Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2023-52160
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to…
Debian Linux
after 2.10
HIGH 7.5
CVE-2021-36369
An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH …
Debian Linux
after 2020.81
MEDIUM 6.5
CVE-2022-2553
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes …
Debian Linux
after 1.0
CRITICAL 9.8
CVE-2021-40874
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (…
Debian Linux
Patch available
HIGH 8.8
CVE-2022-30550
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver …
Debian Linux
2.4.0+
HIGH 8.8
CVE-2022-1049
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to logi…
Debian Linux
after 0.11.2
CRITICAL 9.8
CVE-2022-0730
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
Debian Linux
No fix yet
HIGH 7.2
CVE-2020-25719
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could b…
Debian Linux
Patch available
MEDIUM 5.9
CVE-2016-2124
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the w…
Debian Linux
Patch available
CRITICAL 9.1
CVE-2021-3850
Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.
Debian Linux
after 5.20.21
MEDIUM 5.3
CVE-2020-26139EPSS 6%
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet s…
Debian Linux
Patch available
MEDIUM 5.3
CVE-2021-30158
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. Thi…
Debian Linux
1.31.12 / 1.35.2+
MEDIUM 5.3
CVE-2020-28896
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was inva…
Debian Linux
2.0.2 / 2020-11-20+
CRITICAL 9.8
CVE-2019-20933EPSS 31%
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may ha…
Debian Linux
1.7.6+
CRITICAL 9.8
CVE-2020-25592EPSS 58%
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.
Debian Linux
2015.8.10 / 2015.8.13+
CRITICAL 9.8
CVE-2014-8650
python-requests-Kerberos through 0.5 does not handle mutual authentication
Debian Linux
after 0.5
CRITICAL 9.8
CVE-2019-11187
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t…
Debian Linux
after 2019-04-11
MEDIUM 6.5
CVE-2018-0505
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
Debian Linux
1.31.1+
CRITICAL 9.8
CVE-2018-16947
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not…
Debian Linux
1.6.23 / 1.8.2+
CRITICAL 9.8
CVE-2017-0356
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker …
Debian Linux
3.20170111+
MEDIUM 5.3
CVE-2016-9646
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572),…
Debian Linux
3.20161229+
HIGH 8.1
CVE-2017-1000433
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without k…
Debian Linux
after 4.4.0
HIGH 8.1
CVE-2017-8028
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP Bind…
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2017-16613EPSS 8%
An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and …
Debian Linux
after 2.15.1
MEDIUM 6.5
CVE-2017-7650
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or rem…
Debian Linux
1.4.12+
CRITICAL 9.8
CVE-2015-7871EPSS 82%
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
Debian Linux
4.2.8 / 4.3.77+
CRITICAL 9.8
CVE-2016-1908EPSS 14%
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-contr…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2016-4422
The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg…
Debian Linux
Mitigation only
HIGH 7.7
CVE-2015-7974EPSS 6%
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remot…
Debian Linux
4.2.8 / 4.3.90+
MEDIUM 5.0
CVE-2013-6890EPSS 9%
denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (in…
Debian Linux
Mitigation only