Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2019-9201 Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as d… Ilc 131 Eth Firmware No fix yet Fix from $2,3002019-02-26 CRITICAL 9.8 CVE-2019-9125 An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does… Dir 878 Firmware No fix yet Fix from $2,3002019-02-25 HIGH 8.8 CVE-2019-9082 KEVEPSS 97% ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefu… Thinkphp 3.2.4+ Fix from $1,9502019-02-24 CRITICAL 9.8 CVE-2019-8985EPSS 13% On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that … Wf2411 Firmware No fix yet Fix from $2,3002019-02-21 CRITICAL 9.8 CVE-2019-0261 Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for… Landscape Management Mitigation only Fix from $2,3002019-02-15 CRITICAL 9.8 CVE-2019-6543EPSS 17% AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update… Indusoft Web Studio No fix yet Fix from $2,3002019-02-13 CRITICAL 9.1 CVE-2019-6533 Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions p… Pr100088 Modbus Gateway Firmware Mitigation only Fix from $2,3002019-02-12 HIGH 7.5 CVE-2019-7389 An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attac… Dir 823g Firmware No fix yet Fix from $1,9502019-02-05 HIGH 8.6 CVE-2019-7390 An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers… Dir 823g Firmware No fix yet Fix from $1,9502019-02-05 HIGH 8.1 CVE-2019-6447EPSS 64% The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications v… Es File Explorer File Manager after 4.1.9.7.4 Fix from $1,9502019-01-16 CRITICAL 9.8 CVE-2018-0181 A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could al… Cisco Policy Suite Diameter Routing Agent Mitigation only Fix from $2,3002019-01-10 CRITICAL 9.8 CVE-2019-0246 SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity. Cloud Connector 2.11.3+ Fix from $2,3002019-01-08 CRITICAL 9.8 CVE-2018-18995 Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet … Gate E1 Firmware Mitigation only Fix from $2,3002019-01-03 HIGH 7.5 CVE-2018-18264EPSS 70% Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the clust… Dashboard 1.10.1+ Fix from $1,9502019-01-03 CRITICAL 9.1 CVE-2018-19248 The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attacker… Epson Workforce Wf 2861 Firmware No fix yet Fix from $2,3002018-12-24 HIGH 8.6 CVE-2018-17924 Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP… Micrologix 1400 Firmware after 10.10 Fix from $1,9502018-12-07 HIGH 8.8 CVE-2018-17906 Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within … Intellispace Pacs No fix yet Fix from $1,9502018-11-19 HIGH 8.8 CVE-2018-7357EPSS 88% ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, wh… Zxhn H168n Firmware No fix yet Fix from $1,9502018-11-14 HIGH 7.5 CVE-2018-19079 An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemRe… I5 Application Firmware No fix yet Fix from $1,9502018-11-07 CRITICAL 9.8 CVE-2018-13114 Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a l… Ypc99 Firmware No fix yet Fix from $2,3002018-10-22 HIGH 7.5 CVE-2018-1745 IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Fo… Security Key Lifecycle Manager after 3.0.0.1 Fix from $1,9502018-10-11 MEDIUM 5.9 CVE-2018-16758 Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryptio… Debian Linux after 1.0.34 Fix from $1,6002018-10-10 HIGH 7.5 CVE-2018-17880 On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication to trigger a reboot. Dir 823g Firmware No fix yet Fix from $1,9502018-10-03 CRITICAL 9.8 CVE-2018-5393EPSS 13% The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation … Eap Controller after 2.5.3 Fix from $2,3002018-09-28 HIGH 7.5 CVE-2018-14796 Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be used to perfo… Smartcooler Firmware 180806+ Fix from $1,9502018-09-20 MEDIUM 5.3 CVE-2018-1757 IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentica… Security Identity Governance And Intelligence Patch available Fix from $1,6002018-09-07 HIGH 7.5 CVE-2017-12575 An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some… Wg2600hp2 Firmware Mitigation only Fix from $1,9502018-08-24 CRITICAL 9.8 CVE-2018-11247 The JMX/RMI interface in Nasdaq BWise 5.0 does not require authentication for an SAP BO Component, which allows remote attackers to execute arbitrary… Bwise Mitigation only Fix from $2,3002018-08-15 CRITICAL 9.8 CVE-2018-10603 Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, whi… Telem Gwm Firmware after 2018.04.18-linux_4-01-601cb47 Fix from $2,3002018-07-31 CRITICAL 10.0 CVE-2017-2637 A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed… Openstack Mitigation only Fix from $2,3002018-07-26