Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2018-1129
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who…
Ceph Storage
Patch available
HIGH 8.8
CVE-2016-6541
TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updat…
Trackr Bravo Firmware
2.2.5 / 5.1.6+
HIGH 8.1
CVE-2018-3761
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handin…
Nextcloud Server
12.0.8 / 13.0.3+
CRITICAL 9.8
CVE-2018-11052
Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulner…
Elastic Cloud Storage
Mitigation only
CRITICAL 9.8
CVE-2018-4852
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device c…
Siclock Tc400 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-12575
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of auth…
Tl Wr841n Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-8902
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to …
Avalanche
after 6.2
CRITICAL 9.8
CVE-2018-12984
Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials.
Hycus Cms
No fix yet
CRITICAL 9.8
CVE-2018-6667
Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to exe…
Mcafee Web Gateway
after 7.8.1.5
HIGH 8.8
CVE-2018-12613EPSS 98%
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vu…
phpMyAdmin
4.8.2+
MEDIUM 5.3
CVE-2018-9024
An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.
Privileged Access Manager
3.0.0+
CRITICAL 9.8
CVE-2018-1085
openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabl…
Openshift Container Platform
3.9.31+
MEDIUM 6.4
CVE-2018-12271
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication…
Dropbox
Mitigation only
CRITICAL 9.8
CVE-2018-11407
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It all…
Symfony
2.8.37 / 3.3.17+
CRITICAL 9.8
CVE-2018-12048EPSS 5%
A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal…
Lbp7110cw Firmware
No fix yet
CRITICAL 9.8
CVE-2018-12049EPSS 5%
A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /por…
Lbp6030w Firmware
No fix yet
CRITICAL 9.8
CVE-2018-0318
A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gai…
Prime Collaboration
after 12.1
CRITICAL 9.8
CVE-2018-0319
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to …
Prime Collaboration
after 12.1
CRITICAL 9.8
CVE-2018-0321
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invo…
Prime Collaboration
after 11.6
CRITICAL 9.8
CVE-2017-7931
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the co…
Ip Gateway Firmware
after 3.39
MEDIUM 5.3
CVE-2017-7639
QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the se…
Nas Proxy Server
1.3.0+
HIGH 8.3
CVE-2018-10597
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M an…
Intellivue Mp2 Firmware
Mitigation only
HIGH 8.8
CVE-2018-7943
There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some sp…
1288h V5 Firmware
Mitigation only
MEDIUM 5.9
CVE-2017-16025
Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerabili…
Nes
after 6.4.0
CRITICAL 9.8
CVE-2018-10611
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unaut…
Mds Pulsenet
after 3.2.1
CRITICAL 9.8
CVE-2018-11711EPSS 5%
A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html via vectors i…
Mf210 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-11692
An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for …
Lbp3370 Firmware
No fix yet
HIGH 8.8
CVE-2018-7949
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send s…
1288h V5 Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-10532
console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execut…
Console Io
after 2.2.13
MEDIUM 5.3
CVE-2018-11579
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Ch…
Woocommerce Category Banner Management
No fix yet