CVE-2024-4990 | HIGH | 8.1 | 0.79528 | 60.23 | No | No | 2025-03-20 | 2025-03-20 | euvd | In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that th…In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration. This allows an attacker to instantiate arbitrary classes, passing parameters to their constructors and invoking setter methods. Depending on the installed dependencies, various types of attacks are possible, including the execution of arbitrary code, retrieval of sensitive information, and unauthorized access. |
CVE-2022-0028 | HIGH | 8.6 | 0.02366 | 60.23 | Yes | No | 2022-08-22 | 2022-08-22 | cisa.gov, euvd | A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TC…A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. |
CVE-2022-24682 | MEDIUM | 6.1 | 0.30931 | 60.23 | Yes | No | 2022-02-25 | 2022-02-25 | cisa.gov, euvd, nvd | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker…Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code. |
CVE-2021-26424 | CRITICAL | 9.9 | 0.58898 | 60.21 | No | No | 2021-08-12 | 2024-08-03 | euvd | Windows TCP/IP Remote Code Execution VulnerabilityWindows TCP/IP Remote Code Execution Vulnerability |
CVE-2021-38648 | HIGH | 7.8 | 0.11424 | 60.2 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privileg…Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. |
CVE-2025-30154 | HIGH | 8.6 | 0.02296 | 60.2 | Yes | No | 2025-03-24 | 2025-03-24 | cisa.gov, euvd | reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow…reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs. |
CVE-2016-3351 | MEDIUM | 6.5 | 0.26286 | 60.2 | Yes | No | 2022-05-24 | 2022-05-24 | cisa.gov, euvd | An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The…An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer. |
CVE-2026-45659 | HIGH | 8.0 | 0.0912 | 60.19 | Yes | Yes | 2026-07-07 | 2026-07-06 | cisa.gov, cnvd, euvd, nvd, packetstorm | Microsoft Office SharePoint is an enterprise content collaboration and document management platform of Microsoft Corporation in the United S…Microsoft Office SharePoint is an enterprise content collaboration and document management platform of Microsoft Corporation in the United States. There is a security vulnerability in Microsoft Office SharePoint. An attacker could exploit this vulnerability to execute code over the network. |
CVE-2023-38180 | HIGH | 7.5 | 0.1481 | 60.18 | Yes | No | 2023-08-09 | 2023-08-09 | cisa.gov, euvd | Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS). |
CVE-2022-34753 | HIGH | 8.8 | 0.71284 | 60.15 | No | No | 2022-07-13 | 2024-09-16 | euvd | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause r…A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior) |
CVE-2024-2961 | HIGH | 7.3 | 0.8833 | 60.12 | No | Yes | 2024-04-17 | 2026-07-14 | euvd, github | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converti…The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable. |
CVE-2025-24799 | HIGH | 7.5 | 0.86067 | 60.12 | No | No | 2025-03-18 | 2025-03-18 | euvd | GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint.…GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18. |
CVE-2017-0005 | HIGH | 7.8 | 0.11022 | 60.06 | Yes | No | 2022-05-24 | 2022-05-24 | cisa.gov, euvd | The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application. |
CVE-2024-24992 | HIGH | 8.8 | 0.70908 | 60.02 | No | No | 2024-04-19 | 2025-01-07 | euvd | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary…A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. |
CVE-2021-35215 | HIGH | 8.9 | 0.69731 | 60.01 | No | No | 2021-09-01 | 2024-09-16 | euvd | Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to…Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability. |
CVE-2023-23376 | HIGH | 7.8 | 0.10853 | 60.0 | Yes | No | 2023-02-14 | 2023-02-14 | cisa.gov, euvd, nvd | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2022-2143 | CRITICAL | 9.8 | 0.59406 | 59.99 | No | No | 2022-07-22 | 2025-04-16 | euvd | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. |
CVE-2022-2560 | HIGH | 8.2 | 0.77688 | 59.99 | No | No | 2023-03-29 | 2025-02-18 | euvd | This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Au…This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HttpFile class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. Was ZDI-CAN-17481. |
CVE-2017-1000253 | HIGH | 7.8 | 0.10695 | 59.94 | Yes | No | 2024-09-09 | 2024-09-09 | cisa.gov, euvd | Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a loca…Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. |
CVE-2014-0783 | CRITICAL | 9.0 | 0.68359 | 59.93 | No | No | 2014-03-14 | 2025-09-25 | euvd | Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code…Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet. |
CVE-2020-17143 | HIGH | 8.8 | 0.70632 | 59.92 | No | No | 2020-12-09 | 2026-06-09 | euvd | Microsoft Exchange Server Information Disclosure VulnerabilityMicrosoft Exchange Server Information Disclosure Vulnerability |
CVE-2024-54003 | HIGH | 8.0 | 0.79731 | 59.91 | No | No | 2024-11-27 | 2024-11-27 | euvd | Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability …Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission. |
CVE-2026-42945 | CRITICAL | 9.2 | 0.66039 | 59.91 | No | Yes | 2026-05-13 | 2026-07-20 | euvd, packetstorm | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite dire…NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
CVE-2024-25723 | HIGH | 8.8 | 0.70581 | 59.9 | No | No | 2024-02-27 | 2024-08-01 | euvd | ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{us…ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body. These are also patched versions: 0.44.4, 0.43.1, and 0.42.2. |
CVE-2024-1728 | HIGH | 7.5 | 0.85393 | 59.89 | No | No | 2024-04-10 | 2024-08-01 | euvd | gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButto…gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the `/queue/join` endpoint. This issue could potentially lead to remote code execution. The vulnerability is present in the handling of file upload paths, allowing attackers to redirect file uploads to unintended locations on the server. |
