Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2021-37697
tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code that allows any user to access…
Tmerc Cogs
3.0+
MEDIUM 6.5
CVE-2021-37696
tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code that allows any user to access…
Tmerc Cogs
3.0+
CRITICAL 9.8
CVE-2020-25563
In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTask…
Sapphireims
No fix yet
CRITICAL 9.8
CVE-2020-25566
In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not requ…
Sapphireims
No fix yet
CRITICAL 9.8
CVE-2021-37843
The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no othe…
Saml Single Sign On
2.5.9 / 3.5.6+
CRITICAL 9.8
CVE-2020-36239EPSS 47%
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.1…
Jira Data Center
4.5.16 / 4.13.8+
HIGH 7.5
CVE-2021-32794
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /…
Archisteamfarm
5.1.2.4+
HIGH 7.2
CVE-2020-7389
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by t…
Syracuse
9.22.7.2 / 11.25.2.6+
CRITICAL 9.8
CVE-2021-22772
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 …
T200i Firmware
Mitigation only
MEDIUM 5.7
CVE-2021-22784EPSS 12%
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a…
C Bus Toolkit
1.15.9+
HIGH 7.5
CVE-2020-21934
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed.
Cx2 Firmware
No fix yet
MEDIUM 5.3
CVE-2020-21936
An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSett…
Cx2 Firmware
No fix yet
CRITICAL 9.8
CVE-2021-36124
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive res…
Sharecare
Mitigation only
CRITICAL 9.8
CVE-2021-28809EPSS 16%
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attack…
Hybrid Backup Sync
3.0.210506 / 3.0.210507+
HIGH 7.5
CVE-2021-20474
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity o…
Guardium Data Encryption
Patch available
CRITICAL 9.8
CVE-2021-33221EPSS 56%
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
Ruckus Iot Controller
after 1.7.1.0
CRITICAL 9.8
CVE-2021-34621EPSS 69%
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it …
Profilepress
after 3.1.3
MEDIUM 5.4
CVE-2021-20107
There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS…
Optima Eaf 100 Firmware
No fix yet
HIGH 7.5
CVE-2021-35941EPSS 13%
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory re…
Wd My Book Live Firmware
No fix yet
CRITICAL 9.8
CVE-2021-31337
The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote …
Sinamics Sl150 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-33346
There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the …
Dsl 2888a Firmware
No fix yet
HIGH 7.4
CVE-2021-32700
Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha…
Ballerina
1.2.14+
MEDIUM 5.3
CVE-2020-20472
White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication oper…
White Shark Systems
No fix yet
CRITICAL 9.8
CVE-2021-32930EPSS 8%
The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute ar…
Iview
5.7.03.6182+
CRITICAL 9.1
CVE-2021-23847
A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or chang…
Cpp6 Firmware
7.80.0129+
MEDIUM 6.8
CVE-2021-26928
BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for e…
Bird
after 2.0.7
MEDIUM 6.8
CVE-2021-22316
There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby …
Emui
Mitigation only
HIGH 7.5
CVE-2021-22322
There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair …
Emui
Mitigation only
MEDIUM 5.4
CVE-2020-25634
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive informa…
3scale
2.10.0+
CRITICAL 9.8
CVE-2021-21986EPSS 13%
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Li…
Vcenter Server
3.10.2.1 / 4.2.1+