Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2019-12129 In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains… Open Network Automation Platform after 4.0.0 Fix from $2,3002020-03-19 CRITICAL 9.8 CVE-2019-12130 In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains… Open Network Automation Platform after 4.0.0 Fix from $2,3002020-03-19 HIGH 7.5 CVE-2019-20529 In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (… Frappe Patch available Fix from $1,9502020-03-18 CRITICAL 9.8 CVE-2019-12114 An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already … Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-18 CRITICAL 9.8 CVE-2019-12115 An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has acces… Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-18 CRITICAL 9.8 CVE-2019-12116 An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated attacker (who already has acces… Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-18 CRITICAL 9.8 CVE-2019-12117 An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who alread… Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-18 CRITICAL 9.8 CVE-2019-12118 An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has a… Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-18 CRITICAL 9.8 CVE-2019-12119 An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has a… Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-18 CRITICAL 9.8 CVE-2019-12120 An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has acc… Open Network Automation Platform 4.0.0+ Fix from $2,3002020-03-18 HIGH 7.5 CVE-2020-9325 Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download. Tiff Server No fix yet Fix from $1,9502020-03-18 CRITICAL 9.8 CVE-2020-8598EPSS 13% Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could… Apex One Patch available Fix from $2,3002020-03-18 HIGH 7.5 CVE-2019-13194 Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive infor… Ads 2400n Firmware No fix yet Fix from $1,9502020-03-13 HIGH 7.5 CVE-2019-13205 All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. Thi… Ecosys M5526cdw Firmware Mitigation only Fix from $1,9502020-03-13 MEDIUM 5.3 CVE-2019-19799EPSS 6% Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedSer… Manageengine Applications Manager 14.5+ Fix from $1,6002020-03-13 MEDIUM 5.3 CVE-2020-10079 GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authe… GitLab after 12.8.1 Fix from $1,6002020-03-13 CRITICAL 9.8 CVE-2020-6207 KEVEPSS 98% SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a servic… Solution Manager Mitigation only Fix from $2,3002020-03-10 CRITICAL 9.8 CVE-2020-6198 SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to contro… Solution Manager Mitigation only Fix from $2,3002020-03-10 CRITICAL 9.8 CVE-2020-5328 Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ… Emc Isilon Onefs 8.2.0+ Fix from $2,3002020-03-06 HIGH 7.5 CVE-2020-9544 An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-upd… Dsl 2640b Firmware No fix yet Fix from $1,9502020-03-05 HIGH 7.5 CVE-2019-19224 A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to download the confi… Dsl 2680 Firmware No fix yet Fix from $1,9502020-03-04 HIGH 7.5 CVE-2019-19225 A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers… Dsl 2680 Firmware No fix yet Fix from $1,9502020-03-04 HIGH 7.5 CVE-2019-19226 A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to enable or disable … Dsl 2680 Firmware No fix yet Fix from $1,9502020-03-04 HIGH 7.5 CVE-2015-5201 VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as pack… Enterprise Virtualization 3.5.6 / 6-6.7-20151117.0+ Fix from $1,9502020-02-25 HIGH 8.8 CVE-2020-9330 Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDA… Workcentre 3655 Firmware 073.060.000.02300 / 073.091.000.02300+ Fix from $1,9502020-02-21 MEDIUM 5.3 CVE-2020-5326 Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Te… Chengming 3980 Firmware 1.4.3 / 1.8.0+ Fix from $1,6002020-02-21 HIGH 7.5 CVE-2020-6186 SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host… Host Agent Mitigation only Fix from $1,9502020-02-12 CRITICAL 9.1 CVE-2020-6769 Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set… Video Streaming Gateway after 6.45.08 Fix from $2,3002020-02-07 HIGH 7.5 CVE-2020-7953 An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of … Opmon Mitigation only Fix from $1,9502020-02-06 HIGH 7.8 CVE-2020-7954 An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the … Opmon Mitigation only Fix from $1,9502020-02-06