Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2019-6808EPSS 8% A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which… Modicon Premium Firmware 2.90 / 3.10+ Fix from $2,3002019-05-22 HIGH 8.2 CVE-2019-6820 A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address,… Modicon M100 Firmware Mitigation only Fix from $1,9502019-05-22 CRITICAL 9.4 CVE-2019-10919 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp could perfor… Logo\!8 Bm Firmware 8.3+ Fix from $2,3002019-05-14 CRITICAL 9.8 CVE-2019-10922 A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2… Simatic Pcs 7 after 8.0 Fix from $2,3002019-05-14 HIGH 7.5 CVE-2019-9727 Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retri… Ccu3 Firmware after 3.43.15 Fix from $1,9502019-05-13 HIGH 7.5 CVE-2019-7404 An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing… Gamp 7100 Firmware No fix yet Fix from $1,9502019-05-13 MEDIUM 6.5 CVE-2019-5014 An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An att… Fw 1007 Firmware Mitigation only Fix from $1,6002019-05-08 CRITICAL 9.8 CVE-2019-7564 An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require… Rt3052 Firmware No fix yet Fix from $2,3002019-05-07 CRITICAL 9.8 CVE-2019-10950 Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure teln… Cr Ir 357 Fcr Carbon X Firmware Mitigation only Fix from $2,3002019-04-30 CRITICAL 9.8 CVE-2019-8993 The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric,… Activematrix Bpm after 4.2.0 Fix from $2,3002019-04-24 CRITICAL 9.8 CVE-2019-7727 In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting regis… Engage after 6.5 Fix from $2,3002019-04-23 CRITICAL 9.8 CVE-2019-3899 It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i… Openshift Container Platform Mitigation only Fix from $2,3002019-04-22 MEDIUM 5.9 CVE-2019-10886 An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other a… Photo Sharing Plus No fix yet Fix from $1,6002019-04-19 MEDIUM 5.3 CVE-2019-11321 An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentic… Cx2 Firmware No fix yet Fix from $1,6002019-04-18 HIGH 7.8 CVE-2019-1654 A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating sy… Ap Cos 8.3.150.0 / 8.5.135.0+ Fix from $1,9502019-04-17 CRITICAL 9.1 CVE-2019-9974 diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command… H660rm Firmware No fix yet Fix from $2,3002019-04-11 HIGH 7.5 CVE-2019-10946 An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unaut… Joomla\! after 3.9.4 Fix from $1,9502019-04-10 HIGH 7.5 CVE-2019-3941 Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC. Webaccess No fix yet Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-5514 VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An a… Fusion 11.0.3+ Fix from $1,9502019-04-01 HIGH 7.5 CVE-2019-6542 ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows an unauthenticated user to ini… Datagate Mk2 Firmware 70044_update_05032019-482 / 70050_update_05032019-482+ Fix from $1,9502019-03-28 MEDIUM 6.5 CVE-2019-6538 The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 P… Mycarelink Monitor Firmware Mitigation only Fix from $1,6002019-03-25 HIGH 7.5 CVE-2019-7642 D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS quer… Dir 817lw Firmware No fix yet Fix from $1,9502019-03-25 CRITICAL 9.8 CVE-2019-10039 The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a… Dir 816 Firmware No fix yet Fix from $2,3002019-03-25 CRITICAL 9.8 CVE-2019-10040 The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a… Dir 816 Firmware No fix yet Fix from $2,3002019-03-25 CRITICAL 9.8 CVE-2019-10041 The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a… Dir 816 Firmware No fix yet Fix from $2,3002019-03-25 HIGH 7.5 CVE-2019-10042 The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp a… Dir 816 Firmware No fix yet Fix from $1,9502019-03-25 HIGH 7.5 CVE-2018-20220EPSS 15% An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be int… Enc 400 Hdmi Firmware after 2.56 Fix from $1,9502019-03-21 HIGH 7.5 CVE-2019-3917 The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router … I 240w Q Gpon Ont Firmware No fix yet Fix from $1,9502019-03-05 HIGH 7.8 CVE-2018-19636 Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides… Supportutils 3.1-5.7.1+ Fix from $1,9502019-03-05 HIGH 7.5 CVE-2019-9484 The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session … Pcoweb Card Firmware Mitigation only Fix from $1,9502019-03-01