Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2019-5819
Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code vi…
Chrome
74.0.3729.108+
HIGH 8.8
CVE-2018-6161
Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same origin policy via a crafted …
Chrome
68.0.3440.75+
HIGH 7.8
CVE-2018-6176
Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the rendere…
Chrome
68.0.3440.75+
HIGH 8.8
CVE-2018-6121
Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform privilege escalation via a cra…
Chrome
66.0.3359.170+
HIGH 8.1
CVE-2018-6138
Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malici…
Chrome
67.0.3396.62+
MEDIUM 6.5
CVE-2017-5028
Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Chrome
56.0.2924.76+
MEDIUM 6.5
CVE-2018-16064
Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious…
Chrome
68.0.3440.75+
MEDIUM 6.5
CVE-2018-17460
Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox…
Chrome
68.0.3440.75+
MEDIUM 6.5
CVE-2018-20846
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in Ope…
Openjpeg
after 2.3.0
HIGH 8.8
CVE-2019-12981
Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.c.
Libming
Patch available
MEDIUM 6.5
CVE-2019-9085
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visuali…
Hoteldruid
2.3.1+
HIGH 8.0
CVE-2019-12936
BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions.
Bluestacks App Player
4.90+
MEDIUM 5.5
CVE-2018-15729
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…
Antimalware
No fix yet
MEDIUM 5.5
CVE-2018-15730
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…
Antimalware
No fix yet
MEDIUM 5.5
CVE-2018-15731
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…
Antimalware
No fix yet
MEDIUM 5.5
CVE-2018-15732
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating…
Antimalware
No fix yet
MEDIUM 5.5
CVE-2018-15734
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating…
Antimalware
No fix yet
MEDIUM 5.5
CVE-2018-15735
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating…
Antimalware
No fix yet
MEDIUM 5.5
CVE-2018-15736
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…
Antimalware
No fix yet
MEDIUM 5.5
CVE-2018-15737
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…
Antimalware
No fix yet
CRITICAL 9.8
CVE-2018-15747
The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.syste…
Glot Www
after 2018-05-19
MEDIUM 5.8
CVE-2019-1905
A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, r…
Email Security Appliance
Mitigation only
MEDIUM 6.5
CVE-2019-1906
A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual d…
Prime Infrastructure
Mitigation only
HIGH 7.5
CVE-2019-1843
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, …
Rv110w Firmware
1.0.3.51 / 1.2.2.4+
HIGH 8.8
CVE-2019-2016
In NFA_SendRawFrame of nfa_dm_api.cc, there is a possible out-of-bound write due to improper input validation. This could lead to local escalation of…
Android
Mitigation only
MEDIUM 6.5
CVE-2017-8330
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a UPnP functionality for devi…
Almond 2015 Firmware
No fix yet
HIGH 7.5
CVE-2018-18878
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attac…
Weather Microserver Firmware
Mitigation only
HIGH 7.5
CVE-2018-20013
In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThr…
Urbackup
Mitigation only
HIGH 7.2
CVE-2019-12831
In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a…
Mybb
1.8.21+
HIGH 8.8
CVE-2019-12816
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module…
Znc
after 1.7.3