Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-14927EPSS 42%
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote…
Smartrtu Firmware
after 3.0
MEDIUM 5.3
CVE-2019-13525
In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain we…
Ip Ak2 Firmware
1.04.07+
HIGH 7.5
CVE-2019-13549
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems doe…
Pcoweb Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-15064
HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication.
Gpon Firmware
Mitigation only
CRITICAL 9.1
CVE-2019-17512
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file vi…
Dir 412 Firmware
No fix yet
MEDIUM 5.3
CVE-2019-15282
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacke…
Identity Services Engine Software
2.4+
HIGH 7.5
CVE-2019-17511
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via …
Dir 412 Firmware
No fix yet
HIGH 7.5
CVE-2019-17532
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persi…
Wemo Switch 28b Firmware
No fix yet
CRITICAL 9.8
CVE-2019-17506EPSS 56%
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the r…
Dir 868l B1 Firmware
No fix yet
HIGH 7.5
CVE-2019-17505
D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can re…
Dap 1320 A2 Firmware
No fix yet
MEDIUM 5.5
CVE-2019-9529
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, …
Explorer 710 Firmware
Mitigation only
HIGH 7.5
CVE-2019-15018
A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector …
Inspector
after 1.280
HIGH 8.2
CVE-2019-17353
An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which c…
Dir 615 Firmware
Mitigation only
CRITICAL 9.4
CVE-2019-17354
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure…
Nbg 418n V2 Firmware
Mitigation only
MEDIUM 5.3
CVE-2019-0379
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security pro…
Process Integration
Mitigation only
HIGH 8.8
CVE-2019-17186EPSS 6%
/var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution.
Hg2201t Firmware
No fix yet
HIGH 7.5
CVE-2019-17232
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
Ultimate Faq
after 1.8.24
HIGH 8.8
CVE-2019-17219
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authen…
Combi Stream Mslq Firmware
Mitigation only
MEDIUM 5.3
CVE-2019-8292
Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product del…
Online Store System
No fix yet
CRITICAL 9.8
CVE-2019-15940
Victure PC530 devices allow unauthenticated TELNET access as root.
Pc530 Firmware
No fix yet
MEDIUM 5.3
CVE-2019-13523
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain we…
Hbd3pr2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-15068
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/…
Smart Battery A4 Firmware
Mitigation only
MEDIUM 6.5
CVE-2019-6652
In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).
Big Iq Centralized Management
after 6.1.0
CRITICAL 9.8
CVE-2019-5504
ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote atta…
Ontap Select Deploy Administration Utility
Patch available
MEDIUM 6.5
CVE-2019-14253
An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and perform a query on PHP forms …
Publisure
No fix yet
CRITICAL 9.8
CVE-2019-16199EPSS 9%
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface …
Homematic Ccu2 Firmware
2.47.18 / 3.47.18+
MEDIUM 5.3
CVE-2019-8449EPSS 85%
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosu…
Jira
8.4.0+
MEDIUM 5.3
CVE-2019-11466
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on…
Couchbase Server
Mitigation only
CRITICAL 9.1
CVE-2019-11496
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authenticati…
Couchbase Server
after 5.0.0
HIGH 8.2
CVE-2019-12105
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected compon…
Supervisor
after 4.0.2