Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-12065
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (exe…
Witycms
No fix yet
HIGH 7.5
CVE-2018-12041
An issue was discovered on the MediaTek AWUS036NH wireless USB adapter through 5.1.25.0. Attackers can remotely deny service by sending specially con…
Awus036nh Firmware
Mitigation only
HIGH 7.5
CVE-2018-12046
DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and…
Dedecms
5.7+
HIGH 7.8
CVE-2018-0338
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local att…
Unified Computing System
Mitigation only
MEDIUM 6.1
CVE-2018-0355
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross…
Unified Communications Manager
Mitigation only
HIGH 8.8
CVE-2018-0274
A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to execute arbitrary she…
Network Services Orchestrator
after 4.4.2.0
HIGH 7.5
CVE-2018-0296 KEVEPSS 100%
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affec…
Adaptive Security Appliance Software
6.1.0 / 6.2.2.3+
HIGH 8.8
CVE-2018-3719
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modi…
Mixin Deep
1.3.1+
HIGH 8.8
CVE-2018-3723
defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to m…
Defaults Deep
0.2.4+
CRITICAL 9.8
CVE-2017-16226
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the gl…
Static Eval
2.0.0+
HIGH 7.5
CVE-2017-16113
The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.
Parsejson
after 0.0.3
HIGH 7.5
CVE-2018-3852
An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A specially crafted TCP packet ca…
Ocularis
No fix yet
MEDIUM 6.8
CVE-2018-1268
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, d…
Loggregator
89.5 / 96.1+
CRITICAL 9.1
CVE-2018-11808EPSS 6%
Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to del…
Manageengine Applications Manager
Mitigation only
MEDIUM 5.3
CVE-2017-7653
The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that…
Debian Linux
after 1.4.15
CRITICAL 9.8
CVE-2018-11678
plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.
Monstra Cms
No fix yet
MEDIUM 5.9
CVE-2016-9042
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticate…
FreeBSD
No fix yet
HIGH 7.5
CVE-2017-16023
Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to e…
Decamelize
Mitigation only
MEDIUM 5.9
CVE-2017-16026
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero mem…
Request
2.47.0+
HIGH 7.5
CVE-2017-16005
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, …
Http Signature
after 0.9.11
HIGH 7.5
CVE-2017-16013
hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception…
Hapi
after 16.1.0
MEDIUM 5.5
CVE-2018-1002100
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the c…
Kubernetes
after 1.9.5
HIGH 7.5
CVE-2018-5513
On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leadi…
Big Ip Application Acceleration Manager
after 13.1.0.4
MEDIUM 5.9
CVE-2018-5522
On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted attribute…
Big Ip Application Acceleration Manager
after 12.1.2
MEDIUM 6.5
CVE-2016-10555
Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the ser…
Jwt Simple
after 0.3.0
HIGH 7.5
CVE-2016-10539
negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Lan…
Negotiator
after 0.6.0
HIGH 7.5
CVE-2016-10540
Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(…
Minimatch
after 3.0.1
HIGH 7.5
CVE-2016-10542EPSS 8%
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending…
Ws
after 1.1.0
MEDIUM 5.3
CVE-2016-10543
call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty par…
Call
after 3.0.1
MEDIUM 5.9
CVE-2016-10544
uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibil…
Uws
after 0.10.8