Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2019-14927EPSS 42% An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote… Smartrtu Firmware after 3.0 Fix from $1,9502019-10-28 MEDIUM 5.3 CVE-2019-13525 In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain we… Ip Ak2 Firmware 1.04.07+ Fix from $1,6002019-10-25 HIGH 7.5 CVE-2019-13549 Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems doe… Pcoweb Firmware Mitigation only Fix from $1,9502019-10-25 CRITICAL 9.8 CVE-2019-15064 HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication. Gpon Firmware Mitigation only Fix from $2,3002019-10-17 CRITICAL 9.1 CVE-2019-17512 There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file vi… Dir 412 Firmware No fix yet Fix from $2,3002019-10-16 MEDIUM 5.3 CVE-2019-15282 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacke… Identity Services Engine Software 2.4+ Fix from $1,6002019-10-16 HIGH 7.5 CVE-2019-17511 There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via … Dir 412 Firmware No fix yet Fix from $1,9502019-10-14 HIGH 7.5 CVE-2019-17532 An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persi… Wemo Switch 28b Firmware No fix yet Fix from $1,9502019-10-12 CRITICAL 9.8 CVE-2019-17506EPSS 56% There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the r… Dir 868l B1 Firmware No fix yet Fix from $2,3002019-10-11 HIGH 7.5 CVE-2019-17505 D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can re… Dap 1320 A2 Firmware No fix yet Fix from $1,9502019-10-11 MEDIUM 5.5 CVE-2019-9529 The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, … Explorer 710 Firmware Mitigation only Fix from $1,6002019-10-10 HIGH 7.5 CVE-2019-15018 A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector … Inspector after 1.280 Fix from $1,9502019-10-09 HIGH 8.2 CVE-2019-17353 An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which c… Dir 615 Firmware Mitigation only Fix from $1,9502019-10-09 CRITICAL 9.4 CVE-2019-17354 wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure… Nbg 418n V2 Firmware Mitigation only Fix from $2,3002019-10-09 MEDIUM 5.3 CVE-2019-0379 SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security pro… Process Integration Mitigation only Fix from $1,6002019-10-08 HIGH 8.8 CVE-2019-17186EPSS 6% /var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution. Hg2201t Firmware No fix yet Fix from $1,9502019-10-08 HIGH 7.5 CVE-2019-17232 Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import. Ultimate Faq after 1.8.24 Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17219 An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authen… Combi Stream Mslq Firmware Mitigation only Fix from $1,9502019-10-06 MEDIUM 5.3 CVE-2019-8292 Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product del… Online Store System No fix yet Fix from $1,6002019-10-01 CRITICAL 9.8 CVE-2019-15940 Victure PC530 devices allow unauthenticated TELNET access as root. Pc530 Firmware No fix yet Fix from $2,3002019-10-01 MEDIUM 5.3 CVE-2019-13523 In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain we… Hbd3pr2 Firmware Mitigation only Fix from $1,6002019-09-26 CRITICAL 9.8 CVE-2019-15068 A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/… Smart Battery A4 Firmware Mitigation only Fix from $2,3002019-09-25 MEDIUM 6.5 CVE-2019-6652 In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS). Big Iq Centralized Management after 6.1.0 Fix from $1,6002019-09-25 CRITICAL 9.8 CVE-2019-5504 ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote atta… Ontap Select Deploy Administration Utility Patch available Fix from $2,3002019-09-24 MEDIUM 6.5 CVE-2019-14253 An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and perform a query on PHP forms … Publisure No fix yet Fix from $1,6002019-09-18 CRITICAL 9.8 CVE-2019-16199EPSS 9% eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface … Homematic Ccu2 Firmware 2.47.18 / 3.47.18+ Fix from $2,3002019-09-17 MEDIUM 5.3 CVE-2019-8449EPSS 85% The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosu… Jira 8.4.0+ Fix from $1,6002019-09-11 MEDIUM 5.3 CVE-2019-11466 In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on… Couchbase Server Mitigation only Fix from $1,6002019-09-10 CRITICAL 9.1 CVE-2019-11496 In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authenticati… Couchbase Server after 5.0.0 Fix from $2,3002019-09-10 HIGH 8.2 CVE-2019-12105 In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected compon… Supervisor after 4.0.2 Fix from $1,9502019-09-10