Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2015-9239
ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
Ansi2html
No fix yet
HIGH 7.5
CVE-2016-10520
jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
Jadedown
after 0.0.3
HIGH 7.5
CVE-2016-10521
jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator.
Jshamcrest
after 0.7.1
HIGH 8.8
CVE-2018-11481
TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data be…
Ipc Tl Ipc223\(p\) 6 Firmware
1.0.21+
MEDIUM 5.3
CVE-2018-10995
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).
Debian Linux
after 17.02.10.1
HIGH 8.1
CVE-2018-11518
A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio sign…
Legacy Ivr Firmware
Mitigation only
HIGH 7.5
CVE-2018-11548
An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connections from the same source IP ad…
Eos
Mitigation only
CRITICAL 9.8
CVE-2015-9235EPSS 9%
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (…
Jsonwebtoken
4.2.2+
HIGH 7.5
CVE-2015-9241
Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a …
Hapi
11.1.3+
HIGH 7.5
CVE-2015-9242
Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads …
Ecstatic
1.4.0+
HIGH 7.8
CVE-2018-11479EPSS 10%
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishe…
Windscribe
No fix yet
HIGH 8.1
CVE-2018-1137
An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who a…
Moodle
after 3.4.2
MEDIUM 5.3
CVE-2017-17315
Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00…
Dp300 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-5487
NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) servic…
Oncommand Unified Manager
after 7.3
MEDIUM 5.5
CVE-2018-1000040
In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service …
Debian Linux
after 1.12.0
MEDIUM 5.5
CVE-2018-1000037
In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) vi…
Debian Linux
after 1.12.0
HIGH 7.5
CVE-2018-11411
The transferFrom function of a smart contract implementation for DimonCoin (FUD), an Ethereum ERC20 token, allows attackers to steal assets (e.g., tr…
Dimoncoin
Mitigation only
HIGH 8.8
CVE-2018-8176EPSS 23%
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsof…
Office For Mac
Patch available
HIGH 7.5
CVE-2018-11354
In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by making a certain correction to…
Wireshark
Mitigation only
HIGH 7.5
CVE-2018-11357
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in…
Wireshark
after 2.4.6
HIGH 7.8
CVE-2017-2617
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file…
Hawtio
1.5.5+
MEDIUM 6.5
CVE-2018-11321
An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulat…
Joomla\!
3.8.8+
HIGH 7.5
CVE-2018-11367
An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module.
Cppcms
1.2.1+
MEDIUM 6.5
CVE-2018-11315
The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can resul…
Ct50 Firmware
after 1.04.84
HIGH 8.8
CVE-2018-4943EPSS 7%
Adobe PhoneGap Push Plugin versions 1.8.0 and earlier have an exploitable Same-Origin Method Execution vulnerability. Successful exploitation could l…
Push Notifications
after 1.8.0
HIGH 7.8
CVE-2018-4992
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper input validation vulnerability. Successful explo…
Creative Cloud
after 4.4.1.298
HIGH 7.5
CVE-2018-8867
In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP …
Pacsystems Rx3i Cpe305 Firmware
after 9.30
MEDIUM 5.5
CVE-2018-11232
The etm_setup_aux function in drivers/hwtracing/coresight/coresight-etm-perf.c in the Linux kernel before 4.10.2 allows attackers to cause a denial o…
Linux Kernel
4.10.2+
HIGH 8.8
CVE-2018-9970
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is requ…
Foxit Reader
after 9.0.1.1049
HIGH 8.8
CVE-2018-9935
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is req…
Phantompdf
after 9.0.1.1049