Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.8
CVE-2014-3781
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty pa…
Dotclear
after 2.6.2
MEDIUM 5.8
CVE-2014-3944
The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypas…
TYPO3
Mitigation only
MEDIUM 5.0
CVE-2013-0191
libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass…
Libpam Pgsql
Patch available
MEDIUM 5.0
CVE-2013-6470
The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenSt…
Openstack
Mitigation only
HIGH 7.5
CVE-2014-3780
Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspe…
Vdi In A Box
Mitigation only
HIGH 7.5
CVE-2013-6788
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for r…
Bitrix E Store Module
after 14.0.0
MEDIUM 5.0
CVE-2013-4178
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replay…
Ga Login
Mitigation only
MEDIUM 5.0
CVE-2012-6452
Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests dependi…
Email Firewall
after 6.5.0
MEDIUM 6.8
CVE-2014-0214
login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token wi…
Moodle
after 2.3.11
MEDIUM 5.0
CVE-2013-2756EPSS 6%
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypa…
Cloudstack
Patch available
HIGH 8.3
CVE-2014-2938
Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data v…
Faceid F810 Firmware
after 1.007.109
HIGH 7.5
CVE-2013-6765EPSS 7%
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands …
Openvas Manager
Mitigation only
HIGH 7.5
CVE-2013-6766
OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP com…
Openvas Administrator
Mitigation only
MEDIUM 6.8
CVE-2013-6806
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a cr…
Exceed Ondemand
Mitigation only
MEDIUM 6.8
CVE-2013-7379
The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which allows remote at…
Tomato
after 0.0.5
HIGH 7.6
CVE-2014-0643
EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a …
Rsa Netwitness
9.8.5.19 / 10.2.4+
MEDIUM 5.0
CVE-2014-3430
Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attac…
Dovecot
Patch available
MEDIUM 5.5
CVE-2013-4471
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, w…
Horizon
2013.2+
HIGH 7.5
CVE-2013-4552
lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via…
Drupalauth
after 1.2.1
MEDIUM 6.8
CVE-2013-4580
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impe…
GitLab
after 5.4.1
HIGH 9.3
CVE-2013-4772
D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a d…
Dir 826l Wireless N600 Cloud Router Firmware
No fix yet
MEDIUM 6.8
CVE-2014-0090
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
Foreman
after 1.4.1
MEDIUM 6.8
CVE-2014-2181
Cisco Adaptive Security Appliance (ASA) Software allows remote authenticated users to read files by sending a crafted URL to the HTTP server, as demo…
Adaptive Security Appliance Software
Mitigation only
HIGH 7.5
CVE-2014-3139
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to …
Enterprise Backup
No fix yet
MEDIUM 6.8
CVE-2013-7302
Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers a…
Ubercart
Patch available
HIGH 9.3
CVE-2014-0760
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1
Modular Controller with CoDeSys and SoftMotion provide an undocumented
acc…
Codesys Runtime System
Mitigation only
HIGH 9.3
CVE-2014-0769
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication…
Softmotion
Mitigation only
HIGH 7.5
CVE-2014-0188
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remot…
Openshift
after 2.0.5
MEDIUM 5.0
CVE-2012-4658
The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage…
iOS
after 15.1
MEDIUM 6.4
CVE-2012-5032
The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows re…
iOS
after 15.1