Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.1 CVE-2017-3209 The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permissions to the anonymous user. … U818a Firmware Mitigation only Fix from $1,9502018-07-24 HIGH 8.1 CVE-2017-3217 CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no password is configured for this … Lmu 3030 Obd Ii Firmware Mitigation only Fix from $1,9502018-07-24 CRITICAL 9.8 CVE-2018-0374 A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connect directl… Mobility Services Engine Mitigation only Fix from $2,3002018-07-18 CRITICAL 9.8 CVE-2018-0376 A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Pol… Mobility Services Engine 18.2.0+ Fix from $2,3002018-07-18 CRITICAL 9.8 CVE-2018-0377 A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, remote at… Mobility Services Engine 18.1.0+ Fix from $2,3002018-07-18 MEDIUM 6.5 CVE-2017-2638 It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability… Jboss Data Grid 9.0.0+ Fix from $1,6002018-07-16 MEDIUM 6.5 CVE-2016-9496 Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP … Hn7740s Firmware Mitigation only Fix from $1,6002018-07-13 HIGH 7.5 CVE-2016-6544 getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be e… Itrack Easy Mitigation only Fix from $1,9502018-07-13 CRITICAL 9.8 CVE-2018-10635EPSS 5% In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbitrary URScript code and execu… Cb3.1 Firmware Mitigation only Fix from $2,3002018-07-11 MEDIUM 6.5 CVE-2016-6540 Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by usi… Trackr Bravo Firmware 2.2.5 / 5.1.6+ Fix from $1,6002018-07-06 HIGH 8.8 CVE-2016-6541 TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updat… Trackr Bravo Firmware 2.2.5 / 5.1.6+ Fix from $1,9502018-07-06 HIGH 7.5 CVE-2017-0919 GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import compo… GitLab 10.1.6 / 10.2.6+ Fix from $1,9502018-07-03 CRITICAL 9.8 CVE-2018-7778 In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain… Evlink Charging Station Firmware 3.2.0-12_v1+ Fix from $2,3002018-07-03 CRITICAL 9.8 CVE-2018-4853 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp … Siclock Tc400 Firmware Mitigation only Fix from $2,3002018-07-03 HIGH 8.8 CVE-2018-4854 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp … Siclock Tc400 Firmware Mitigation only Fix from $1,9502018-07-03 CRITICAL 9.8 CVE-2018-8016 The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows r… Cassandra after 3.11.1 Fix from $2,3002018-06-28 MEDIUM 5.3 CVE-2011-4190 The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. Thi… Suse Linux Enterprise Desktop Mitigation only Fix from $1,6002018-06-08 HIGH 8.8 CVE-2018-11476 An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryp… Icar 2 Wi Fi Obd2 Firmware Mitigation only Fix from $1,9502018-05-30 HIGH 7.8 CVE-2018-5486 NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized lo… Oncommand Unified Manager after 7.3 Fix from $1,9502018-04-25 CRITICAL 9.8 CVE-2018-5338EPSS 9% An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechani… Manageengine Desktop Central No fix yet Fix from $2,3002018-04-18 CRITICAL 9.8 CVE-2018-5339EPSS 8% An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. Manageengine Desktop Central No fix yet Fix from $2,3002018-04-18 HIGH 8.8 CVE-2018-0554 Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified ve… Wzr 1750dhp2 Firmware after 2.30 Fix from $1,9502018-04-09 MEDIUM 6.1 CVE-2018-9119 An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the card, extract credit card number… Fuze Card Ble Firmware Mitigation only Fix from $1,6002018-04-04 CRITICAL 9.8 CVE-2018-9162 Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by chang… Smart Home Firmware No fix yet Fix from $2,3002018-03-31 CRITICAL 9.8 CVE-2018-6223EPSS 10% A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate t… Email Encryption Gateway Patch available Fix from $2,3002018-03-15 HIGH 8.8 CVE-2017-10854 Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors. Cg Wgr 1200 Firmware after 2.20 Fix from $1,9502018-03-09 HIGH 8.8 CVE-2018-0521 Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspe… Wxr 1900dhp2 Firmware after 2.48 Fix from $1,9502018-03-09 HIGH 7.8 CVE-2014-7271 Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. Fedora 0.10.0+ Fix from $1,9502018-03-08 HIGH 7.5 CVE-2018-4838 A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versio… En100 Ethernet Module Iec 104 Firmware 4.30+ Fix from $1,9502018-03-08 HIGH 7.5 CVE-2018-4840 A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet m… Siprotec Compact 7sj80 Firmware 4.30 / 4.77+ Fix from $1,9502018-03-08