Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2009-4801
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.
Ez Blog
No fix yet
HIGH 7.5
CVE-2009-4806
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to re…
Digital Interchange Document Library
No fix yet
MEDIUM 5.8
CVE-2010-0744
aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's C…
Alvaros Messenger
after 0.98.3
MEDIUM 5.0
CVE-2010-1221
CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.
Xosoft Content Distribution
Patch available
MEDIUM 5.0
CVE-2010-1222
CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP reques…
Xosoft Content Distribution
Patch available
HIGH 7.5
CVE-2009-2936EPSS 64%
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 doe…
Varnish
Mitigation only
MEDIUM 6.4
CVE-2010-1191
Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable ad…
Sahana
Mitigation only
MEDIUM 5.0
CVE-2010-0521
Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to …
Mac Os X
after 10.6.2
HIGH 7.2
CVE-2010-0498
Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local user…
Mac Os X
after 10.6.2
MEDIUM 6.8
CVE-2010-1097
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain adminis…
Dedecms
No fix yet
MEDIUM 5.8
CVE-2010-1040
The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device su…
Openpne
Mitigation only
HIGH 7.5
CVE-2010-1022
The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication …
T3sec Saltedpw
after 0.2.12
HIGH 10.0
CVE-2010-0447EPSS 5%
The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate reque…
Openview Performance Insight
after 5.4
HIGH 7.5
CVE-2009-4670
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user par…
Roomphplanning
No fix yet
HIGH 7.5
CVE-2009-4671
Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cook…
Roomphplanning
No fix yet
HIGH 7.5
CVE-2009-4675
admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows…
Gastro Portal \(restaurant Directory\) Script
No fix yet
HIGH 7.5
CVE-2009-4657
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting …
Xerver
No fix yet
MEDIUM 5.8
CVE-2010-0756
Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.…
Wikyblog
No fix yet
HIGH 7.5
CVE-2010-0554
The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attacker…
Geo\+\+ Gncaster
after 1.4.0.7
HIGH 7.5
CVE-2009-4584
admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain administrative access via a certai…
Db Masters Multimedia Links Directory
No fix yet
HIGH 7.5
CVE-2009-4447
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.…
Jax Guestbook
No fix yet
MEDIUM 6.8
CVE-2009-4367EPSS 6%
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers …
Staging Module
after 5.4.0
HIGH 10.0
CVE-2009-3027EPSS 11%
VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0…
Backup Exec Continuous Protection Server
Patch available
MEDIUM 5.0
CVE-2009-4232
The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages wit…
Com Kide
Mitigation only
MEDIUM 5.8
CVE-2009-3585
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows …
Rt
Patch available
MEDIUM 5.8
CVE-2009-4151
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows …
Rt
Patch available
HIGH 7.2
CVE-2009-4128
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for phys…
Grub 2
Patch available
HIGH 7.5
CVE-2009-4095
myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party info…
Myphile
Patch available
MEDIUM 5.0
CVE-2009-4089EPSS 7%
telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to aj…
Telepark.wiki
No fix yet
HIGH 7.5
CVE-2009-3966
Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true.
Arcade Trade Script
No fix yet