Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2018-20870
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
Cpanel
76.0.8+
MEDIUM 5.3
CVE-2018-17211
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers asso…
Central Print Services
after 4.1.4
MEDIUM 6.5
CVE-2015-9288
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credenti…
Web Player
4.6.6f2 / 5.0.3f2+
MEDIUM 5.3
CVE-2019-14280EPSS 9%
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so,…
Craft Cms
2.7.10 / 3.2.6+
HIGH 7.5
CVE-2019-0202
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i…
Storm
after 1.2.2
HIGH 7.5
CVE-2018-13897
Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Snapdragon Auto, Snapdragon Conn…
Mdm9206 Firmware
Patch available
HIGH 7.5
CVE-2019-1010283
Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure. The impact …
Univention Corporate Server
after 12.0.1-3
MEDIUM 5.3
CVE-2018-2022
IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system…
Qradar Security Information And Event Manager
7.2.8+
HIGH 8.8
CVE-2019-1575
Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow f…
Pan Os
7.1.24 / 8.0.19+
MEDIUM 6.5
CVE-2019-1108EPSS 11%
An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Proto…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1112EPSS 9%
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information…
Office
Patch available
MEDIUM 5.5
CVE-2019-1091
An information disclosure vulnerability exists when Unistore.dll fails to properly handle objects in memory, aka 'Microsoft unistore.dll Information …
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1093
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-1094EPSS 7%
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-1095EPSS 7%
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1096
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure V…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1097
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1071
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosu…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1073
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosu…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-1084EPSS 5%
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authe…
Exchange Server
Patch available
MEDIUM 5.3
CVE-2019-1010299
The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitializ…
Rust
1.30.0+
MEDIUM 6.5
CVE-2014-10374
On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this leads to "permanent trackabi…
Charge 2 Firmware
Mitigation only
MEDIUM 5.3
CVE-2019-1010024
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: g…
Glibc
No fix yet
HIGH 7.5
CVE-2019-4193
IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthor…
Jazz For Service Management
after 1.1.3.2
MEDIUM 5.3
CVE-2018-1968
IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on th…
Security Identity Manager Virtual Appliance
after 7.0.1.12
MEDIUM 5.8
CVE-2019-0048
On EX4300 Series switches with TCAM optimization enabled, incoming multicast traffic matches an implicit loopback filter rule first, since it has hig…
Junos
Patch available
CRITICAL 9.8
CVE-2019-11991
HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.…
3par Service Processor Firmware
after 4.4
HIGH 7.5
CVE-2018-14529
Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes.
Nvx220 Firmware
No fix yet
HIGH 7.8
CVE-2019-13313
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the comm…
Fedora
Patch available
HIGH 7.8
CVE-2019-13314
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password…
Virt Bootstrap
No fix yet