Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-11478
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the ca…
Icar 2 Wi Fi Obd2 Firmware
Mitigation only
MEDIUM 5.9
CVE-2014-10067
paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal …
Paypal Ipn
3.0.0+
CRITICAL 9.8
CVE-2016-10525
When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authenticati…
Hapi Auth Jwt2
after 5.1.1
MEDIUM 6.5
CVE-2017-9421
Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web …
Kiteworks
2017.01.00+
CRITICAL 9.8
CVE-2018-8898EPSS 13%
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer…
Dsl 3782 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-0271
A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass a…
Digital Network Architecture Center
1.1.2+
MEDIUM 5.3
CVE-2018-10825
Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows…
Mimo Baby 2 Firmware
Mitigation only
HIGH 7.8
CVE-2018-6617
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by le…
Easy Hosting Control Panel
No fix yet
MEDIUM 6.2
CVE-2018-7940
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authenti…
Mate 9 Firmware
8.0.0.129+
HIGH 8.8
CVE-2018-7941
Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authe…
Ch121 V3 Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-6020
In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, whi…
Sd 320an Firmware
after 2.01
CRITICAL 9.8
CVE-2018-10682EPSS 8%
An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authe…
Wildfly
No fix yet
CRITICAL 9.8
CVE-2018-10683
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful…
Wildfly
No fix yet
MEDIUM 6.4
CVE-2017-3775
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code …
Flex System X240 M5 Bios
2.23 / 2.61+
CRITICAL 9.8
CVE-2018-10561 KEVEPSS 93%
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device th…
Gpon Router Firmware
Mitigation only
HIGH 8.1
CVE-2018-10641
D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.
Dir 601 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-10544
Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.
Mss110 Firmware
after 1.1.24
HIGH 7.8
CVE-2018-9232
Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and …
Be126 Firmware
No fix yet
HIGH 7.8
CVE-2018-10576
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native A…
Ap200 Firmware
1.2.9.15+
HIGH 8.8
CVE-2018-1418EPSS 52%
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.
Qradar Security Information And Event Manager
7.2.8+
HIGH 8.8
CVE-2017-12712
The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stam…
Accent Firmware
Mitigation only
HIGH 8.8
CVE-2018-1112
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to conne…
Glusterfs
3.10.12+
CRITICAL 9.8
CVE-2018-10362
An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for th…
Phpliteadmin
after 1.9.7.1
MEDIUM 5.5
CVE-2018-1106
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed package…
Enterprise Linux Desktop
Mitigation only
HIGH 8.1
CVE-2014-0927
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass …
Sterling B2b Integrator
Patch available
HIGH 8.8
CVE-2018-6960
VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication.…
Horizon Daas
8.0.0+
CRITICAL 9.9
CVE-2018-0238EPSS 5%
A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, …
Unified Computing System Director
Mitigation only
CRITICAL 9.8
CVE-2018-7760
An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI …
Bmxnor0200 Firmware
Mitigation only
HIGH 7.5
CVE-2016-10434
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 820 and SD 820A, the input to…
Sd 820 Firmware
Mitigation only
MEDIUM 5.9
CVE-2017-12196
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that…
Undertow
after 1.4.18