Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2017-10709
The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressin…
Android
Mitigation only
CRITICAL 9.8
CVE-2017-6034EPSS 5%
An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted i…
Modbus Firmware
No fix yet
CRITICAL 9.8
CVE-2015-1778
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and pass…
Opendaylight
Patch available
CRITICAL 9.8
CVE-2017-4989
In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypa…
Avamar Server
Mitigation only
CRITICAL 9.8
CVE-2017-3167EPSS 20%
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication p…
HTTP Server
2.2.33 / 2.4.26+
HIGH 7.8
CVE-2017-3745
In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password …
Xclarity Administrator
after 1.2.2
HIGH 7.8
CVE-2017-9552
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology …
Photo Station
Mitigation only
CRITICAL 9.8
CVE-2017-9542EPSS 5%
D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to val…
Dir 615 Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-7836 KEVEPSS 19%
SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the mana…
Skysea Client View
after 11.221.03
HIGH 7.5
CVE-2015-2800
The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH012 and S7700, S9300, and S97…
S5700 Firmware
Mitigation only
HIGH 7.5
CVE-2017-7314
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of databa…
Personify360 E Business
after 7.6.1
MEDIUM 5.5
CVE-2014-8180
MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can caus…
MongoDB
Patch available
HIGH 7.8
CVE-2014-9952
In the Secure File System in all Android releases from CAF using the Linux kernel, a capture-replay vulnerability could potentially exist.
Android
Patch available
CRITICAL 9.8
CVE-2017-9148
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably …
Freeradius
Mitigation only
HIGH 7.3
CVE-2014-0097
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows…
Spring Security
Mitigation only
CRITICAL 9.8
CVE-2014-3527
When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authent…
Spring Security
Mitigation only
HIGH 8.1
CVE-2015-6817
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.
Pgbouncer
Patch available
HIGH 8.8
CVE-2017-9100EPSS 85%
login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the…
Dir 600m Firmware
No fix yet
MEDIUM 6.8
CVE-2017-8879
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to ob…
Dolibarr Erp\/crm
No fix yet
CRITICAL 9.1
CVE-2017-8827
forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibl…
Genixcms
Patch available
CRITICAL 9.8
CVE-2017-7909
A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses…
Mesr901 Firmware
after 1.5.2
CRITICAL 9.8
CVE-2017-7921 KEVEPSS 100%
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5…
Ds 2cd2032 I Firmware
Patch available
MEDIUM 5.3
CVE-2017-6624
A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthoriz…
iOS
Mitigation only
HIGH 8.8
CVE-2017-8403
360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, whi…
4k Camera Firmware
Mitigation only
HIGH 7.3
CVE-2017-2101
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to perform arb…
Appgoat
after 3.0.0
HIGH 7.5
CVE-2017-8223
On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via …
Wireless Ip Camera \(p2p\) Firmware
No fix yet
HIGH 8.3
CVE-2017-2319
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromi…
Northstar Controller
after 2.1.0
MEDIUM 6.2
CVE-2017-2329
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an …
Northstar Controller
after 2.1.0
HIGH 8.8
CVE-2017-2332
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a m…
Northstar Controller
after 2.1.0
MEDIUM 5.3
CVE-2017-8078
On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This af…
Tl Sg108e Firmware
No fix yet