Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-14006
GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credenti…
Xeleris
Mitigation only
CRITICAL 9.8
CVE-2017-14008
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successf…
Centricity Pacs Ra1000
Mitigation only
CRITICAL 9.8
CVE-2016-9880
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and cou…
Gemfire For Pivotal Cloud Foundry
1.6.5+
HIGH 8.1
CVE-2018-8715EPSS 23%
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forge…
Appweb
after 7.0.2
CRITICAL 9.8
CVE-2018-6328EPSS 65%
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unau…
Unitrends Backup
10.1+
CRITICAL 9.8
CVE-2018-8710
A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the …
Woocommerce Products Filter
2.2.0+
HIGH 7.0
CVE-2018-0886EPSS 82%
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, W…
Windows 10
Patch available
CRITICAL 9.8
CVE-2018-8096EPSS 49%
Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","…
Seq
4.2.605+
CRITICAL 9.8
CVE-2018-7750EPSS 27%
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2…
Ansible Engine
Patch available
CRITICAL 9.8
CVE-2018-6294
Unsecured way of firmware update in Hanwha Techwin Smartcams
Snh V6410pn Firmware
No fix yet
CRITICAL 9.8
CVE-2018-6299
Authentication bypass in Hanwha Techwin Smartcams
Snh V6410pn Firmware
No fix yet
CRITICAL 9.8
CVE-2018-7749
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests.…
Asyncssh
1.12.1+
CRITICAL 9.8
CVE-2017-2628
curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not refl…
Curl
Mitigation only
CRITICAL 9.8
CVE-2018-7213
The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authentication and macOS disk-encry…
Blur
No fix yet
HIGH 8.1
CVE-2017-18223
BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.
Remedy Action Request System
9.1.03+
MEDIUM 5.3
CVE-2018-7227
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of spe…
Mps110 1 Firmware
3.29.67+
CRITICAL 9.8
CVE-2018-7228
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticate…
Mps110 1 Firmware
3.29.67+
HIGH 8.1
CVE-2018-7236
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due …
Mps110 1 Firmware
3.29.67+
MEDIUM 5.9
CVE-2018-1443
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated …
Security Access Manager
after 9.0.4
MEDIUM 6.5
CVE-2017-7638
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitatio…
Media Streaming Add On
after 430.1.2.0
MEDIUM 5.6
CVE-2018-0087
A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP serv…
Asyncos
Mitigation only
HIGH 7.5
CVE-2018-7745EPSS 12%
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/installation/createuserinfo reque…
Razor
No fix yet
HIGH 7.2
CVE-2017-15519
Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File S…
Snapcenter Server
after 3.0.1
CRITICAL 9.8
CVE-2018-1343
PAM exposure enabling unauthenticated access to remote host
Privileged Account Manager
3.1.0.4 / 3.2.0.3+
CRITICAL 9.8
CVE-2018-5455
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and …
Oncell G3110 Hspa Firmware
after 1.4
CRITICAL 9.8
CVE-2017-9285
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
Edirectory
after 9.0
HIGH 7.5
CVE-2017-5189
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extrac…
Imanager
Mitigation only
HIGH 7.5
CVE-2018-5314
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build…
Netscaler Application Delivery Controller
Mitigation only
MEDIUM 6.5
CVE-2018-1286
In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny servi…
Openmeetings
after 4.0.1
CRITICAL 9.8
CVE-2018-0121
A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unau…
Elastic Services Controller
Mitigation only