Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.3
CVE-2013-1241
The ISM module in Cisco IOS on ISR G2 routers does not properly handle authentication-header packets, which allows remote authenticated users to caus…
iOS
Mitigation only
HIGH 7.5
CVE-2013-1186
Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted auth…
Unified Computing System Infrastructure And Unified Computing System Software
Mitigation only
HIGH 10.0
CVE-2013-3268
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
Imanager
after 2.7
MEDIUM 6.4
CVE-2013-3060EPSS 6%
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cau…
Activemq
after 5.7.0
MEDIUM 5.0
CVE-2013-0282
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain i…
Keystone
after 2012.2.4
HIGH 7.5
CVE-2013-0314
The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, whi…
Jboss Enterprise Portal Platform
Mitigation only
HIGH 7.8
CVE-2013-1150
The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31),…
Adaptive Security Appliance Software
Mitigation only
HIGH 7.8
CVE-2013-1155
The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1…
Firewall Services Module Software
Mitigation only
HIGH 7.5
CVE-2013-2741
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, whic…
Backupbuddy
No fix yet
HIGH 7.5
CVE-2013-2743
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via …
Backupbuddy
No fix yet
HIGH 10.0
CVE-2013-1080EPSS 77%
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/js…
Zenworks Configuration Management
Mitigation only
HIGH 9.3
CVE-2013-0935
EMC Smarts Network Configuration Manager (NCM) before 9.2 does not require authentication for all Java RMI method calls, which allows remote attacker…
Smarts Network Configuration Manager
after 9.1
MEDIUM 6.8
CVE-2013-0258
The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers …
Ga Login
Patch available
HIGH 8.5
CVE-2013-0487
The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration detai…
Lotus Domino
Mitigation only
MEDIUM 6.8
CVE-2013-1865
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remot…
Ubuntu Linux
Mitigation only
MEDIUM 6.8
CVE-2012-4446
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking t…
Qpid
after 0.20
MEDIUM 5.8
CVE-2012-5633EPSS 8%
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Secu…
Cxf
after 2.5.7
MEDIUM 5.0
CVE-2013-0239
Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote att…
Cxf
after 2.5.8
MEDIUM 5.0
CVE-2012-4066
The internal message protocol for Walrus in Eucalyptus 3.2.0 and earlier does not require signatures for unspecified request headers, which allows at…
Eucalyptus
after 3.2.0
HIGH 7.5
CVE-2013-0910
Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization o…
Chrome
after 25.0.1364.126
HIGH 7.1
CVE-2013-1134
The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not req…
Unified Communications Manager
Mitigation only
MEDIUM 5.0
CVE-2012-6274EPSS 47%
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under…
Bigant Im Message Server
Mitigation only
MEDIUM 5.0
CVE-2012-5952
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials befor…
Websphere Message Broker
Mitigation only
HIGH 7.5
CVE-2012-6354
The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain…
San Volume Controller Software
Mitigation only
HIGH 10.0
CVE-2013-1405
VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 bef…
Vcenter Server
Mitigation only
MEDIUM 6.8
CVE-2012-0874EPSS 14%
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (E…
Jboss Enterprise Application Platform
after 5.3.0
CRITICAL 9.8
CVE-2012-6437EPSS 8%
The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, wheth…
Controllogix Controllers
after 1400
HIGH 7.5
CVE-2013-0209EPSS 45%
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration fun…
Movable Type
Patch available
MEDIUM 5.0
CVE-2013-0759
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 a…
Firefox
2.15 / 10.0.12+
CRITICAL 9.8
CVE-2013-0625 KEVEPSS 94%
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbi…
Coldfusion
Mitigation only