Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-1468
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…
Catalyst Sd Wan Manager
20.3.3 / 20.4.1+
CRITICAL 9.8
CVE-2020-19111
Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication…
Online Book Store Project In Php
No fix yet
HIGH 7.5
CVE-2021-20092EPSS 8%
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sen…
Wsr 2533dhpl2 Bk Firmware
after 1.24
CRITICAL 9.8
CVE-2021-27651EPSS 54%
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication chec…
Infinity
after 8.5.2
HIGH 8.1
CVE-2021-25147
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has …
Airwave
8.2.12.1+
CRITICAL 9.8
CVE-2020-21991
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET para…
Dominaplus
after 1.10.77
CRITICAL 9.1
CVE-2021-23365
The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause…
Tyk Identity Broker
1.1.1+
CRITICAL 10.0
CVE-2021-22893 KEVEPSS 47%
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul…
Connect Secure
Mitigation only
HIGH 7.5
CVE-2021-20590
Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 series GT25 model VNC server vers…
Got2000 Gt27 Firmware
after 01.40.000
HIGH 7.5
CVE-2020-28973
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can…
Secvest Wireless Alarm System Fuaa50000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-7856
A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient authen…
Helpcom
11.2020+
HIGH 7.7
CVE-2021-26073
Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for …
Connect Express
6.6.0+
MEDIUM 6.5
CVE-2021-26074
Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring…
Connect Spring Boot
2.1.3+
HIGH 7.2
CVE-2021-20288
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitiz…
Ceph Storage
14.2.21+
HIGH 7.5
CVE-2021-27990
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is…
Appspace
No fix yet
HIGH 7.5
CVE-2021-21399
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the …
Ampache
4.4.1+
HIGH 7.2
CVE-2021-22497
Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.
Netiq Advanced Authentication
6.3+
CRITICAL 9.8
CVE-2021-20020
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
Global Management System
Mitigation only
HIGH 7.8
CVE-2021-25377
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to …
Experience Service
after 10.8.0.4
CRITICAL 9.8
CVE-2021-22507
Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerabilit…
Operations Bridge Manager
Mitigation only
HIGH 8.8
CVE-2021-27522
Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the in…
Learnsite
No fix yet
MEDIUM 6.5
CVE-2021-28174
Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in the URL, remote attackers can g…
Smart Stock Selection
after 2020-06-23
CRITICAL 9.8
CVE-2021-1472EPSS 72%
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbit…
Rv160 Firmware
1.0.01.03 / 1.0.03.21+
MEDIUM 5.3
CVE-2021-30158
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. Thi…
Debian Linux
1.31.12 / 1.35.2+
CRITICAL 9.8
CVE-2021-24175EPSS 14%
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication…
The Plus Addons For Elementor
4.1.7+
HIGH 7.5
CVE-2019-20464
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over …
Smart Hd Wifi Security Camera Ean 2 950004 595317 Firmware
No fix yet
CRITICAL 9.8
CVE-2021-29012
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is inva…
Dma Radius Manager
No fix yet
HIGH 8.1
CVE-2021-23923
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.
Devolutions Server
2020.3+
CRITICAL 9.1
CVE-2021-21982
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network …
Carbon Black Cloud Workload
after 1.0.1
MEDIUM 6.8
CVE-2019-5317
A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.…
Instant
6.5.4.16 / 8.3.0.12+