Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.6
CVE-2016-2076
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Iden…
Vcenter Server
after 6.0
CRITICAL 9.8
CVE-2016-0733
The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to by…
Ranger
after 0.5.0
CRITICAL 9.8
CVE-2016-2245EPSS 6%
HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.
Support Assistant
after 8.1.40.3
CRITICAL 9.8
CVE-2016-1329
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardc…
X14j Firmware
2.50+
MEDIUM 5.4
CVE-2016-1307
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it e…
Gs1900 10hp Firmware
2.50+
HIGH 8.1
CVE-2015-7914
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without k…
Moduweb Vision
after 1.5.5
HIGH 7.5
CVE-2015-8269
The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 80…
Smart Toy Bear
Mitigation only
HIGH 7.3
CVE-2016-0755EPSS 9%
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow …
Curl
after 7.46.0
HIGH 8.3
CVE-2015-7521EPSS 6%
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, …
Hive
No fix yet
HIGH 7.7
CVE-2015-7974EPSS 6%
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remot…
Debian Linux
4.2.8 / 4.3.90+
CRITICAL 9.8
CVE-2015-6314
Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change conf…
Wireless Lan Controller Software
Mitigation only
CRITICAL 9.8
CVE-2015-7938
Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors.
Eki 1321 Series Firmware
after 2015-10-06
HIGH 8.3
CVE-2015-6480
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain a…
Oncell Central Manager
after 2.0
HIGH 7.3
CVE-2015-1772EPSS 7%
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.…
Hive
Mitigation only
CRITICAL 9.8
CVE-2015-7755 KEVEPSS 61%
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15…
Screenos
Mitigation only
HIGH 7.5
CVE-2015-6401EPSS 8%
Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspeci…
Epc3928 Docsis 3.0 8x4 Wireless Residential Gateway With Embedded Digital Voice Adapter
No fix yet
HIGH 9.0
CVE-2015-6389
Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH…
Prime Collaboration Assurance
Mitigation only
MEDIUM 5.8
CVE-2015-7285
CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allo…
Gprs Cs2300 R Firmware
No fix yet
HIGH 9.3
CVE-2015-7361
FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for a…
Fortios
Mitigation only
HIGH 7.0
CVE-2015-5649
Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP inj…
Garoon
Mitigation only
MEDIUM 5.0
CVE-2015-5372
The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 c…
Nevisauth
after 4.18.3.0
HIGH 9.3
CVE-2015-6280
The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S before 3.10.6S, 3.11S before…
iOS
Mitigation only
HIGH 10.0
CVE-2015-5998
Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remote attackers to execute arbitr…
Impero Education Pro
after 5008
HIGH 9.4
CVE-2014-9605
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a syst…
Netsweeper
3.1.10 / 4.0.9+
MEDIUM 5.0
CVE-2015-6266
The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote att…
Identity Services Engine Software
Mitigation only
HIGH 7.5
CVE-2014-3612EPSS 7%
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att…
Activemq
Mitigation only
HIGH 7.2
CVE-2015-3775
Apple OS X before 10.10.5 does not properly implement authentication, which allows local users to obtain admin privileges via unspecified vectors.
Mac Os X
after 10.10.4
HIGH 7.5
CVE-2015-1486EPSS 68%
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a…
Endpoint Protection Manager
No fix yet
MEDIUM 5.0
CVE-2015-2978
Webservice-DIC yoyaku_v41 allows remote attackers to bypass authentication and complete a conference-room reservation via unspecified vectors, as dem…
Yoyaku
No fix yet
MEDIUM 5.0
CVE-2015-4453
interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive informa…
Openemr
Patch available