Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 10.0
CVE-2017-13995
An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not proper…
Ininet Webserver
after 2.02.0000
CRITICAL 9.4
CVE-2017-14000
An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a specific unifo…
Skyrouter Z4200 Firmware
after 6.00.05
HIGH 8.5
CVE-2017-1000106
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing …
Blue Ocean
after 1.1.5
CRITICAL 9.8
CVE-2017-12819
Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK produ…
Sentinel Ldk Rte Firmware
after 7.50
CRITICAL 9.8
CVE-2017-13983EPSS 6%
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows rem…
Bsm Platform Application Performance Management System Health
Mitigation only
MEDIUM 6.5
CVE-2017-13984
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows rem…
Bsm Platform Application Performance Management System Health
Mitigation only
CRITICAL 9.8
CVE-2017-12229EPSS 5%
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote atta…
Ios Xe
Mitigation only
CRITICAL 9.8
CVE-2017-12236
A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, r…
Ios Xe
Mitigation only
HIGH 7.5
CVE-2017-14766
The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function an…
Simple Student Result
after 1.6.3
HIGH 7.2
CVE-2017-14602
A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 …
Application Delivery Controller Firmware
Patch available
HIGH 8.8
CVE-2017-5192
When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, externa…
Salt
after 2015.8.12
CRITICAL 9.8
CVE-2017-14706EPSS 28%
DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservice…
I Suite
Patch available
CRITICAL 9.8
CVE-2017-14080
Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific par…
Mobile Security
Patch available
CRITICAL 9.8
CVE-2015-1187 KEVEPSS 83%
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
Dir 626l Firmware
Mitigation only
HIGH 8.1
CVE-2017-14623
In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application…
Ldap
after 2.5.0
HIGH 8.8
CVE-2017-10784EPSS 16%
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject …
Ruby
after 2.2.7
CRITICAL 9.8
CVE-2014-9611EPSS 13%
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/i…
Netsweeper
after 4.0.4
CRITICAL 9.8
CVE-2014-9618EPSS 73%
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authenticati…
Netsweeper
after 3.1.9
HIGH 7.5
CVE-2017-9803
Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or a…
Solr
Mitigation only
CRITICAL 9.8
CVE-2017-14243EPSS 15%
An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administr…
Wa3002g4 Firmware
No fix yet
HIGH 8.1
CVE-2017-14337
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST A…
Misp
after 2.4.79
HIGH 7.5
CVE-2014-9624
CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
Mantisbt
after 1.2.18
CRITICAL 9.8
CVE-2017-7649
The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be con…
Kura
after 2.0.2
MEDIUM 6.5
CVE-2017-7650
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or rem…
Debian Linux
1.4.12+
MEDIUM 6.5
CVE-2017-12225
A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another u…
Prime Lan Management Solution
Mitigation only
CRITICAL 9.8
CVE-2017-14147EPSS 66%
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its …
Adsl An1020 25 Firmware
No fix yet
CRITICAL 9.8
CVE-2015-3442
Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API call.
Xpert.line
No fix yet
MEDIUM 5.9
CVE-2017-14117EPSS 8%
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures an unauthenticated pro…
U Verse Firmware
No fix yet
CRITICAL 9.8
CVE-2015-7746
NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtain sensitive information from …
Data Ontap
after 8.2.3
HIGH 8.1
CVE-2017-14032
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via …
Mbed Tls
Patch available