Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-21403
In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacte…
Kongchuanhujiao
1.3.21+
MEDIUM 6.5
CVE-2021-3153
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two…
Terraform Enterprise
after 202102-2
HIGH 7.5
CVE-2021-25368
Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.
Cloud
4.7.0.3+
HIGH 7.5
CVE-2021-22496
Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could caus…
Access Manager
4.5.3.3+
HIGH 7.2
CVE-2021-26070
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via…
Data Center
8.13.3 / 8.14.1+
CRITICAL 9.8
CVE-2021-24148
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unaut…
Mstore Api
3.2.0+
CRITICAL 9.8
CVE-2021-22860
EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote atta…
E Document System
Mitigation only
HIGH 8.2
CVE-2021-21378
Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT…
Envoy
Patch available
HIGH 8.8
CVE-2020-35231
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to by…
Gs116e Firmware
Mitigation only
MEDIUM 6.5
CVE-2020-27838EPSS 18%
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like cli…
Keycloak
13.0.0+
CRITICAL 9.8
CVE-2021-21335
In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a …
Spnego Http Authentication Module
1.1.1+
CRITICAL 9.8
CVE-2021-21329
RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF users with multi factor authentic…
Ratcf
2021-02-26+
CRITICAL 9.1
CVE-2020-28050
Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.
Manageengine Desktop Central
10.0.647+
HIGH 8.2
CVE-2020-5148
SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential atta…
Directory Services Connector
4.1.19+
MEDIUM 5.3
CVE-2021-25347
Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is execu…
Android
No fix yet
HIGH 7.8
CVE-2021-25315
CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute a…
Salt
3002.2+
CRITICAL 9.8
CVE-2021-21513EPSS 6%
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration c…
Openmanage Server Administrator
9.4.0.3 / 9.5.0.1+
MEDIUM 5.3
CVE-2021-3332
WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
Wps Hide Login
No fix yet
CRITICAL 9.8
CVE-2021-25281EPSS 73%
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attac…
Fedora
2015.8.10 / 2015.8.13+
CRITICAL 9.1
CVE-2021-21308
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an atta…
Prestashop
1.7.7.2+
MEDIUM 6.8
CVE-2020-26200
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component…
Endpoint Security
18.0.11.3+
MEDIUM 5.9
CVE-2020-10254
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
Owncloud
10.4.0+
HIGH 8.8
CVE-2021-22858
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obt…
Changjia Property Management System
Mitigation only
MEDIUM 6.5
CVE-2020-27863
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-2888A rou…
Dva 2800 Firmware
Mitigation only
HIGH 8.8
CVE-2020-27865
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 …
Dap 1860 Firmware
after 1.04b03
HIGH 8.8
CVE-2020-27866EPSS 9%
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260,…
Ac2100 Firmware
1.2.0.76+
MEDIUM 6.5
CVE-2020-13185
Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to sp…
Cloud Access Connector
18+
CRITICAL 9.8
CVE-2021-21502
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRI…
Emc Powerscale Onefs
Mitigation only
MEDIUM 5.5
CVE-2020-10048
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verificatio…
Simatic Pcs 7
7.5+
MEDIUM 6.5
CVE-2021-26905
1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key.
Scim Bridge
1.6.2+