Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2019-13744
Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted H…
Chrome
79.0.3945.79+
HIGH 7.5
CVE-2014-0242EPSS 9%
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type …
Mod Wsgi
3.4+
MEDIUM 5.3
CVE-2019-19625
SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS…
Sros2
Patch available
MEDIUM 5.3
CVE-2019-19627
SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_kind configuration. (SROS2 pr…
Sros2
No fix yet
MEDIUM 5.5
CVE-2012-1105
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Serv…
Fedora
Patch available
HIGH 7.2
CVE-2019-19007
Intelbras IWR 3000N 1.8.7 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled, a related issue…
Iwr 3000n Firmware
Mitigation only
HIGH 7.5
CVE-2011-2480
Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signed…
FreeBSD
8.2+
MEDIUM 6.5
CVE-2019-10195
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIP…
Fedora
4.6.7 / 4.7.4+
HIGH 7.5
CVE-2019-18679EPSS 41%
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when pro…
Ubuntu Linux
after 4.8
HIGH 7.5
CVE-2019-18460
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch int…
GitLab
after 12.4.0
HIGH 7.5
CVE-2016-5724
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
Cdh
5.9.0+
HIGH 7.5
CVE-2015-6495
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
Cloudera Manager
4.8.6 / 5.0.7+
MEDIUM 5.9
CVE-2011-4076
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a…
Nova
2012.1+
MEDIUM 6.5
CVE-2019-10217
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP m…
Ansible
2.8.4+
HIGH 7.4
CVE-2019-5880
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTM…
Chrome
77.0.3865.75+
MEDIUM 5.5
CVE-2012-5644
libuser has information disclosure when moving user's home directory
Debian Linux
0.59+
HIGH 7.5
CVE-2012-5535
gnome-system-log polkit policy allows arbitrary files on the system to be read
Fedora
No fix yet
HIGH 7.5
CVE-2012-6078
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
W3 Total Cache
0.9.2.5+
HIGH 7.5
CVE-2012-6079
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash…
W3 Total Cache
0.9.2.5+
HIGH 7.5
CVE-2012-6077EPSS 5%
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
W3 Total Cache
0.9.2.5+
HIGH 7.5
CVE-2013-3314EPSS 7%
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and sy…
Nexus 543 Firmware
No fix yet
HIGH 7.5
CVE-2019-6852
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communicati…
Bmx P34x Firmware
Mitigation only
HIGH 7.5
CVE-2015-3167
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different err…
PostgreSQL
9.0.20 / 9.1.16+
HIGH 7.5
CVE-2013-1817
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive informatio…
Debian Linux
1.19.4 / 1.20.3+
MEDIUM 5.3
CVE-2019-10083
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most …
Nifi
after 1.9.2
MEDIUM 5.5
CVE-2012-0843
uzbl: Information disclosure via world-readable cookies storage file
Debian Linux
Mitigation only
HIGH 7.5
CVE-2011-4919
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users
Mpack
No fix yet
MEDIUM 5.5
CVE-2012-0842
surf: cookie jar has read access from other local user
Debian Linux
0.5+
HIGH 7.5
CVE-2019-19022
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allo…
Iterm2
after 3.3.6
HIGH 7.5
CVE-2013-7089
ClamAV before 0.97.7: dbg_printhex possible information leak
Debian Linux
0.97.7+