Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-15721
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers c…
Harmony Hub Firmware
4.15.206+
HIGH 8.1
CVE-2018-1778
IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is ex…
Api Connect
after 2018.4.1.0
CRITICAL 9.8
CVE-2018-17777
An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000)…
Dva 5592 Firmware
Mitigation only
HIGH 8.1
CVE-2018-13804
A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UA Discrete…
Simatic It Line Monitoring System
Mitigation only
CRITICAL 10.0
CVE-2018-13816
A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although con…
Tim 1531 Irc Firmware
2.0+
HIGH 7.2
CVE-2018-7067
A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of Clea…
Clearpass Policy Manager
6.6.10 / 6.7.6+
CRITICAL 9.8
CVE-2018-14708
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.
5n2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-14709
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure to…
5n2 Firmware
No fix yet
HIGH 8.1
CVE-2018-14637
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th…
Keycloak
4.6.0+
HIGH 7.4
CVE-2018-7958
There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-mid…
Espace 7950 Firmware
Mitigation only
HIGH 7.5
CVE-2018-19458EPSS 33%
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability …
Php Proxy
No fix yet
HIGH 7.8
CVE-2018-16160
SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Windows PC.
Securecore
3.0+
HIGH 8.8
CVE-2018-7358EPSS 90%
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, wh…
Zxhn H168n Firmware
No fix yet
MEDIUM 5.5
CVE-2018-3696
Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative priv…
Raid Web Console 3
4.186+
MEDIUM 6.8
CVE-2018-7910
Some Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.127(C432), 8.0.0.128(C432), 8…
Alp Al00b Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-19076
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…
I5 Application Firmware
No fix yet
CRITICAL 9.8
CVE-2018-17918
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.
Circarlife Firmware
4.3.1+
CRITICAL 9.8
CVE-2018-6908
An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing a…
Mini 8 Firmware
after 4.0.975
HIGH 8.1
CVE-2018-6011
The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2nd generation) uses the admin…
Mini 8 Firmware
after 4.0.975
HIGH 7.5
CVE-2018-18891
MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.
Minicms
No fix yet
MEDIUM 6.5
CVE-2016-2125EPSS 9%
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh…
Gluster Storage
4.3.13 / 4.4.8+
MEDIUM 5.7
CVE-2018-16464
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had change…
Nextcloud Server
14.0.0+
MEDIUM 5.3
CVE-2018-16465
Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor fail…
Nextcloud Server
14.0.0+
MEDIUM 5.3
CVE-2018-16467
A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.
Nextcloud Server
14.0.0+
CRITICAL 9.8
CVE-2016-10732
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-d…
Projectsend
Mitigation only
MEDIUM 6.9
CVE-2018-17923
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may able to repr…
Saga1 L8b Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-15751EPSS 5%
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-a…
Salt
2017.7.8 / 2018.3.3+
CRITICAL 9.8
CVE-2018-12666
SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, whic…
H.264 Poe Ip Camera Firmware
No fix yet
CRITICAL 9.8
CVE-2018-12667
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) is affected by an improper authentication vulnerabili…
H.264 Poe Ip Camera Firmware
No fix yet
CRITICAL 9.8
CVE-2018-1822
IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability t…
Flashsystem 900 Firmware
Patch available