Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2015-1330
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in…
Ubuntu Linux
after 0.86
HIGH 7.5
CVE-2014-4882
Aptexx Resident Anywhere does not require authentication, which allows remote attackers to obtain sensitive information or modify data via a direct r…
Resident Anywhere
Mitigation only
HIGH 7.5
CVE-2015-2117EPSS 9%
HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1…
Tippingpoint Security Management System
after 4.2
MEDIUM 6.8
CVE-2015-2823
Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Up…
Wincc
after 13.0
HIGH 10.0
CVE-2015-0198
IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows …
General Parallel File System
Patch available
MEDIUM 6.4
CVE-2015-0670
The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows re…
Spa500 Firmware
Mitigation only
HIGH 10.0
CVE-2015-0653
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before…
Expressway Software
Mitigation only
HIGH 10.0
CVE-2015-2033
Anyterm Daemon in Infoblox Network Automation NetMRI before NETMRI-23483 allows remote attackers to execute arbitrary commands with root privileges v…
Netmri
after 6.8.2.11
MEDIUM 5.0
CVE-2014-9045
The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requ…
Owncloud
after 5.0.17
MEDIUM 5.0
CVE-2014-9043
The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers…
Owncloud
after 5.0.17
MEDIUM 5.0
CVE-2014-8033
The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID…
Webex Meetings Server
Mitigation only
MEDIUM 5.0
CVE-2014-9578
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain l…
Vdg Sense
No fix yet
HIGH 7.5
CVE-2013-4793
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require…
Umbraco Cms
after 6.0.3
HIGH 8.5
CVE-2014-7879
HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configuration includes libpam_updbe, allows remote authenticated users to bypass authentication,…
Hp Ux
Patch available
MEDIUM 5.0
CVE-2014-7807
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, …
Cloudstack
Mitigation only
MEDIUM 5.0
CVE-2014-9217
Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.
Graylog2
after 0.91.3
MEDIUM 5.0
CVE-2014-4631
RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authent…
Rsa Adaptive Authentication On Premise
Mitigation only
MEDIUM 5.0
CVE-2014-9184
ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) …
Zxdsl
No fix yet
HIGH 7.8
CVE-2014-8424EPSS 60%
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.
Vap2500 Firmware
after 08.41
MEDIUM 5.8
CVE-2014-4831
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2…
Qradar Risk Manager
Patch available
HIGH 7.5
CVE-2014-2373
The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors…
Axm Net
Patch available
MEDIUM 6.8
CVE-2014-8472
CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assi…
Cloud Service Management
after 2014
MEDIUM 5.0
CVE-2014-3623EPSS 9%
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does …
Wss4j
1.6.17 / 2.0.2+
HIGH 7.5
CVE-2014-8522
The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers t…
Network Data Loss Prevention
after 9.2.2
MEDIUM 5.0
CVE-2014-8763
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password sta…
Dokuwiki
after 2014-05-05a
MEDIUM 5.0
CVE-2014-8764
DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user na…
Mageia
after 2013-12-08
MEDIUM 5.0
CVE-2014-8088
The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to …
Zend Framework
after 1.12.7
MEDIUM 5.0
CVE-2014-6387
gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers a…
Mantisbt
after 1.2.17
HIGH 10.0
CVE-2014-8329
Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which…
Technik Microcontrol Firmware
after 1.7.0
MEDIUM 6.5
CVE-2014-2062
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to reta…
Jenkins
after 1.550