Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2019-5800
Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a cra…
Chrome
73.0.3683.75+
MEDIUM 6.5
CVE-2019-5801
Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted…
Chrome
73.0.3683.75+
MEDIUM 6.5
CVE-2019-5803
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content securit…
Chrome
73.0.3683.75+
MEDIUM 6.5
CVE-2019-5793
Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installatio…
Chrome
73.0.3683.75+
HIGH 8.8
CVE-2017-11740
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon…
Manageengine Applications Manager
No fix yet
HIGH 7.5
CVE-2017-5211
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
Open Xchange Appsuite
after 7.8.3
MEDIUM 5.3
CVE-2017-8341
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
Open Xchange Appsuite
after 7.8.3
HIGH 8.8
CVE-2018-14729EPSS 11%
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.
Discuz\!
after 3.4
MEDIUM 5.4
CVE-2018-12270
In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users int…
Steam Client
Mitigation only
HIGH 7.8
CVE-2019-11085
Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potenti…
I915 Firmware
5.0+
HIGH 7.8
CVE-2019-11094
Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege,…
Nuc Kit Firmware
Mitigation only
HIGH 8.7
CVE-2019-5931
Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors.
Garoon
after 4.6.3
MEDIUM 6.8
CVE-2019-0092
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthent…
Active Management Technology Firmware
11.8.65 / 11.11.65+
MEDIUM 5.5
CVE-2019-0115
Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33…
Graphics Driver
Mitigation only
HIGH 8.8
CVE-2019-0957
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affe…
Sharepoint Enterprise Server
Patch available
HIGH 7.8
CVE-2019-0885EPSS 14%
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution…
Windows 10
Patch available
MEDIUM 6.8
CVE-2019-0886
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated…
Windows 10
Patch available
HIGH 7.4
CVE-2019-1846
A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software…
Ios Xr
Mitigation only
HIGH 8.6
CVE-2019-1858
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow a…
Nx Os
2.2.2.91 / 2.3.1.130+
CRITICAL 9.8
CVE-2019-1821EPSS 98%
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could a…
Evolved Programmable Network Manager
3.0.1 / 3.4.1+
HIGH 7.2
CVE-2019-1822
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could a…
Evolved Programmable Network Manager
3.0.1 / 3.4.1+
HIGH 7.2
CVE-2019-1823
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could a…
Evolved Programmable Network Manager
3.0.1 / 3.4.1+
HIGH 7.7
CVE-2019-1806
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Mana…
Sf200 24 Firmware
1.4.10.6+
HIGH 7.8
CVE-2019-1726
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted…
Nx Os
4.0 / 6.0+
MEDIUM 6.0
CVE-2019-1729
A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software could allow an authenticated, loc…
Nx Os
7.0+
HIGH 7.5
CVE-2019-5598
In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4,…
FreeBSD
Patch available
CRITICAL 9.1
CVE-2019-5597
In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in th…
FreeBSD
Patch available
HIGH 7.2
CVE-2019-1862EPSS 6%
A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands o…
Ios Xe
Mitigation only
MEDIUM 6.4
CVE-2018-18558
An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage …
Esp Idf
3.0.6+
CRITICAL 9.8
CVE-2017-12795
OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).
Openmrs Module Htmlformentry
Patch available