Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.6
CVE-2017-12549
A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
System Management Homepage
7.6.1+
CRITICAL 9.8
CVE-2011-4973
Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and en…
Mod Nss
Mitigation only
MEDIUM 6.8
CVE-2017-17161
The 'Find Phone' function in some Huawei smart phones with software earlier than Duke-L09C10B186 versions, earlier than Duke-L09C432B187 versions, ea…
Duke L09 Firmware
Mitigation only
MEDIUM 6.8
CVE-2017-15351
The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an authentication bypass vulnerabili…
Honor V9 Play Firmware
Mitigation only
HIGH 7.5
CVE-2018-7034
TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demon…
Tew 751dr Firmware
No fix yet
CRITICAL 9.8
CVE-2018-5459
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different …
Pfc200 Firmware
02.07.07+
HIGH 8.8
CVE-2017-18179
Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termina…
Sitefinity
No fix yet
MEDIUM 5.4
CVE-2017-0911
Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to…
Twitter Kit
after 3.2.1
CRITICAL 9.8
CVE-2018-3601
A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication o…
Control Manager
Patch available
CRITICAL 9.8
CVE-2018-6180
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts.
Online Voting Platform
No fix yet
CRITICAL 9.8
CVE-2018-1163EPSS 16%
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw…
Netvault Backup
Mitigation only
HIGH 7.2
CVE-2018-0116
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subsc…
Mobility Services Engine
Mitigation only
CRITICAL 9.8
CVE-2017-6199
A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field.
Sandstorm
0.203+
HIGH 8.8
CVE-2018-6569
West Wind Web Server 6.x does not require authentication for /ADMIN.ASP.
Web Connection
Mitigation only
MEDIUM 5.3
CVE-2018-5794
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is No Authentication for the Aero…
Wing
5.8.6.9 / 5.9.1.3+
HIGH 7.5
CVE-2017-2297
Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issu…
Puppet Enterprise
2016.4.5+
CRITICAL 9.8
CVE-2011-4068
The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty passwor…
Packetfence
after 3.0.1
MEDIUM 6.8
CVE-2017-16858
The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an …
Crowd
3.1.2+
HIGH 8.8
CVE-2017-1000354
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user. T…
Jenkins
after 2.56
CRITICAL 9.8
CVE-2017-14698
ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N…
Dsl Ac51 Firmware
Patch available
MEDIUM 5.3
CVE-2018-4835
A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's port 8000/t…
Telecontrol Server Basic
3.1+
HIGH 8.8
CVE-2018-4836
A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleControl Se…
Telecontrol Server Basic
3.1+
HIGH 8.1
CVE-2017-15135
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during th…
389 Directory Server
after 1.4.0.3
CRITICAL 9.8
CVE-2017-15531
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users.…
Reporter
9.5.4.1+
HIGH 8.8
CVE-2017-16590
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.699 build 1…
Enterprise Manager
Mitigation only
HIGH 7.5
CVE-2015-6926
The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address …
Eshop
after 4.4.8
CRITICAL 9.8
CVE-2018-5328
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can…
Contractorweb.net
No fix yet
HIGH 7.5
CVE-2014-6435EPSS 13%
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attacker…
Adsl Dsl5018en \(1t1r\) Firmware
No fix yet
CRITICAL 9.8
CVE-2014-6436EPSS 42%
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opp…
Adsl Dsl5018en \(1t1r\) Firmware
No fix yet
MEDIUM 6.2
CVE-2018-0008
An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain in…
Junos
Mitigation only