Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2019-1293
An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory, …
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1251
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-1252EPSS 61%
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1263EPSS 8%
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information…
Excel
Patch available
MEDIUM 6.5
CVE-2019-1244EPSS 12%
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-1245EPSS 13%
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-1209EPSS 6%
An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'.
Lync
Patch available
MEDIUM 5.5
CVE-2019-1216
An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'.
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1219
An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Ma…
Windows 10
Patch available
HIGH 7.5
CVE-2019-0352
In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.5
CVE-2019-16177
In Limesurvey before 3.17.14, the entire database is exposed through browser caching.
Limesurvey
3.17.14+
HIGH 7.5
CVE-2019-11605
An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allow…
GitLab
11.8.10 / 11.9.11+
MEDIUM 5.3
CVE-2019-5463
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnera…
GitLab
11.11.7 / 12.0.4+
HIGH 7.5
CVE-2018-21011
The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.
Charitable
1.5.14+
MEDIUM 5.3
CVE-2019-10667
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and …
Librenms
after 1.47
MEDIUM 5.5
CVE-2019-2103
In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. Thi…
Android
Patch available
CRITICAL 9.8
CVE-2019-1976
A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remo…
Industrial Network Director
1.6.0+
MEDIUM 5.6
CVE-2019-15902
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x …
Linux Kernel
after 5.2.11
CRITICAL 9.8
CVE-2019-11064
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration…
Vd 1 Firmware
after 230
MEDIUM 5.3
CVE-2018-13367
An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as ve…
Fortios
after 6.2.0
MEDIUM 5.3
CVE-2014-10388
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
Wp Support Plus Responsive Ticket System
4.2+
CRITICAL 9.8
CVE-2019-6177
A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standa…
Solution Center
Mitigation only
HIGH 7.5
CVE-2019-1908
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an…
Unified Computing System
2.0 / 3.0+
MEDIUM 5.3
CVE-2019-15045
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
Manageengine Servicedesk Plus
10509+
MEDIUM 6.5
CVE-2019-12746
An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS…
Debian Linux
after 6.0.19
MEDIUM 5.3
CVE-2019-4437
IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network via API swagger. IBM X-force ID…
Api Connect
after 2018.4.1.6
MEDIUM 5.5
CVE-2017-18550
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory becaus…
Linux Kernel
4.13+
MEDIUM 5.5
CVE-2017-18549
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory becaus…
Linux Kernel
4.13+
HIGH 7.5
CVE-2018-14669
ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arb…
Clickhouse
1.1.54390+
MEDIUM 5.3
CVE-2019-14800
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-ad…
Fv Flowplayer Video Player
7.3.15.727+