Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.0
CVE-2021-43414
An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middl…
Hurd
0.9.20210404-9+
CRITICAL 9.8
CVE-2021-42837
An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the nati…
Data Catalog
7.3-20210930+
HIGH 7.8
CVE-2021-25505
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
Samsung Pass
3.0.02.4+
MEDIUM 5.5
CVE-2021-25506
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
Health
6.19.1.0001+
HIGH 8.1
CVE-2021-38161
Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Ap…
Traffic Server
after 8.0.8
HIGH 7.5
CVE-2021-41312
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to e…
Data Center
8.19.1+
MEDIUM 5.3
CVE-2021-22490
There is a Permission verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect the device performance.
Emui
Mitigation only
HIGH 7.5
CVE-2021-22473
There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
Emui
No fix yet
MEDIUM 5.3
CVE-2021-32951
WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources…
Webaccess\/nms
after 3.0.3
MEDIUM 5.3
CVE-2021-41157
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…
Freeswitch
1.10.6+
HIGH 7.5
CVE-2021-37624
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…
Freeswitch
1.10.7+
HIGH 7.5
CVE-2021-30302
Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, Snapdragon Conne…
Aqt1000 Firmware
Mitigation only
HIGH 7.5
CVE-2021-30312
Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdrago…
Apq8053 Firmware
Patch available
CRITICAL 9.8
CVE-2021-31349
The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change se…
128 Technology Session Smart Router Firmware
4.5.11+
MEDIUM 5.5
CVE-2010-2496
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwor…
Cluster Glue
1.0.6 / 1.1.3+
CRITICAL 9.8
CVE-2021-37123
There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain o…
Hero Ct060 Firmware
1.0.0.200+
HIGH 8.1
CVE-2021-41129
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati…
Panel
1.6.2+
HIGH 7.2
CVE-2021-41126
October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts whi…
October
2.1.12+
MEDIUM 6.0
CVE-2021-25490
A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.
Android
Mitigation only
HIGH 7.8
CVE-2021-0595
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. Thi…
Android
Patch available
HIGH 7.3
CVE-2021-39226 KEVEPSS 100%
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit…
Grafana
7.5.11 / 8.1.6+
HIGH 7.8
CVE-2021-41286
Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the application, the validity of the p…
Multicash
Mitigation only
MEDIUM 6.5
CVE-2021-39872
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLa…
GitLab
14.1.7 / 14.2.5+
CRITICAL 9.8
CVE-2021-23857
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combin…
Rexroth Indramotion Mlc L20 Firmware
after 12
CRITICAL 9.8
CVE-2021-35296
An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie val…
Hg150 Ub Firmware
No fix yet
CRITICAL 9.8
CVE-2021-20578
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m…
Cloud Pak For Security
Patch available
CRITICAL 9.1
CVE-2021-41292
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass aut…
Ecs Router Controller Ecs Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-35943
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password,…
Couchbase Server
6.6.3+
HIGH 7.5
CVE-2021-31606
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
Openvpn Monitor
after 1.1.3
CRITICAL 9.8
CVE-2021-38299
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable servic…
Webauthn Framwork
3.2.9 / 3.3.4+