Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-2871
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. An attack…
C1 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-6546EPSS 17%
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes c…
Plays.tv
1.27.7.0+
CRITICAL 9.1
CVE-2018-6547
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, contains a…
Plays.tv
1.27.7.0+
MEDIUM 5.3
CVE-2016-9646
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572),…
Debian Linux
3.20161229+
CRITICAL 9.8
CVE-2017-0356
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker …
Debian Linux
3.20170111+
HIGH 8.1
CVE-2014-3999
The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.
Horde Ldap
2.0.6+
HIGH 7.3
CVE-2016-8371EPSS 11%
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.
Ilc Plcs Firmware
No fix yet
HIGH 7.3
CVE-2016-8380EPSS 11%
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
Ilc Plcs Firmware
No fix yet
HIGH 8.1
CVE-2018-1082
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspende…
Moodle
after 3.4.1
CRITICAL 9.8
CVE-2018-6873
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
Auth0.js
after 8.10.1
CRITICAL 9.8
CVE-2018-9248EPSS 15%
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
Vdsl2 Modem Hg 150 Ub Firmware
No fix yet
CRITICAL 9.8
CVE-2018-9249EPSS 6%
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to a…
Vdsl2 Modem Hg 150 Ub Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-3822
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. …
X Pack
Mitigation only
CRITICAL 9.8
CVE-2018-9148
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass…
My Cloud Firmware
No fix yet
CRITICAL 9.8
CVE-2017-14911
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 2…
Mdm9206 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-4841
A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could…
Tim 1531 Irc Firmware
1.1+
HIGH 8.8
CVE-2018-0195
A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the AP…
Ios Xe
16.2.2+
MEDIUM 6.5
CVE-2018-0163
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to…
iOS
Mitigation only
CRITICAL 9.8
CVE-2018-5451
In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficiently prove…
Alice 6 Firmware
Mitigation only
HIGH 8.8
CVE-2018-9105
NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privileged helper tool's implemente…
Nordvpn
Mitigation only
CRITICAL 9.8
CVE-2018-1237
Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This…
Emc Scaleio
2.5+
MEDIUM 6.5
CVE-2015-4987
The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified ve…
Tealeaf Customer Experience
after 9.0.2
CRITICAL 9.8
CVE-2018-9032EPSS 28%
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version…
Dir 850l Firmware
after 2.06
MEDIUM 6.7
CVE-2017-15534
The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can a…
Norton App Lock
1.3.0.13+
CRITICAL 9.8
CVE-2018-1312EPSS 16%
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g…
HTTP Server
Mitigation only
CRITICAL 9.8
CVE-2018-7532EPSS 8%
Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras,…
G Cam\/efd 2250 Firmware
No fix yet
MEDIUM 6.8
CVE-2017-16242
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data acces…
Usb Memory Stick With Fingerprint Firwmare
Mitigation only
MEDIUM 6.7
CVE-2017-17743
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5…
Wireless Appliance Firmware
4.4.20 / 5.0.19+
CRITICAL 9.8
CVE-2017-14002
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Succ…
Infinia Hawkeye 4 Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-14004
GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation …
Gemnet License Server
Mitigation only