Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2019-5601
In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a b…
FreeBSD
No fix yet
MEDIUM 6.5
CVE-2018-14865
Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passin…
Odoo
Patch available
CRITICAL 9.8
CVE-2018-11215
Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.
Data Science Workbench
after 1.3.0
MEDIUM 5.9
CVE-2017-11578
It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web m…
Wi Fi Blood Pressure Monitor Firmware
No fix yet
HIGH 8.8
CVE-2019-7259EPSS 13%
Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
Linear Emerge Essential Firmware
after 1.00-06
HIGH 7.1
CVE-2019-4140
IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IB…
Spectrum Protect
7.1.9.300 / 8.1.8.0+
MEDIUM 5.3
CVE-2019-13075
Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involvin…
Tor Browser
after 8.5.3
MEDIUM 6.5
CVE-2019-13055
Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency tra…
Unifying Receiver Firmware
No fix yet
MEDIUM 6.5
CVE-2019-10175
A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine wheth…
Containerized Data Importer
Mitigation only
MEDIUM 5.3
CVE-2018-20811
A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.
Connect Secure
No fix yet
HIGH 7.5
CVE-2018-20812
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse S…
Pulse Secure Desktop Client
Mitigation only
MEDIUM 6.5
CVE-2018-6150
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted…
Chrome
66.0.3359.117+
MEDIUM 6.5
CVE-2018-6159
Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive inf…
Chrome
68.0.3440.75+
MEDIUM 6.5
CVE-2018-6168
Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from pr…
Chrome
68.0.3440.75+
MEDIUM 5.5
CVE-2018-20073
Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem.
Chrome
72.0.3626.81+
MEDIUM 6.5
CVE-2018-6134
Information leak in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page.
Chrome
67.0.3396.62+
MEDIUM 5.3
CVE-2018-2011
IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could ai…
Api Connect
after 2018.4.1.5
MEDIUM 5.3
CVE-2018-2013
IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the …
Api Connect
after 2018.4.1.5
HIGH 7.5
CVE-2014-9699
The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs, design files (i.e., a histor…
Replicator 5th Generation Firmware
Mitigation only
HIGH 7.5
CVE-2019-11648
An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be…
Self Service Password Reset
4.4+
MEDIUM 5.3
CVE-2018-15665
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.
Data Science Workbench
after 1.4.0
CRITICAL 9.8
CVE-2016-7404
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the inst…
Magnum
Patch available
HIGH 7.5
CVE-2019-11233
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information without being authenticated, by sending a LOGIN_ID element to the au…
Biyan
after 2.8
HIGH 8.8
CVE-2017-8337
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of…
Almond 2015 Firmware
No fix yet
MEDIUM 5.3
CVE-2018-18839
An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "is intentional.
Netdata
Patch available
MEDIUM 6.5
CVE-2017-10719
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-F…
Endoscope Camera Firmware
No fix yet
CRITICAL 9.1
CVE-2019-5016
An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of…
R8000 Firmware
Mitigation only
MEDIUM 5.3
CVE-2019-5017
An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadySHARE Printer functionality of…
R8000 Firmware
Mitigation only
HIGH 7.2
CVE-2019-11407
app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessiv…
Fusionpbx
Patch available
MEDIUM 5.3
CVE-2019-12497
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x…
Debian Linux
after 7.0.8