Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-12664
A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs…
Ios Xe
Mitigation only
MEDIUM 6.6
CVE-2019-14239
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can…
Kinetis Kv1x Firmware
No fix yet
MEDIUM 6.6
CVE-2019-14238
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug pr…
Stm32l0 Firmware
No fix yet
CRITICAL 10.0
CVE-2019-16649
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows c…
X11dai N Firmware
Mitigation only
HIGH 8.3
CVE-2019-6832
A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known…
Wiser For Knx Firmware
2.4.0+
MEDIUM 6.5
CVE-2016-10983
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
Ghost
0.5.6+
CRITICAL 9.1
CVE-2019-16261
Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by chang…
Pdumh15at Firmware
No fix yet
HIGH 7.5
CVE-2019-16250
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading …
Ocean Extra
after 1.5.8
CRITICAL 9.8
CVE-2019-16190
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication B…
Dir 868l Firmware
after 2.03
HIGH 7.2
CVE-2019-5473
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.
GitLab
No fix yet
CRITICAL 9.8
CVE-2019-12405
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.…
Traffic Control
Mitigation only
CRITICAL 9.8
CVE-2019-13188
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
Knowage
6.4+
MEDIUM 5.3
CVE-2019-13190
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
Knowage
after 6.1.1
MEDIUM 6.5
CVE-2019-13361
Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.
W100 Firmware
No fix yet
HIGH 8.8
CVE-2019-13526
Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker to remotely…
Av7000 Firmware
4.6.0.0+
CRITICAL 9.8
CVE-2019-11064
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration…
Vd 1 Firmware
after 230
CRITICAL 10.0
CVE-2019-12643EPSS 5%
A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass a…
Ios Xe
Mitigation only
MEDIUM 6.5
CVE-2019-15648
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a …
Insert Or Embed Articulate Content
4.29991+
HIGH 8.8
CVE-2019-13423
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserv…
Search Guard
5.6.8-7 / 6.2.3-12+
CRITICAL 9.8
CVE-2014-10389
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
Wp Support Plus Responsive Ticket System
4.2+
CRITICAL 9.8
CVE-2019-1937EPSS 76%
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D…
Integrated Management Controller Supervisor
after 6.7.1.0
CRITICAL 9.8
CVE-2019-1938
A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticate…
Ucs Director
Mitigation only
CRITICAL 9.8
CVE-2019-1974
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D…
Integrated Management Controller Supervisor
after 6.7.2.0
CRITICAL 9.1
CVE-2019-6143
Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vul…
Next Generation Firewall
6.4.7 / 6.5.4+
CRITICAL 9.8
CVE-2019-11187
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t…
Debian Linux
after 2019-04-11
MEDIUM 6.5
CVE-2018-14008
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
Eos
after 4.21.0f
HIGH 7.5
CVE-2019-15046EPSS 5%
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, a…
Manageengine Servicedesk Plus
10509+
HIGH 7.8
CVE-2019-5223
PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation of user-mo…
Pcmanager
Mitigation only
CRITICAL 9.8
CVE-2019-14985EPSS 8%
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,…
Homematic Ccu2 Firmware
No fix yet
HIGH 7.5
CVE-2018-20954
The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys.
Mailpile
Patch available