Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-5909EPSS 5%
License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4…
B\/m 9000 Vp
Mitigation only
CRITICAL 9.8
CVE-2018-19645
An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
Solutions Business Manager
11.5+
CRITICAL 9.8
CVE-2019-6527
PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an …
Pr100088 Modbus Gateway Firmware
Mitigation only
MEDIUM 6.4
CVE-2019-3825
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by select…
Ubuntu Linux
3.31.4+
CRITICAL 10.0
CVE-2018-18505
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and…
Firefox
60.5.0 / 65.0+
CRITICAL 9.8
CVE-2019-6519
WebAccess/SCADA, Version 8.3. An improper authentication vulnerability exists that could allow a possible authentication bypass allowing an attacker …
Webaccess\/scada
Mitigation only
HIGH 8.6
CVE-2019-6521
WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and mani…
Webaccess\/scada
Mitigation only
MEDIUM 5.3
CVE-2018-19000EPSS 9%
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.
Laquis Scada
4.1.0.4150+
MEDIUM 6.5
CVE-2018-17928
The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user au…
Cms 770 Firmware
after 1.7.1
CRITICAL 9.8
CVE-2018-17431EPSS 84%
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.
Unified Threat Management Firewall
2.7.0+
HIGH 7.5
CVE-2018-1668
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "n…
Datapower Gateway
after 7.6.0.11
HIGH 8.8
CVE-2018-19023
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of …
Nova M Firmware
Mitigation only
MEDIUM 6.0
CVE-2019-3584
Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated…
Mvision Endpoint
18.11.31.62+
HIGH 7.8
CVE-2018-20735EPSS 7%
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalatio…
Patrol Agent
after 11.3.01
CRITICAL 9.8
CVE-2018-18814
The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server…
Spotfire Analytics Platform For Aws
after 10.0.0
HIGH 8.1
CVE-2018-16886
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is…
Enterprise Linux Desktop
3.2.26 / 3.3.11+
CRITICAL 9.8
CVE-2017-13889
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validatio…
Mac Os X
10.13.3+
HIGH 8.1
CVE-2018-5403
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authenti…
Securesphere
No fix yet
CRITICAL 9.8
CVE-2018-0669
INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. Th…
Inplc Rt
after 3.08
CRITICAL 9.8
CVE-2018-0670
INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. Th…
Inplc Rt
after 3.08
HIGH 8.8
CVE-2018-0676
BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to bypass authentication to access to the management scre…
Bn Sdwbp3 Firmware
after 1.0.9
CRITICAL 9.8
CVE-2018-20675
D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-8…
Dir 822 Firmware
after 3.10b06
HIGH 7.8
CVE-2019-0543 KEV
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege…
Windows 10 1507
Patch available
HIGH 7.5
CVE-2018-19249
The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing …
Stripe Api
Mitigation only
MEDIUM 6.5
CVE-2018-19505
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act …
Remedy Action Request System Server
No fix yet
MEDIUM 6.6
CVE-2018-19937
A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the ph…
Vlc For Mobile
3.1.5+
HIGH 8.1
CVE-2018-19616EPSS 30%
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because ac…
Powermonitor 1000 Firmware
No fix yet
HIGH 7.8
CVE-2018-17957
The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, a…
Repository Mirroring Tool
1.1.2+
HIGH 8.1
CVE-2018-20422
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_w…
Discuzx
No fix yet
MEDIUM 6.8
CVE-2018-20342
The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This allows attackers with physical a…
Sp012
No fix yet