Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2011-1519EPSS 9%
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname speci…
Lotus Domino
Mitigation only
MEDIUM 6.8
CVE-2011-1025
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attack…
Openldap
Patch available
MEDIUM 6.8
CVE-2011-0438
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass au…
Nss Pam Ldapd
Patch available
MEDIUM 5.0
CVE-2011-0435
Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which …
Domain Technologie Control
after 0.32.8
MEDIUM 5.8
CVE-2011-0718
Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to cond…
Network Satellite Server
Mitigation only
HIGH 7.5
CVE-2011-0392
Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers…
Telepresence Recording Server Software
Mitigation only
HIGH 7.5
CVE-2011-0380
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP req…
Telepresence Manager
Mitigation only
HIGH 10.0
CVE-2011-0383EPSS 6%
The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (…
Telepresence Recording Server Software
Mitigation only
HIGH 10.0
CVE-2011-0384EPSS 6%
The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require admin…
Telepresence Multipoint Switch Software
Mitigation only
MEDIUM 5.0
CVE-2011-0453
F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obta…
Internet Gatekeeper
Patch available
HIGH 7.2
CVE-2011-0039
The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authenticati…
Windows 2003 Server
Mitigation only
HIGH 9.3
CVE-2011-0920EPSS 10%
The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to by…
Lotus Domino
Mitigation only
HIGH 9.3
CVE-2011-0688
Intel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Cente…
Antivirus
Mitigation only
HIGH 7.5
CVE-2011-0489EPSS 13%
The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data,…
Objectivity\/db
No fix yet
MEDIUM 5.0
CVE-2010-4690
The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly …
Adaptive Security Appliance Software
after 8.3
HIGH 9.3
CVE-2010-4573
The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows …
Esxi
Mitigation only
HIGH 7.5
CVE-2010-3905
The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attacke…
Eucalyptus
Mitigation only
HIGH 7.5
CVE-2010-4332EPSS 7%
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values…
Pointter Php Content Management System
No fix yet
HIGH 7.5
CVE-2010-4333EPSS 7%
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary va…
Pointter Php Micro Blogging Social Network
No fix yet
MEDIUM 5.0
CVE-2010-4481
phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, …
phpMyAdmin
after 3.3.9.0
MEDIUM 5.0
CVE-2010-4488
Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (appl…
Chrome
after 8.0.552.214
CRITICAL 9.8
CVE-2010-4478
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attacke…
Openssh
after 5.6
HIGH 10.0
CVE-2010-4279EPSS 66%
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypa…
Pandora Fms
after 3.1
MEDIUM 5.8
CVE-2010-3868
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, w…
Certificate System
Patch available
HIGH 10.0
CVE-2010-4232
The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 all…
Cmnc 200 Firmware
No fix yet
HIGH 7.5
CVE-2010-3896
The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers …
Omnifind
No fix yet
MEDIUM 6.4
CVE-2010-3852
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easie…
Luci
after 0.22.4
HIGH 7.5
CVE-2010-4121
The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows…
Tivoli Provisioning Manager Os Deployment
Mitigation only
HIGH 7.5
CVE-2008-7263
ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attacke…
Pyftpdlib
after 0.4.0
HIGH 7.5
CVE-2007-6737
FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which mak…
Pyftpdlib
after 0.1.1