Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-15958
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticat…
Prime Infrastructure
3.0.2 / 3.4.2+
CRITICAL 9.8
CVE-2019-19249
Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.
Querytree
Patch available
HIGH 8.8
CVE-2019-5856
Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process …
Chrome
76.0.3809.87+
HIGH 8.8
CVE-2019-5858
Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code…
Chrome
76.0.3809.87+
MEDIUM 6.5
CVE-2019-5862
Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to…
Chrome
76.0.3809.87+
MEDIUM 6.5
CVE-2019-5852
Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive informati…
Chrome
76.0.3809.87+
MEDIUM 5.5
CVE-2019-13707
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a …
Chrome
78.0.3904.70+
HIGH 8.8
CVE-2019-13692
Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafte…
Chrome
77.0.3865.75+
CRITICAL 9.8
CVE-2012-5582
opendnssec misuses libcurl API
Opendnssec
No fix yet
HIGH 7.5
CVE-2014-1936
rc before 1.7.1-5 insecurely creates temporary files.
Debian Linux
1.7.1-5+
HIGH 7.5
CVE-2014-1937
Gamera before 3.4.1 insecurely creates temporary files.
Gamera
3.4.1+
MEDIUM 5.5
CVE-2019-10535
Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdra…
Apq8053 Firmware
Patch available
HIGH 7.8
CVE-2019-10563
Buffer over-read can occur in fast message handler due to improper input validation while processing a message from firmware in Snapdragon Auto, Snap…
Apq8053 Firmware
Patch available
CRITICAL 9.8
CVE-2012-3460
cumin: At installation postgresql database user created without password
Enterprise Mrg
Mitigation only
HIGH 7.5
CVE-2012-4524
xlockmore before 5.43 'dclock' security bypass vulnerability
Fedora
5.43+
MEDIUM 5.5
CVE-2014-0084
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.…
Openshift Origin
2014-02-14+
MEDIUM 5.3
CVE-2014-1935
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
Debian Linux
No fix yet
HIGH 7.5
CVE-2012-2350
pam_shield before 0.9.4: Default configuration does not perform protective action
Debian Linux
0.9.4+
HIGH 7.5
CVE-2012-3543
mono 2.10.x ASP.NET Web Form Hash collision DoS
Ubuntu Linux
after 2.10.12
CRITICAL 9.8
CVE-2013-7171EPSS 6%
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow rem…
Slackware Linux
Mitigation only
HIGH 7.8
CVE-2013-7172
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which c…
Slackware Linux
Mitigation only
CRITICAL 9.8
CVE-2013-2093EPSS 5%
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary …
Dolibarr Erp\/crm
Patch available
HIGH 7.5
CVE-2013-1816
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially craf…
Debian Linux
1.19.4 / 1.20.3+
MEDIUM 5.5
CVE-2015-1607
kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows re…
Ubuntu Linux
1.4.19 / 2.0.27+
CRITICAL 9.8
CVE-2010-4660
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
Statusnet
after 2010
HIGH 7.5
CVE-2011-0529
Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
Debian Linux
0.12.5+
CRITICAL 9.8
CVE-2011-1028
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_s…
Debian Linux
3.0.7+
HIGH 8.6
CVE-2019-11289
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HT…
Cf Deployment
0.193.0 / 12.8.0+
HIGH 7.8
CVE-2011-2922
ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GT…
Ktsuss
after 1.4
HIGH 7.5
CVE-2012-6070
Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.
Falconpl
0.9.6.9+