Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-14643EPSS 6%
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely exec…
Foreman
Patch available
CRITICAL 9.8
CVE-2018-12242
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allo…
Messaging Gateway
10.6.6+
HIGH 7.8
CVE-2017-3912
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbit…
Application And Change Control
Mitigation only
MEDIUM 5.3
CVE-2018-16670EPSS 25%
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
Circarlife Scada
4.3+
MEDIUM 5.3
CVE-2018-16668EPSS 10%
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /ht…
Circarlife Scada
4.3+
CRITICAL 9.8
CVE-2018-17153EPSS 87%
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated …
My Cloud Wdbctl0020hwt Firmware
2.30.196+
HIGH 8.1
CVE-2018-11787
In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re…
Karaf
3.0.9 / 4.0.9+
HIGH 7.2
CVE-2017-2872
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A HTTP re…
C1 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-16286EPSS 22%
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is lim…
Supersign Cms
No fix yet
MEDIUM 6.8
CVE-2018-7572
Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windo…
Pulse Secure Desktop
Mitigation only
CRITICAL 9.8
CVE-2018-16947
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not…
Debian Linux
1.6.23 / 1.8.2+
CRITICAL 9.1
CVE-2018-15485
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or authorization, aka KONE-03.
Group Controller Firmware
4.6.5+
CRITICAL 9.8
CVE-2018-16590
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.
Felcom 250 Firmware
No fix yet
HIGH 7.5
CVE-2017-14026
In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allow an att…
Thermal Management Center Firmware
4.13+
HIGH 8.1
CVE-2018-15478
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LE…
Wifi Switch Firmware
2.58 / 2.66+
MEDIUM 6.5
CVE-2018-15479
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LE…
Wifi Switch Firmware
2.58 / 2.66+
CRITICAL 9.8
CVE-2018-13821
A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, inc…
Unified Infrastructure Management
Patch available
CRITICAL 9.8
CVE-2018-7791
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior t…
Modicon M221 Firmware
1.6.2.0+
CRITICAL 9.8
CVE-2018-14805
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values withi…
Esoms
Mitigation only
CRITICAL 9.8
CVE-2018-15727EPSS 64%
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cooki…
Grafana
4.6.4 / 5.2.3+
CRITICAL 9.8
CVE-2017-9819
The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier …
Bharat Interface For Money \(bhim\)
Mitigation only
CRITICAL 9.8
CVE-2017-9820
The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Acce…
Bharat Interface For Money \(bhim\)
Mitigation only
CRITICAL 9.4
CVE-2018-14786
Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and pri…
Alaris Gs Firmware
after 2.3.6
MEDIUM 5.4
CVE-2018-1999045
A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2…
Jenkins
after 2.137
HIGH 7.5
CVE-2017-16348
An exploitable denial of service vulnerability exists in Insteon Hub running firmware version 1012. Leftover demo functionality allows for arbitraril…
Insteon Hub Firmware
No fix yet
HIGH 7.5
CVE-2018-15667
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send" command in the URL scheme all…
Airmail
Mitigation only
HIGH 7.5
CVE-2018-15598
Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is pu…
Traefik
1.6.6+
CRITICAL 9.8
CVE-2017-16748EPSS 5%
An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using…
Niagara
after 4.4
CRITICAL 9.8
CVE-2018-14078
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL …
Smart Hp Wmt
Mitigation only
HIGH 7.0
CVE-2018-13435
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulati…
Line
No fix yet