Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.0
CVE-2017-3765
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoo…
Enterprise Network Operating System
8.4.6.0+
HIGH 8.8
CVE-2017-12695
An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this …
Shanghai Onstar
Mitigation only
CRITICAL 9.8
CVE-2017-15883
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of servic…
Sitefinity
Mitigation only
MEDIUM 5.7
CVE-2018-3815
The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS…
Communigate Pro
No fix yet
CRITICAL 9.8
CVE-2017-15548
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Inte…
Avamar Server
Mitigation only
HIGH 8.1
CVE-2017-1000489
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
Mautic
Mitigation only
HIGH 8.1
CVE-2017-1000433
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without k…
Debian Linux
after 4.4.0
CRITICAL 9.8
CVE-2018-3810EPSS 91%
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to inse…
Smart Google Code Inserter
3.5+
CRITICAL 9.8
CVE-2014-0121
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
Jboss Fuse
after 1.2.2
CRITICAL 9.8
CVE-2015-6237
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerat…
Ip360
Mitigation only
CRITICAL 9.8
CVE-2015-7224
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password …
Puppetlabs Mysql
after 3.6.0
CRITICAL 9.8
CVE-2017-17777
Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parame…
Paid To Read Script
No fix yet
CRITICAL 9.8
CVE-2017-17560EPSS 73%
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.ph…
My Cloud Pr4100 Firmware
Patch available
CRITICAL 9.8
CVE-2017-16684
SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionaliti…
Business Intelligence Promotion Management Application
Mitigation only
HIGH 8.8
CVE-2017-16689
A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT, 7.22, 7.22EXT; SAP KERNEL f…
Sap Kernel
Mitigation only
CRITICAL 9.8
CVE-2017-17430
Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface.
Netborder\/vega Session Firmware
Mitigation only
HIGH 8.8
CVE-2017-17435
An issue was discovered in the software on Vaultek Gun Safe VT20i products, aka BlueSteal. An attacker can remotely unlock any safe in this product l…
Vt20i Firmware
Mitigation only
HIGH 7.5
CVE-2017-16953EPSS 11%
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration …
Zxdsl 831cii Firmware
No fix yet
CRITICAL 9.8
CVE-2017-10903
Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device with root privileges and conduct…
Ptw Wms1 Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-14377
EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Bu…
Authentication Agent For Web
Mitigation only
HIGH 8.1
CVE-2017-13872EPSS 37%
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory U…
Mac Os X
Patch available
MEDIUM 6.5
CVE-2017-9316
Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal D…
Nvr11hs Firmware
Patch available
HIGH 8.8
CVE-2017-0910
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the …
Zulip Server
1.7.1+
HIGH 8.1
CVE-2017-8028
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP Bind…
Debian Linux
Mitigation only
MEDIUM 6.2
CVE-2017-8214
Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, …
Honor 8 Firmware
Mitigation only
HIGH 8.8
CVE-2017-8194
The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authen…
Fusionsphere Openstack
Mitigation only
HIGH 8.8
CVE-2017-8195
The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authen…
Fusionsphere Openstack
Mitigation only
MEDIUM 6.8
CVE-2017-8151
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design…
Honor 5s Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-2738
VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability. This is due to improper implementation of…
Vcm5010 Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-8861
Missing authentication for the remote configuration port 1236/tcp on the Cohu 3960HD allows an attacker to change configuration parameters such as IP…
3960hd Firmware
Mitigation only