Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2019-15896EPSS 7% An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is… Lifterlms after 3.34.5 Fix from $2,3002019-09-10 CRITICAL 9.1 CVE-2019-10668 An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authenticatio… Librenms after 1.47 Fix from $2,3002019-09-09 HIGH 7.5 CVE-2019-15895 search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes. Search Exclude 1.2.4+ Fix from $1,9502019-09-09 CRITICAL 9.8 CVE-2019-15102 An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication … Sahi Pro after 8.0.0 Fix from $2,3002019-09-06 HIGH 7.5 CVE-2019-15043EPSS 63% In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack ag… Grafana 5.4.5 / 6.3.4+ Fix from $1,9502019-09-03 HIGH 8.8 CVE-2019-15858EPSS 18% admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demons… Woody Ad Snippets 2.2.5+ Fix from $1,9502019-09-03 CRITICAL 9.8 CVE-2019-15819 The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication. Restaurant Reservations after 1.3 Fix from $2,3002019-08-30 CRITICAL 9.8 CVE-2019-13405 A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to … Vd 1 Firmware No fix yet Fix from $2,3002019-08-29 HIGH 7.5 CVE-2019-13406 A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to… Vd 1 Firmware after 230 Fix from $1,9502019-08-29 HIGH 8.1 CVE-2019-11061 A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devic… Hg100 Firmware 4.00.09+ Fix from $1,9502019-08-29 HIGH 8.8 CVE-2019-11063 A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the sa… Smarthome 2.0.22 / 3.0.42_190515+ Fix from $1,9502019-08-29 MEDIUM 5.3 CVE-2019-9935 Various Lexmark products have Incorrect Access Control (issue 2 of 2). Cs31x Firmware No fix yet Fix from $1,6002019-08-28 MEDIUM 5.3 CVE-2019-9934 Various Lexmark products have Incorrect Access Control (issue 1 of 2). Cs31x Firmware No fix yet Fix from $1,6002019-08-28 HIGH 7.5 CVE-2019-15506 An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An una… Virtual System Administrator after 9.4.0.37 Fix from $1,9502019-08-26 HIGH 7.5 CVE-2019-14511 Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a fir… Sphinx No fix yet Fix from $1,9502019-08-22 HIGH 7.5 CVE-2019-12634 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D… Integrated Management Controller Supervisor after 6.7.2.0 Fix from $1,9502019-08-21 MEDIUM 5.3 CVE-2019-15129 The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo… Humatrix 7 No fix yet Fix from $1,6002019-08-18 CRITICAL 9.8 CVE-2019-15106EPSS 25% An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on t… Manageengine Opmanager after 12.4.034 Fix from $2,3002019-08-16 CRITICAL 9.8 CVE-2019-9585 eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, res… Homematic Ccu2 Firmware 2.47.10 / 3.47.10+ Fix from $2,3002019-08-14 HIGH 8.1 CVE-2019-14984EPSS 6% eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to t… Homematic Ccu2 Firmware after 1.2.0 Fix from $1,9502019-08-13 CRITICAL 9.8 CVE-2019-13101EPSS 67% An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lea… Dir 600m Firmware No fix yet Fix from $2,3002019-08-08 CRITICAL 9.8 CVE-2019-1895 A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an … Enterprise Network Function Virtualization Infrastructure 3.12.1+ Fix from $2,3002019-08-07 MEDIUM 6.5 CVE-2019-10198 An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, w… Satellite 0.15.7+ Fix from $1,6002019-07-31 HIGH 7.5 CVE-2019-3948EPSS 25% The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and D… Ip2m 841b Firmware 2018-05-18+ Fix from $1,9502019-07-29 HIGH 7.5 CVE-2019-1010136 ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's … Gpn2.4p21 C Cn Firmware No fix yet Fix from $1,9502019-07-19 CRITICAL 9.8 CVE-2019-13983 Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endp… Directus 7 Api 2.2.2+ Fix from $2,3002019-07-19 HIGH 7.8 CVE-2019-10915 A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA Administra… Tia Administrator Patch available Fix from $1,9502019-07-11 CRITICAL 9.8 CVE-2019-12468 An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow… Debian Linux after 1.32.1 Fix from $2,3002019-07-10 CRITICAL 9.8 CVE-2019-10119 eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attack… Ccu3 Firmware 2.41.8 / 3.43.16+ Fix from $2,3002019-07-10 CRITICAL 9.8 CVE-2019-10121 eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attack… Ccu3 Firmware 2.41.8 / 3.43.15+ Fix from $2,3002019-07-10