Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2014-0091
Foreman has improper input validation which could lead to partial Denial of Service
Foreman
No fix yet
HIGH 7.3
CVE-2013-4245
Orca has arbitrary code execution due to insecure Python module load
Debian Linux
Mitigation only
HIGH 7.8
CVE-2019-1484EPSS 9%
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution…
Windows 10
Patch available
MEDIUM 6.0
CVE-2019-1470EPSS 6%
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated…
Windows 10
Patch available
HIGH 8.2
CVE-2019-1471EPSS 8%
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-13750
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a cra…
Chrome
79.0.3945.79+
MEDIUM 6.5
CVE-2013-1689
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.
Firefox
after 19.0.2
HIGH 7.5
CVE-2019-2232
In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service wh…
Android
Patch available
CRITICAL 9.8
CVE-2019-7193 KEVEPSS 14%
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend…
Qts
Mitigation only
HIGH 7.4
CVE-2013-0243
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections
Hs Tls
0.6.1+
MEDIUM 6.5
CVE-2019-11255
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshot…
External Provisioner
after 1.2.1
MEDIUM 6.8
CVE-2019-19579
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce…
Fedora
after 4.12.1
HIGH 7.5
CVE-2019-17555
The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method w…
Olingo
after 4.6.0
HIGH 8.8
CVE-2016-1000104
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
Mod Fcgid
after 2016-07-07
HIGH 8.1
CVE-2013-2103
OpenShift cartridge allows remote URL retrieval
Openshift
Mitigation only
HIGH 7.8
CVE-2012-4576
FreeBSD: Input Validation Flaw allows local users to gain elevated privileges
FreeBSD
No fix yet
HIGH 7.5
CVE-2019-19396
illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurre…
Omnios
Mitigation only
HIGH 8.1
CVE-2019-5268
Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulne…
Cd10 10 Firmware
10.0.2.5 / 10.0.2.6+
MEDIUM 5.9
CVE-2015-1855
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properl…
Ruby
2.1.6 / 2.2.2+
MEDIUM 6.5
CVE-2019-19376
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input valida…
Octopus Deploy
2019.6.14 / 2019.9.8+
HIGH 7.5
CVE-2019-18247
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.…
Relion 650 Firmware
after 2.1.0.1
HIGH 7.5
CVE-2019-15705
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticate…
Fortios
after 6.2.1
HIGH 8.1
CVE-2012-2248
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
Debian Linux
Mitigation only
HIGH 7.5
CVE-2011-4310
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
Cms Made Simple
1.9.4.3+
CRITICAL 9.8
CVE-2011-4120
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured…
Debian Linux
2.10+
MEDIUM 6.7
CVE-2019-15997
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitra…
Dna Spaces\
2.0+
MEDIUM 6.7
CVE-2019-15986
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…
Unity Express
10.1+
MEDIUM 5.3
CVE-2019-15988
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticat…
Email Security Appliance Firmware
after 12.5.0
MEDIUM 6.5
CVE-2019-15276EPSS 46%
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause …
Wireless Lan Controller Software
8.10+
HIGH 8.8
CVE-2019-15288
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an…
Telepresence Codec
7.3.19 / 9.8.1+