Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-16613EPSS 8%
An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and …
Debian Linux
after 2.15.1
CRITICAL 9.8
CVE-2017-16566
On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core s…
Jooan A5 Ip Camera Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-12337EPSS 6%
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an u…
Emergency Responder
Mitigation only
HIGH 7.5
CVE-2017-12316
A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform mul…
Identity Services Engine Software
Mitigation only
MEDIUM 5.3
CVE-2017-15272
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The app…
Psftpd
No fix yet
HIGH 8.8
CVE-2017-9314
Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171…
Nvr5464 16p 4ks2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-16562EPSS 27%
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and…
Userpro
4.9.17.1+
CRITICAL 9.8
CVE-2017-16634
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
Joomla\!
after 3.8.1
HIGH 8.1
CVE-2017-2914
An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token c…
Circle With Disney Firmware
No fix yet
CRITICAL 9.8
CVE-2017-2864
An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets …
Circle With Disney Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-1000154
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara'…
Mahara
Patch available
HIGH 7.5
CVE-2017-12281
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Air…
Aironet 1800 Firmware
Mitigation only
HIGH 8.1
CVE-2017-10873
OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vul…
Openam
after 13.0.0-73
MEDIUM 6.5
CVE-2017-1222
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allow…
Bigfix Platform
Patch available
HIGH 7.2
CVE-2017-12160
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit…
Keycloak
Mitigation only
HIGH 7.5
CVE-2017-9946EPSS 25%
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network …
Apogee Pxc Firmware
3.5+
HIGH 7.5
CVE-2017-5635
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin…
Nifi
Mitigation only
CRITICAL 9.9
CVE-2017-12251
A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciou…
Cloud Services Platform 2100
Mitigation only
CRITICAL 9.8
CVE-2017-14322EPSS 37%
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attack…
Email Marketer
after 6.1.5
HIGH 8.2
CVE-2017-9625
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authenticat…
Envidas Ultimate
after 1.0.0.4
CRITICAL 9.8
CVE-2017-15295
Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.
Point Of Sale Xpress Server
Mitigation only
HIGH 7.5
CVE-2017-15297
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
Host Agent
Mitigation only
CRITICAL 9.8
CVE-2017-15293
Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain at…
Point Of Sale Xpress Server
Mitigation only
CRITICAL 9.8
CVE-2017-10622EPSS 5%
An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based a…
Junos Space
Mitigation only
HIGH 8.1
CVE-2017-10623
Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to interc…
Junos Space
after 16.2
CRITICAL 9.8
CVE-2016-5791
An Improper Authentication issue was discovered in JanTek JTC-200, all versions. The improper authentication could provide an undocumented BusyBox Li…
Jtc 200 Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-5791EPSS 69%
The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via un…
Intelligent Management Center Plat
Mitigation only
CRITICAL 9.8
CVE-2017-14003
An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior vers…
Ether Serial Link Firmware
after 6.01.00
HIGH 7.5
CVE-2017-14972
InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Mana…
Mondopad
No fix yet
CRITICAL 9.8
CVE-2016-8937
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclo…
Tivoli Storage Manager
Patch available