Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-1224EPSS 8%
An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory. An attacker who successfu…
Windows 10
Patch available
HIGH 7.5
CVE-2019-1225EPSS 10%
An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory. An attacker who successfu…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1227
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited t…
Windows 10
Patch available
MEDIUM 5.6
CVE-2019-1171
An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerabilit…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1158
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who succes…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1143
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who succes…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1078
An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory. An attacker who successfully…
Windows 10
Patch available
MEDIUM 5.3
CVE-2019-0338
During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set,…
Gateway
Mitigation only
HIGH 7.5
CVE-2019-13419
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
Search Guard
23.1+
MEDIUM 5.3
CVE-2019-13417
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for…
Search Guard
24.0+
HIGH 8.8
CVE-2016-10811
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
Cpanel
11.50.6.2 / 11.52.6.1+
MEDIUM 6.5
CVE-2018-20958
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are …
Tapplock Firmware
2018-06-12+
HIGH 8.8
CVE-2016-10809
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
Cpanel
11.50.6.2 / 11.52.6.1+
HIGH 8.8
CVE-2016-10810
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
Cpanel
11.50.6.2 / 11.52.6.1+
MEDIUM 6.5
CVE-2016-10794
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
Cpanel
11.52.6.6 / 11.54.0.29+
HIGH 7.5
CVE-2016-10790
cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192).
Cpanel
11.54.0.33 / 56.0.39+
MEDIUM 6.5
CVE-2016-10785
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
Cpanel
11.54.0.33 / 56.0.39+
MEDIUM 6.5
CVE-2016-10786
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
Cpanel
11.54.0.33 / 56.0.39+
HIGH 7.8
CVE-2019-3800
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --c…
Elasticsearch
1.16.0 / 2.1.2+
MEDIUM 6.5
CVE-2017-18474
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
Cpanel
11.54.0.36 / 56.0.43+
MEDIUM 6.5
CVE-2017-18478
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
Cpanel
11.54.0.36 / 56.0.43+
MEDIUM 5.3
CVE-2019-7852
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specifi…
Magento
2.1.18 / 2.2.9+
HIGH 7.8
CVE-2017-18432
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
Cpanel
56.0.49 / 58.0.49+
MEDIUM 5.5
CVE-2017-18396
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).
Cpanel
62.0.35 / 64.0.42+
MEDIUM 6.5
CVE-2016-10815
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
Cpanel
11.50.6.2 / 11.52.6.1+
MEDIUM 6.5
CVE-2018-20952
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
Cpanel
62.0.39 / 66.0.35+
MEDIUM 5.6
CVE-2018-20941
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
Cpanel
68.0.27+
MEDIUM 6.5
CVE-2016-10844
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
Cpanel
11.48.5.2 / 11.50.4.3+
MEDIUM 5.5
CVE-2018-20902
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
Cpanel
71.9980.37+
MEDIUM 5.4
CVE-2019-10156
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of informati…
Ansible
2.6.18 / 2.7.12+