Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-8038EPSS 11%
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response…
Cxf Fediz
1.4.4+
CRITICAL 9.8
CVE-2018-3749
The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can co…
Deap
1.0.1+
CRITICAL 9.8
CVE-2018-3750
The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacke…
Deep Extend
after 0.5.0
CRITICAL 9.8
CVE-2018-3751
The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the att…
Merge Recursive
after 0.3.0
CRITICAL 9.8
CVE-2018-3752
The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attac…
Merge Options
after 1.0.0
CRITICAL 9.8
CVE-2018-3753
The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attac…
Merge Object
after 1.0.0
MEDIUM 5.5
CVE-2018-9242
The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to d…
Pan Os
after 8.0.9
CRITICAL 9.6
CVE-2018-11314
The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and…
Roku Firmware
Mitigation only
CRITICAL 9.6
CVE-2018-11316
The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device contro…
Sonos Firmware
Mitigation only
MEDIUM 5.3
CVE-2018-7635
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, whi…
Whale
1.0.41.8+
HIGH 8.8
CVE-2018-7777EPSS 32%
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder softwa…
U.motion Builder
1.3.4+
CRITICAL 9.8
CVE-2018-7784
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated…
U.motion
1.3.4+
MEDIUM 5.3
CVE-2018-7787
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parame…
U.motion Builder
1.3.4+
HIGH 8.2
CVE-2018-4851
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device c…
Siclock Tc400 Firmware
Mitigation only
HIGH 8.8
CVE-2018-10843
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privile…
Openshift Container Platform
3.7.53+
HIGH 7.5
CVE-2018-13056
An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_…
Zzcms
No fix yet
MEDIUM 6.5
CVE-2017-17175
Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) …
Mate 9 Pro
Mitigation only
HIGH 7.8
CVE-2018-10874
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con…
Ansible Engine
Mitigation only
HIGH 7.5
CVE-2018-12999EPSS 9%
Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web se…
Manageengine Desktop Central
No fix yet
HIGH 7.5
CVE-2018-12988
GreenCMS 2.3.0603 has an arbitrary file download vulnerability via an index.php?m=admin&c=media&a=downfile URI.
Greencms
No fix yet
MEDIUM 5.3
CVE-2018-5528
Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4-13.1.0.7.
Big Ip Access Policy Manager
after 13.1.0.7
HIGH 7.5
CVE-2018-3840
A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x67). The vulnerability is present in the parsing of a netw…
Renderman
No fix yet
MEDIUM 6.5
CVE-2018-1374
An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4) client connect…
Websphere Mq
Mitigation only
HIGH 8.8
CVE-2018-12712
An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" functi…
Joomla\!
after 3.8.8
MEDIUM 6.5
CVE-2018-1000607
A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to c…
Fortify Cloudscan
after 1.5.1
HIGH 8.1
CVE-2018-1000523
topydo contains a CWE-20: Improper Input Validation vulnerability in ListFormatParser::parse, file topydo/lib/ListFormat.py line 292 as of d4f843dac7…
Topydo
Mitigation only
HIGH 7.5
CVE-2018-1000531
inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can re…
Prime Jwt
after 1.3.0
CRITICAL 9.8
CVE-2018-1000533EPSS 73%
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that ca…
Gitlist
after 0.6.0
MEDIUM 5.5
CVE-2018-1000205
U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This…
U Boot
after 2018.07
HIGH 7.5
CVE-2017-9312
Improperly implemented option-field processing in the TCP/IP stack on Allen-Bradley L30ERMS safety devices v30 and earlier causes a denial of service…
Allen Bradley L30erms Firmware
after 30