2014-9195EPSS 81%

Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compli…

No fix yet
Fix from $1,950 2015-01-17
Track It\! HIGH 7.5
CVE-2014-4872EPSS 80%

BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary…

No fix yet
Fix from $1,950 2014-10-10
Ruggedcom Rugged Operating System MEDIUM 5.0
CVE-2014-2590

The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote…

Fix: 3.11.0 / 3.11.5+
Fix from $1,600 2014-04-01
Altiris Deployment Solution HIGH 7.8
CVE-2008-6827

The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM…

Fix: 6.9.355+
Fix from $1,950 2009-06-08
Php Recommend HIGH 7.5
CVE-2009-1780

admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers t…

Fix: after 1.3
Fix from $1,950 2009-05-22
Debian Linux HIGH 10.0
CVE-2007-0956EPSS 30%

The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning…

Fix: 1.6.1+
Fix from $1,950 2007-04-06
Dwl 900ap\+ Firmware HIGH 7.5
CVE-2002-1810

D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, whi…

Mitigation only
Fix from $1,950 2002-12-31