Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2016-6434
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CL…
Secure Firewall Management Center
No fix yet
CRITICAL 9.8
CVE-2016-5686
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a …
Onetouch Ping Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-5086
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
Onetouch Ping Firmware
Mitigation only
HIGH 7.5
CVE-2016-7141EPSS 8%
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authen…
Leap
after 7.50.1
HIGH 8.1
CVE-2016-7191EPSS 29%
The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize th…
Azure Active Directory Passport
Patch available
HIGH 7.5
CVE-2016-6159
The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and…
Ws331a Router Firmware
Mitigation only
MEDIUM 6.5
CVE-2016-4966
The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via v…
Fortiwan
after 4.2.4
HIGH 7.3
CVE-2016-4860
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers…
Stardom Fcn\/fcj
Mitigation only
CRITICAL 9.8
CVE-2016-0883
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installa…
Operations Manager
after 1.5.13
CRITICAL 9.8
CVE-2016-1279
J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 1…
Junos
after 12.1x46
HIGH 8.8
CVE-2016-7114
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP …
En100 Ethernet Module Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-7112
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP …
En100 Ethernet Module Firmware
after 4.28
HIGH 8.1
CVE-2016-6377
Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and ma…
Media Origination System Suite
Mitigation only
HIGH 8.8
CVE-2015-6397
Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obt…
Rv110w Wireless N Vpn Firewall Firmware
Mitigation only
HIGH 7.8
CVE-2016-1278
Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a…
Junos
after 12.1x46
MEDIUM 5.3
CVE-2016-5133
Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a prox…
Chrome
after 51.0.2704.106
CRITICAL 9.8
CVE-2016-4503
Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings and data, via vectors relate…
Device Server Web Console 5232 N Firmware
Mitigation only
HIGH 7.5
CVE-2016-4953EPSS 17%
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypt…
Ntp
4.2.8 / 4.3.93+
HIGH 7.5
CVE-2016-1427
The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remo…
Prime Network Registrar
Mitigation only
MEDIUM 6.5
CVE-2016-3085
Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl…
Cloudstack
No fix yet
CRITICAL 9.8
CVE-2016-0916EPSS 8%
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary…
Networker
8.2.2.6 / 9.0.0.6+
CRITICAL 9.1
CVE-2016-4510EPSS 20%
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbit…
Vtscada
Mitigation only
CRITICAL 9.1
CVE-2016-4432EPSS 8%
The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons…
Qpid Broker J
6.0.3+
MEDIUM 5.9
CVE-2016-3094EPSS 8%
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a…
Qpid Broker J
after 6.0.2
HIGH 7.5
CVE-2016-2286
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 …
Miineport E2 1242 Firmware
Mitigation only
HIGH 7.5
CVE-2016-1402
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorizati…
Identity Services Engine Software
Mitigation only
MEDIUM 6.5
CVE-2016-2012
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors.
Network Node Manager I
Patch available
CRITICAL 9.8
CVE-2016-4422
The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg…
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2016-1387
The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8…
Telepresence Tc Software
Mitigation only
MEDIUM 6.5
CVE-2016-2300
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.
Integraxor
after 4.2.4502