Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2011-4051EPSS 69%
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows re…
Web Studio
Patch available
MEDIUM 6.8
CVE-2011-1372
The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obt…
Ts3100 Tape Library Firmware
Mitigation only
HIGH 7.5
CVE-2011-3997
Opengear console servers with firmware before 2.2.1 allow remote attackers to bypass authentication, and modify settings or access connected equipmen…
Opengear Console Server Firmware
after 2.1.0u7
MEDIUM 5.5
CVE-2011-2676
The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require admi…
A Form
after 3.0
HIGH 10.0
CVE-2011-4214
OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges vi…
Aims
Mitigation only
HIGH 7.8
CVE-2011-3297
Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authenticat…
Firewall Services Module Software
Mitigation only
HIGH 7.9
CVE-2011-3298
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…
Adaptive Security Appliance Software
Mitigation only
HIGH 7.5
CVE-2011-2766EPSS 7%
The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing …
Fast Cgi
after 0.73
HIGH 10.0
CVE-2011-3577
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which…
Websphere Commerce
Mitigation only
MEDIUM 5.8
CVE-2011-1411
Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass aut…
Opensaml
after 2.3.1
MEDIUM 5.0
CVE-2011-2762
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) allows remote attackers to bypass authentication via unspecified data associated w…
Lifesize Room Appliance Software
No fix yet
HIGH 7.5
CVE-2011-2733
EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not prevent reuse of authenticatio…
Rsa Adaptive Authentication On Premise
Mitigation only
HIGH 7.5
CVE-2011-2907
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authent…
Torque Resource Manager
after 3.0.1
MEDIUM 5.0
CVE-2011-0527
VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during J…
Tc Server
Mitigation only
MEDIUM 6.8
CVE-2009-5083
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login re…
Tivoli Federated Identity Manager
No fix yet
MEDIUM 5.8
CVE-2011-2701
The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allo…
Freeradius
Patch available
HIGH 10.0
CVE-2011-2963EPSS 8%
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to…
Movicon
Patch available
HIGH 7.8
CVE-2011-2956EPSS 7%
AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of …
Daqfactory
after 5.84
MEDIUM 5.0
CVE-2011-2758
IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for …
Tivoli Directory Server
Mitigation only
MEDIUM 5.0
CVE-2011-2756
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files …
Servicedesk Plus
Mitigation only
MEDIUM 5.0
CVE-2011-1409
Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication an…
Fex
Patch available
HIGH 7.5
CVE-2009-5077
CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SEL…
Cre Loaded
after 6.2
HIGH 7.5
CVE-2009-5076
CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privilege…
Cre Loaded
after 6.2
MEDIUM 5.8
CVE-2011-1766
includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth …
Mediawiki
after 1.16.4
HIGH 7.5
CVE-2011-2155
Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete f…
Smarterstats
Mitigation only
HIGH 7.5
CVE-2011-1901
The mail-filter web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, …
Messaging Security Gateway
after 6.2.0.263
MEDIUM 6.8
CVE-2011-1674
The NetGear ProSafe WNAP210 with firmware 2.0.12 allows remote attackers to bypass authentication and obtain access to the configuration page by visi…
Prosafe Wnap210
Mitigation only
MEDIUM 6.8
CVE-2011-1561
The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentic…
Aix
Mitigation only
HIGH 7.2
CVE-2011-1472
The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified bu…
E75 Firmware
after 211.12
HIGH 7.2
CVE-2011-1520
The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physicall…
Lotus Domino
Mitigation only