CVE-2022-25772 | CRITICAL | 9.6 | 0.61396 | 59.89 | No | No | 2022-06-20 | 2024-08-03 | euvd | A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable…A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript |
CVE-2025-25292 | CRITICAL | 9.3 | 0.64822 | 59.89 | No | No | 2025-03-12 | 2025-11-03 | euvd | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found…ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 contain a patch for the issue. |
CVE-2020-13557 | HIGH | 8.8 | 0.70388 | 59.84 | No | No | 2020-12-22 | 2024-08-04 | euvd | A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially craft…A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability. |
CVE-2022-2487 | HIGH | 8.0 | 0.79513 | 59.83 | No | No | 2022-07-20 | 2025-04-15 | euvd | A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the fil…A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection. The exploit has been disclosed to the public and may be used. |
CVE-2020-27932 | HIGH | 7.8 | 0.10337 | 59.82 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with ker…Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. |
CVE-2023-27034 | CRITICAL | 9.8 | 0.58743 | 59.76 | No | No | 2023-03-23 | 2025-02-25 | euvd | PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. |
CVE-2023-32046 | HIGH | 7.8 | 0.10049 | 59.72 | Yes | No | 2023-07-11 | 2023-07-11 | cisa.gov, euvd | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2020-3433 | HIGH | 7.8 | 0.10049 | 59.72 | Yes | No | 2022-10-24 | 2022-10-24 | cisa.gov, euvd | Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources…Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges. |
CVE-2017-0263 | HIGH | 7.8 | 0.10034 | 59.71 | Yes | No | 2022-02-10 | 2022-02-10 | cisa.gov, euvd | Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in m…Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory. |
CVE-2023-32164 | HIGH | 7.5 | 0.8487 | 59.7 | No | No | 2024-05-03 | 2024-09-18 | euvd | D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to dis…D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the TftpSendFileThread class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-19496. |
CVE-2024-21683 | HIGH | 7.2 | 0.88267 | 59.69 | No | No | 2024-05-21 | 2025-05-12 | euvd | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
This RCE (…This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.
Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html
You can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives.
This vulnerability was found internally. |
CVE-2025-21479 | HIGH | 8.6 | 0.00778 | 59.67 | Yes | Yes | 2025-06-03 | 2025-06-03 | cisa.gov, euvd, github | Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthor…Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. |
CVE-2025-1976 | HIGH | 8.6 | 0.00784 | 59.67 | Yes | No | 2025-04-28 | 2025-04-28 | cisa.gov, euvd | Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitr…Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges. |
CVE-2015-1130 | HIGH | 7.8 | 0.09887 | 59.66 | Yes | No | 2022-02-10 | 2022-02-10 | cisa.gov, euvd | The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileg…The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges. |
CVE-2026-2699 | CRITICAL | 9.8 | 0.58386 | 59.64 | No | No | 2026-04-02 | 2026-04-08 | euvd | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This …Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution. |
CVE-2019-1132 | HIGH | 7.8 | 0.09788 | 59.63 | Yes | No | 2022-03-15 | 2022-03-15 | cisa.gov, euvd | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. |
CVE-2025-21333 | HIGH | 7.8 | 0.09798 | 59.63 | Yes | No | 2025-01-14 | 2025-01-14 | cisa.gov, euvd | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain…Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. |
CVE-2020-6820 | HIGH | 8.1 | 0.06305 | 59.61 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race con…Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. |
CVE-2021-20022 | HIGH | 7.2 | 0.16509 | 59.58 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker…SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. |
CVE-2026-41091 | HIGH | 7.8 | 0.09641 | 59.57 | Yes | Yes | 2026-05-20 | 2026-05-20 | cisa.gov, euvd, nvd, packetstorm | Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. |
CVE-2025-21480 | HIGH | 8.6 | 0.00435 | 59.55 | Yes | No | 2025-06-03 | 2025-06-03 | cisa.gov, euvd | Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthor…Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. |
CVE-2002-0391 | CRITICAL | 9.8 | 0.58133 | 59.55 | No | No | 2003-04-02 | 2025-01-16 | euvd | Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including di…Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd. |
CVE-2026-54420 | HIGH | 8.5 | 0.01439 | 59.5 | Yes | No | 2026-06-15 | 2026-06-15 | cisa.gov, euvd, nvd | LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access…LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS. |
CVE-2024-11320 | MEDIUM | 6.9 | 0.91128 | 59.49 | No | No | 2024-11-21 | 2024-11-21 | euvd | Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue …Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4 |
CVE-2020-26214 | CRITICAL | 9.1 | 0.65933 | 59.48 | No | No | 2020-11-06 | 2024-08-04 | euvd | In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is conf…In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deployments where LDAP servers are configured to allow unauthenticated authentication mechanism for anonymous authorization are affected. A fix has been implemented in version 8.1.0 that returns HTTP 401 Unauthorized response for any authentication attempts where the password field is empty. As a workaround LDAP administrators can disallow unauthenticated bind requests by clients. |