Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-12698
An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible a…
Webaccess
after 8.2
HIGH 8.8
CVE-2015-8332
Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows r…
Vcm5010 Firmware
Mitigation only
CRITICAL 9.8
CVE-2015-1401
Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
Ldap \/ Sso Authentication
Mitigation only
HIGH 7.4
CVE-2017-7930
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws …
Pi Data Archive
after 3.4.410.1256
MEDIUM 5.9
CVE-2017-7934
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older prot…
Pi Data Archive
after 3.4.410.1256
CRITICAL 9.8
CVE-2014-7857EPSS 15%
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and …
Dns 322l Firmware
after 2.00b07
CRITICAL 9.8
CVE-2014-7858EPSS 15%
The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username c…
Dnr 326 Firmware
after 1.40b03
MEDIUM 5.3
CVE-2014-7860EPSS 10%
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which …
Dns 327l Firmware
after 1.03b04
HIGH 8.1
CVE-2015-3206
The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a…
Pykerberos
Patch available
HIGH 7.8
CVE-2015-8308
LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.
Lxdm
after 0.5.1
MEDIUM 5.3
CVE-2016-2102
HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.
Haproxy
No fix yet
CRITICAL 9.8
CVE-2016-4460EPSS 6%
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
Pony Mail
Patch available
HIGH 8.8
CVE-2017-7557
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
Dnsdist
Patch available
CRITICAL 9.8
CVE-2017-7420
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterpr…
Enterprise Developer
after 2.3
CRITICAL 9.8
CVE-2015-4464
Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server.
Kg Sha104 Firmware
No fix yet
MEDIUM 5.3
CVE-2017-6781
A vulnerability in the management of shell user accounts for Cisco Policy Suite (CPS) Software for CPS appliances could allow an authenticated, local…
Policy Suite
Mitigation only
CRITICAL 9.8
CVE-2017-7546EPSS 62%
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain …
PostgreSQL
Mitigation only
CRITICAL 9.8
CVE-2015-6816
ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
Fedora
after 3.7.0
HIGH 8.8
CVE-2017-9370
An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legi…
Workspaces
Mitigation only
CRITICAL 9.8
CVE-2012-0803
The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as pa…
Cxf
Patch available
CRITICAL 9.8
CVE-2017-11151EPSS 16%
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files wi…
Photo Station
after 6.7.2-3429
CRITICAL 9.8
CVE-2017-6869
A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user …
Viewport For Web Office Portal
Mitigation only
MEDIUM 5.4
CVE-2017-6871
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Andr…
Simatic Wincc Sm\@rtclient
after 1.0.2.1
CRITICAL 9.8
CVE-2017-9939
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPas…
Sipass Integrated
after 2.65
CRITICAL 9.8
CVE-2015-7871EPSS 82%
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
Debian Linux
4.2.8 / 4.3.77+
CRITICAL 9.8
CVE-2017-12477EPSS 68%
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which it…
Unitrends Backup
10.0+
CRITICAL 9.8
CVE-2017-12478EPSS 78%
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not…
Unitrends Backup
10.0+
HIGH 7.5
CVE-2017-7920
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versi…
Vsn300 Firmware
after 1.8.15
CRITICAL 9.4
CVE-2017-9630
An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash…
Laserwash G5 Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-6747EPSS 5%
A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local …
Identity Services Engine
Mitigation only