Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-25165
BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnera…
Alaris 8015 Pcu Firmware
after 9.33.1
HIGH 8.2
CVE-2020-2050
An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to…
Pan Os
8.1.17 / 9.0.11+
CRITICAL 9.8
CVE-2020-26168
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify p…
Hazelcast
4.0.3+
CRITICAL 9.8
CVE-2020-26542
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjuncti…
Percona Server
after 2020-10-02
MEDIUM 5.5
CVE-2020-23139
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized …
Microweber
Mitigation only
CRITICAL 9.8
CVE-2020-26214EPSS 66%
In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to …
Alerta
7.5.7 / 8.1.0+
CRITICAL 9.8
CVE-2020-25592EPSS 58%
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.
Debian Linux
2015.8.10 / 2015.8.13+
CRITICAL 9.8
CVE-2020-17510EPSS 9%
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Shiro
1.7.0+
MEDIUM 5.3
CVE-2020-8267
A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token…
Unifi Protect Firmware
after 1.14.10
CRITICAL 9.8
CVE-2020-12145EPSS 6%
Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This m…
Unity Orchestrator
8.9.11 / 8.10.11+
HIGH 7.5
CVE-2020-15949
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
Immuta
No fix yet
MEDIUM 6.8
CVE-2020-8236
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking…
Nextcloud Server
19.0.2+
MEDIUM 5.3
CVE-2020-28002
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login opt…
Sonarqube
No fix yet
HIGH 7.9
CVE-2020-5425
Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user imper…
Single Sign On For Tanzu
1.11.3 / 1.12.4+
CRITICAL 9.8
CVE-2020-7197
SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web appl…
Storeserv Management Console
3.7.1.1+
HIGH 7.8
CVE-2020-24848
FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local p…
Fruitywifi
after 2.4
MEDIUM 5.8
CVE-2020-3565
A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t…
Secure Firewall Threat Defense
6.4.0.8 / 6.5.0.4+
HIGH 8.1
CVE-2020-3410
A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthentic…
Secure Firewall Management Center
Mitigation only
CRITICAL 9.1
CVE-2020-15240
omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Imp…
Omniauth Auth0
2.4.1+
CRITICAL 9.1
CVE-2020-15269
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in v…
Spree
3.7.11 / 4.0.4+
CRITICAL 9.8
CVE-2020-24629
A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC P…
Intelligent Management Center
7.3+
MEDIUM 6.5
CVE-2020-14299
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox Secur…
Jboss Enterprise Application Platform
5.0.3+
HIGH 8.8
CVE-2020-7591
A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to i…
Siport Mp
3.2.1+
HIGH 8.8
CVE-2020-8350
An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of …
Thinkpad Stack Wireless Router Firmware
after 1.1.3.4
HIGH 8.1
CVE-2020-4779
A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attac…
Curam Social Program Management
Mitigation only
HIGH 8.8
CVE-2020-26921
Certain NETGEAR devices are affected by authentication bypass. This affects GS110EMX before 1.0.1.7, GS810EMX before 1.7.1.3, XS512EM before 1.0.1.3,…
Gs110emx Firmware
1.0.1.3 / 1.0.1.7+
CRITICAL 9.8
CVE-2020-15243
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 …
Smartstore
Mitigation only
HIGH 7.5
CVE-2020-10816
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor …
Manageengine Applications Manager
Mitigation only
MEDIUM 5.3
CVE-2020-25867
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentica…
Soplanning
1.47+
CRITICAL 9.8
CVE-2020-12126
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router s…
Wn530h4 Firmware
Mitigation only