Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2013-2499
SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via spoofing a cookie.
Simplehrm
after 2.3
MEDIUM 5.3
CVE-2020-5220
Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintend…
Syliusresourcebundle
after 1.6.2
MEDIUM 5.9
CVE-2014-9481
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted mod…
Mediawiki
1.19.23 / 1.22.15+
HIGH 7.5
CVE-2013-1594EPSS 7%
An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party crede…
Pt7135 Firmware
No fix yet
HIGH 8.8
CVE-2019-19631
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud…
Big Cloud Fabric
1.1.0 / 4.5.5+
MEDIUM 5.5
CVE-2013-4176
mysecureshell 1.31: Local Information Disclosure Vulnerability
Mysecureshell
No fix yet
HIGH 7.5
CVE-2011-3613
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
Vanilla
2.0.17.9+
MEDIUM 6.5
CVE-2018-16264
The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-B…
Tizen
Mitigation only
HIGH 7.5
CVE-2018-16269
The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to imp…
Galaxy Gear Firmware
No fix yet
MEDIUM 5.3
CVE-2011-5282
mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.
Mirc
7.22+
MEDIUM 5.3
CVE-2017-3211
Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent purchase data of customers, all…
Yopify
after 2017-04-06
MEDIUM 6.5
CVE-2020-6954
An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test. This passw…
Smp Pro4 Firmware
No fix yet
HIGH 7.5
CVE-2014-6038EPSS 73%
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyze…
Manageengine Eventlog Analyzer
after 9.9
HIGH 7.5
CVE-2019-14301
Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).
Sp C250sf Firmware
1.02 / 1.09+
MEDIUM 5.3
CVE-2019-4559
IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on th…
Qradar Security Information And Event Manager
after 7.3.3
MEDIUM 6.5
CVE-2014-5011
DOMPDF before 0.6.2 allows Information Disclosure.
Dompdf
0.6.2+
MEDIUM 5.3
CVE-2012-2724
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of…
Simplenews
Mitigation only
MEDIUM 5.5
CVE-2014-3753
AgileBits 1Password through 1.0.9.340 allows security feature bypass
1password
after 1.0.9.340
MEDIUM 5.3
CVE-2019-17018
When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerabi…
Firefox
72.0+
MEDIUM 5.5
CVE-2016-5346
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing…
Android
7.0+
MEDIUM 5.5
CVE-2016-6587
An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, …
Norton Mobile Security
3.16+
CRITICAL 9.8
CVE-2020-6170EPSS 7%
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the …
Platinum 4410 Firmware
No fix yet
MEDIUM 5.3
CVE-2014-5209
An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a mali…
Big Ip Access Policy Manager
after 14.1.0
MEDIUM 6.5
CVE-2019-6700
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker …
Fortisiem
5.2.5+
MEDIUM 6.1
CVE-2019-9541
: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script…
Automated Message Handling System
4.1.5.5+
MEDIUM 5.3
CVE-2019-19256
GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.
GitLab
12.5.1+
MEDIUM 5.3
CVE-2019-19254
GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.
GitLab
12.5.1+
MEDIUM 5.9
CVE-2014-6275
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages a…
Debian Linux
5.3.2+
MEDIUM 5.3
CVE-2018-20495
An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. …
GitLab
11.4.13 / 11.5.6+
MEDIUM 5.5
CVE-2012-5476
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the adm…
Debian Linux
Mitigation only