Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-7847
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which…
Modicon M580 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-6814EPSS 37%
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to con…
Net5501 Firmware
2.1.9.7+
HIGH 8.1
CVE-2019-8443
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows …
Jira
7.13.4 / 8.0.4+
HIGH 7.5
CVE-2019-10911
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker …
Symfony
2.7.51 / 2.8.50+
HIGH 8.1
CVE-2019-8978EPSS 6%
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 an…
Banner Enterprise Identity Services
No fix yet
MEDIUM 5.9
CVE-2019-7218
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline …
Sharefile
after 19.1
CRITICAL 10.0
CVE-2019-1867EPSS 30%
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication o…
Elastic Services Controller
4.5+
HIGH 7.1
CVE-2017-12778
The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorr…
Qbittorrent
No fix yet
CRITICAL 9.8
CVE-2018-13990
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction …
Fl Switch 3005 Firmware
1.35+
HIGH 8.8
CVE-2019-1724
A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Rout…
Rv325 Dual Wan Gigabit Vpn Router Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-3927
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.…
Am 100 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-11576
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send th…
Gitea
1.8.0+
HIGH 8.1
CVE-2019-11488
Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allows Unauthorized Attackers to R…
Simplybook
2019-04-23+
HIGH 8.8
CVE-2018-16219
A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same netwo…
405hd Firmware
No fix yet
CRITICAL 9.8
CVE-2019-11081
A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative access to the application serv…
Sidexis
Mitigation only
HIGH 8.8
CVE-2018-1317
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentica…
Zeppelin
0.8.0+
CRITICAL 9.8
CVE-2019-11234EPSS 8%
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
Fedora
3.0.19+
MEDIUM 6.8
CVE-2019-11015
A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscreen based authentication via t…
Miui
No fix yet
HIGH 7.8
CVE-2018-16877
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could us…
Ubuntu Linux
after 2.0.0
HIGH 7.5
CVE-2018-0382
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software cou…
Wireless Lan Controller Software
Mitigation only
CRITICAL 9.8
CVE-2019-10643
Contao 4.7 allows Use of a Key Past its Expiration Date.
Contao Cms
No fix yet
HIGH 7.5
CVE-2018-7340
Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attack…
Duo Network Gateway
after 1.2.9
HIGH 8.1
CVE-2019-9498
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not va…
Fedora
after 11.1
HIGH 8.1
CVE-2019-9499
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do n…
Fedora
after 11.1
HIGH 7.5
CVE-2019-3798
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote aut…
Capi Release
1.79.0+
HIGH 7.5
CVE-2019-9496
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE conf…
Fedora
after 2.7
HIGH 8.1
CVE-2019-9497
The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. Thi…
Fedora
after 2.7
CRITICAL 9.8
CVE-2017-11427
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attack…
Pythonsaml
after 2.3.0
CRITICAL 9.8
CVE-2017-11428
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacke…
Ruby Saml
after 1.6.0
CRITICAL 9.8
CVE-2017-11429
Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may…
Saml2 Js
after 2.0