Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-5611
In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.…
FreeBSD
Patch available
MEDIUM 5.3
CVE-2019-14978
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 para…
Payu India Payment Gateway
No fix yet
MEDIUM 5.3
CVE-2019-14979
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount param…
Paypal Checkout Payment Gateway
No fix yet
HIGH 8.1
CVE-2019-11247
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced.…
Kubernetes
1.13.9 / 1.14.5+
HIGH 7.5
CVE-2019-10054
An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memo…
Suricata
No fix yet
HIGH 7.5
CVE-2019-1962
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crash…
Nx Os
3.2 / 4.0+
MEDIUM 6.5
CVE-2019-1963
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow a…
Nx Os
2.2.2.91 / 2.3.1.130+
HIGH 7.5
CVE-2019-1964
A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an unexpected restart…
Nx Os
8.2 / 8.4+
HIGH 8.8
CVE-2019-13269
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device…
Br 6208ac V1 Firmware
No fix yet
HIGH 8.8
CVE-2019-13270
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device…
Br 6208ac V1 Firmware
No fix yet
HIGH 8.8
CVE-2019-13268
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are establish…
Archer C3200 V1 Firmware
No fix yet
HIGH 7.5
CVE-2015-9348
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
Sell Downloads
1.0.8+
CRITICAL 9.8
CVE-2015-9351
The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.
Feed Them Social
1.7.0+
HIGH 7.5
CVE-2015-9345
The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.
Link Log
2.0+
HIGH 7.5
CVE-2017-18589
An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic.
Cookie
0.7.6+
HIGH 7.5
CVE-2019-15640
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
Limesurvey
3.17.10+
MEDIUM 5.5
CVE-2019-12400
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static poo…
Santuario Xml Security For Java
2.1.4+
CRITICAL 9.8
CVE-2019-1581
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access…
Pan Os
after 9.0.3
CRITICAL 9.8
CVE-2013-7483
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
Slidedeck 2
2.3.5+
CRITICAL 9.8
CVE-2016-10930
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
Wp Support Plus Responsive Ticket System
7.1.0+
HIGH 7.2
CVE-2019-7617
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can cont…
Apm Agent
5.1.0+
HIGH 8.8
CVE-2019-15324
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
Ad Inserter
2.4.22+
CRITICAL 9.8
CVE-2017-18580EPSS 12%
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
Shortcodes Ultimate
5.0.1+
CRITICAL 9.8
CVE-2018-20985EPSS 8%
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
Wp Payeezy Pay
2.98+
CRITICAL 9.8
CVE-2014-10383
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
Memphis Documents Library
3.0+
CRITICAL 9.8
CVE-2014-10384
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
Memphis Documents Library
3.0+
MEDIUM 6.1
CVE-2017-18574
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
Ninja Forms
3.0.31+
HIGH 7.5
CVE-2018-20980
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
Ninja Forms
3.2.15+
CRITICAL 9.1
CVE-2018-20981
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
Ninja Forms
3.3.9+
MEDIUM 6.1
CVE-2009-5158
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.
Google Analyticator
5.2.1+