Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-10539
An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted …
Epikur
20.1.1+
CRITICAL 9.8
CVE-2020-17523EPSS 86%
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Shiro
1.7.1+
HIGH 7.5
CVE-2021-3282
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication…
Vault
Mitigation only
CRITICAL 9.8
CVE-2020-15835
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the …
Mofi4500 4gxelte Firmware
Patch available
CRITICAL 9.8
CVE-2020-13859
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - Ope…
Mofi4500 4gxelte Firmware
Patch available
MEDIUM 6.5
CVE-2021-25910
Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in…
4cct Ea6 334126bf Firmware
Mitigation only
HIGH 7.5
CVE-2021-26117EPSS 11%
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior…
Activemq
2.16.0 / 5.15.14+
HIGH 7.8
CVE-2021-3297EPSS 21%
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
Nbg2105 Firmware
No fix yet
HIGH 8.8
CVE-2021-25863
Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
Open5gs
No fix yet
HIGH 7.5
CVE-2020-28874
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not proper…
Projectsend
Patch available
HIGH 7.8
CVE-2020-4983
IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitr…
Spectrum Lsf
Patch available
MEDIUM 6.5
CVE-2020-27266
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and A…
Anydana A Firmware
3.0+
HIGH 7.5
CVE-2020-24641
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully ex…
Airwave Glass
1.3.3+
MEDIUM 6.5
CVE-2021-22171
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click …
GitLab
13.5.6 / 13.6.4+
CRITICAL 9.8
CVE-2020-27488
Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the …
Miniserver Gen 1 Firmware
11.1.9.3+
HIGH 7.5
CVE-2020-5686
Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker …
Univerge Sv9500 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-5633
Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Expr…
Baseboard Management Controller
after 1.09
MEDIUM 5.5
CVE-2021-1725
Bot Framework SDK Information Disclosure Vulnerability
Bot Framework Software Development Kit
No fix yet
HIGH 7.5
CVE-2020-36176
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing acco…
Ithemes Security
7.7.0+
CRITICAL 9.8
CVE-2012-10001
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attacker…
Limit Login Attempts
1.7.1+
CRITICAL 9.8
CVE-2020-35219
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication vi…
Dsl N17u Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-25848
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
Msr45 Isherlock Antispam
4.5-114 / 4.5-122+
HIGH 8.8
CVE-2020-35785
NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-2020-0365).
Dgn2200 Firmware
1.0.0.60+
HIGH 7.8
CVE-2020-9207
There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. A…
Cloudengine 12800 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-26030
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configure…
Zammad
3.4.1+
CRITICAL 9.8
CVE-2020-24675
In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ H…
Symphony \+ Historian
Mitigation only
HIGH 8.8
CVE-2020-24579EPSS 10%
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authenticati…
Dsl2888a Firmware
No fix yet
HIGH 7.5
CVE-2020-27254
Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper aut…
X Stream Enhanced Xegp Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-27780
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM…
Linux Pam
1.5.1+
CRITICAL 9.8
CVE-2020-8465
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combinat…
Interscan Web Security Virtual Appliance
No fix yet