Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.8 CVE-2020-9004 A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to … Streaming Engine after 4.8.0 Fix from $1,9502020-04-14 CRITICAL 9.8 CVE-2020-11673 An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clon… Responsive Poll after 1.3.4 Fix from $2,3002020-04-13 CRITICAL 9.8 CVE-2020-3952 KEVEPSS 90% Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does no… Vcenter Server Mitigation only Fix from $2,3002020-04-10 CRITICAL 9.8 CVE-2020-10625 WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account. Webaccess\/nms 3.0.2+ Fix from $2,3002020-04-09 MEDIUM 6.8 CVE-2020-10263 An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART interface and then they can (i) … Xiaomi Xiaoai Speaker Pro Lx06 Firmware No fix yet Fix from $1,6002020-04-08 HIGH 7.5 CVE-2018-21041 An issue was discovered on Samsung mobile devices with O(8.x) software. Access to Gallery in the Secure Folder can occur without authentication. The … Android Mitigation only Fix from $1,9502020-04-08 CRITICAL 9.8 CVE-2020-11598 An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and exe… Cipace 9.1+ Fix from $2,3002020-04-06 HIGH 7.5 CVE-2020-11599 An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the username and password of the SM… Cipace 9.1+ Fix from $1,9502020-04-06 MEDIUM 6.6 CVE-2020-9473 The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, an attacker with access to the… Sg 150 0 Firmware 1.2.4+ Fix from $1,6002020-04-06 HIGH 8.8 CVE-2020-10264 CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Data Exchange) interface on por… Ur Software after 3.3.3.292 Fix from $1,9502020-04-06 CRITICAL 9.4 CVE-2020-10265 Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a s… Ur Software after 3.3.3.292 Fix from $2,3002020-04-06 MEDIUM 5.3 CVE-2020-11547EPSS 52% PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU… Prtg Network Monitor 20.1.57.1745+ Fix from $1,6002020-04-05 HIGH 7.5 CVE-2020-9349 The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service without a password. Tv 288zd 2mp Firmware No fix yet Fix from $1,9502020-04-02 HIGH 7.5 CVE-2020-8509EPSS 11% Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information discl… Manageengine Desktop Central 10.0.483+ Fix from $1,9502020-03-30 HIGH 8.1 CVE-2020-3920 UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access th… Ultralog Express Firmware Mitigation only Fix from $1,9502020-03-27 HIGH 8.1 CVE-2020-10965 Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default ad… Pcoip Management Console Patch available Fix from $1,9502020-03-25 MEDIUM 5.3 CVE-2019-20624 An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words via the lock screen. The Sams… Android Mitigation only Fix from $1,6002020-03-24 MEDIUM 5.5 CVE-2019-20550 An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a lo… Android Mitigation only Fix from $1,6002020-03-24 HIGH 7.5 CVE-2020-10833 An issue was discovered on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows attackers to access the quick panel and notificati… Android Mitigation only Fix from $1,9502020-03-24 MEDIUM 5.3 CVE-2019-20532 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the Developer options without authe… Android Mitigation only Fix from $1,6002020-03-24 HIGH 7.5 CVE-2020-10874 Motorola FX9500 devices allow remote attackers to read database files. Fx9500 41324d41 Us Firmware No fix yet Fix from $1,9502020-03-23 HIGH 7.8 CVE-2020-7479 A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which cou… Interactive Graphical Scada System 14.0.0.20009+ Fix from $1,9502020-03-23 MEDIUM 5.3 CVE-2020-8497EPSS 5% In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, use… Pandora Fms after 7.42 Fix from $1,6002020-03-23 MEDIUM 6.8 CVE-2019-16258 The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environ… Brain Cube Core after 2.23.0 Fix from $1,6002020-03-20 CRITICAL 9.8 CVE-2019-12125 In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker g… Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-19 CRITICAL 9.8 CVE-2019-12126 In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gain… Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-19 CRITICAL 9.8 CVE-2019-12127 In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains… Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-19 HIGH 7.5 CVE-2019-15654 Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web mana… Ac2400 Firmware No fix yet Fix from $1,9502020-03-19 HIGH 7.5 CVE-2019-15655 D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. Th… Dsl 2875al Firmware after 1.00.05 Fix from $1,9502020-03-19 CRITICAL 9.8 CVE-2019-12128 In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains … Open Network Automation Platform after 4.0.0 Fix from $2,3002020-03-19