Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-16088
iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key mat…
OpenBSD
after 6.7
CRITICAL 9.8
CVE-2020-12812 KEVEPSS 49%
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succe…
Fortios
6.0.10 / 6.2.4+
HIGH 8.8
CVE-2020-8207
Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic upd…
Workspace
Mitigation only
CRITICAL 9.8
CVE-2020-15921EPSS 18%
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as …
Eframework
after 2.9.0
HIGH 7.5
CVE-2020-10918
This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen pa…
C More Hmi Ea9 Firmware
Mitigation only
MEDIUM 6.8
CVE-2020-12638
An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK dev…
Esp Idf
after 4.2
HIGH 7.5
CVE-2020-15896
An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessi…
Dap 1522 Firmware
Patch available
CRITICAL 9.8
CVE-2020-6871
The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server a…
R8500g4 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-14485
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a sessio…
Openclinic Ga
Mitigation only
CRITICAL 9.8
CVE-2020-14494
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to prot…
Openclinic Ga
Mitigation only
MEDIUM 6.5
CVE-2020-9259
Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerability. The system does not su…
Honor V30 Firmware
10.1.0.212+
HIGH 7.8
CVE-2020-3388
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands that are execut…
Sd Wan Firmware
19.2.2 / 20.1.1+
MEDIUM 5.3
CVE-2020-3197
A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Re…
Meeting Server
Mitigation only
CRITICAL 9.8
CVE-2020-3144
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction …
Rv110w Firmware
1.0.3.55 / 1.2.2.8+
CRITICAL 9.8
CVE-2020-15027
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attem…
Automate
2019.12+
CRITICAL 9.8
CVE-2020-10288
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can inpu…
Robotware
Mitigation only
MEDIUM 6.5
CVE-2020-8193 KEVEPSS 88%
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW…
Application Delivery Controller Firmware
10.2.7 / 10.5-70.18+
MEDIUM 5.5
CVE-2020-1838
HUAWEI Mate 30 Pro with versions earlier than 10.1.0.150(C00E136R5P3) have is an improper authentication vulnerability. The device does not sufficien…
Mate 30 Pro Firmware
10.1.0.150+
CRITICAL 9.8
CVE-2020-4074
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and e…
Prestashop
1.7.6.6+
CRITICAL 9.8
CVE-2020-3297
A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, …
Sg250x 24 Firmware
2.5.5.47+
CRITICAL 9.8
CVE-2020-14070
An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessable credentials to admin/execut…
Mk Auth
Mitigation only
MEDIUM 5.3
CVE-2019-20412
The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following in…
Jira
7.13.9 / 8.4.2+
HIGH 8.1
CVE-2017-18906
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody el…
Mattermost Server
3.9.2 / 3.10.2+
CRITICAL 9.8
CVE-2017-18908
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-ma…
Mattermost Server
3.9.2 / 3.10.2+
MEDIUM 5.3
CVE-2017-18919
An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.
Mattermost Server
3.6.3+
MEDIUM 6.5
CVE-2016-11072
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
Mattermost Server
3.0.2+
CRITICAL 9.8
CVE-2016-11074
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
Mattermost Server
3.0.0+
HIGH 8.8
CVE-2018-21263
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a craft…
Mattermost Server
4.5.2 / 4.6.2+
MEDIUM 5.3
CVE-2019-20875
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is…
Mattermost Server
4.10.8 / 5.7.3+
MEDIUM 6.5
CVE-2020-14455
An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-20…
Mattermost Desktop
4.4.0+