Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-10804
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain …
Odoo
Patch available
CRITICAL 9.8
CVE-2017-7315
An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router cred…
Hg100r Firmware
No fix yet
CRITICAL 9.8
CVE-2017-6044
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions …
Airlink Raven Xe Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-3216EPSS 5%
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthe…
Ox350 Firmware
No fix yet
MEDIUM 6.5
CVE-2016-10364
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any …
Kibana
Mitigation only
HIGH 7.8
CVE-2015-9030
In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication.
Android
No fix yet
HIGH 8.8
CVE-2016-7830
Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firm…
Pcs Xg100 Firmware
after 1.21
CRITICAL 9.8
CVE-2016-5053
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000.
Lightify Home
after 1.6.1
CRITICAL 9.8
CVE-2015-2888
Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the MySnapCam web service.
Baby Zoom Wifi Monitor Firmware
Mitigation only
HIGH 8.8
CVE-2017-3819
A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 Series, A…
Asr 5000 Series Software
Mitigation only
CRITICAL 9.8
CVE-2017-6409
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Unauthenticated CORBA interfaces permit inappro…
Netbackup
after 8.0
CRITICAL 9.9
CVE-2016-8355
An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-Solis Medication Safety Softwar…
Cadd Solis Medication Safety Software
Mitigation only
CRITICAL 9.8
CVE-2016-9369EPSS 9%
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2…
Nport 5100 Series Firmware
after 3.10
CRITICAL 9.8
CVE-2017-5162EPSS 13%
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to a…
Universal Multifunctional Electric Power Quality Meter Firmware
Mitigation only
CRITICAL 10.0
CVE-2010-5326 KEVEPSS 17%
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote att…
Netweaver Application Server Java
after 7.30
CRITICAL 9.8
CVE-2016-2004EPSS 94%
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors rel…
Data Protector
7.03_108 / 8.15+
HIGH 7.8
CVE-2014-9197
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access con…
Etg3000 Factorycast Hmi Gateway Firmware
Patch available
HIGH 7.5
CVE-2014-9195EPSS 81%
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compli…
Multiprog
No fix yet
HIGH 7.5
CVE-2014-4872EPSS 80%
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary…
Track It\!
No fix yet
MEDIUM 5.0
CVE-2014-2590
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote…
Ruggedcom Rugged Operating System
3.11.0 / 3.11.5+
HIGH 7.8
CVE-2008-6827
The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM…
Altiris Deployment Solution
6.9.355+
HIGH 7.5
CVE-2009-1780
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers t…
Php Recommend
after 1.3
HIGH 10.0
CVE-2007-0956EPSS 30%
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning…
Debian Linux
1.6.1+
HIGH 7.5
CVE-2002-1810
D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, whi…
Dwl 900ap\+ Firmware
Mitigation only