Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2019-4173
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive information, caused by a flaw in t…
Cognos Controller
Patch available
MEDIUM 5.5
CVE-2018-11942
Failure to initialize the reserved memory which is sent to the firmware might lead to exposure of 1 byte of uninitialized kernel SKB memory to FW in …
Ipq4019 Firmware
Patch available
MEDIUM 6.8
CVE-2018-10946
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user'…
Realpresence Debut Firmware
1.3.0-66872+
HIGH 8.5
CVE-2019-1019EPSS 14%
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.
To exploit this vulnerab…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-1023EPSS 5%
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge. An attacker wh…
Chakracore
1.11.10+
MEDIUM 6.5
CVE-2019-0990EPSS 5%
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). Th…
Chakracore
1.11.10+
MEDIUM 5.3
CVE-2019-3579
MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a password-reset request that la…
Mybb
Mitigation only
MEDIUM 5.3
CVE-2018-7122
A remote disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Intelligent Management Center
7.3+
MEDIUM 5.6
CVE-2018-12126
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticat…
Fedora
No fix yet
MEDIUM 5.6
CVE-2018-12127
Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated use…
Fedora
No fix yet
MEDIUM 5.9
CVE-2018-12130
Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated…
Fedora
No fix yet
MEDIUM 5.3
CVE-2018-15131
An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, a…
Zimbra Collaboration Suite
8.7.11 / 8.8.8+
MEDIUM 5.3
CVE-2018-13365
An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of Fort…
Fortios
after 6.0.1
MEDIUM 6.5
CVE-2019-9866
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.
GitLab
11.7.7 / 11.8.3+
MEDIUM 6.5
CVE-2018-10815
An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive clus…
Cloudera Manager
5.13.4 / 5.14.4+
MEDIUM 5.5
CVE-2018-11976
ECDSA signature code leaks private keys from secure world to non-secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdr…
Ipq8074 Firmware
Mitigation only
MEDIUM 5.5
CVE-2018-12004
Secure keypad is unlocked with secure display still intact in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snap…
Mdm9206 Firmware
Mitigation only
MEDIUM 5.5
CVE-2018-13885
Possible memory overread may be lead to access of sensitive data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industri…
Mdm9150 Firmware
Mitigation only
MEDIUM 5.3
CVE-2017-11557
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names a…
Manageengine Applications Manager
No fix yet
MEDIUM 5.5
CVE-2017-15652
Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file…
Ghostscript
Patch available
CRITICAL 9.8
CVE-2017-5210
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.
Open Xchange Appsuite
after 7.8.3
HIGH 7.5
CVE-2018-7844
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which co…
Modicon Premium Firmware
No fix yet
HIGH 7.5
CVE-2018-7848
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which co…
Modicon M580 Firmware
2.90 / 3.10+
MEDIUM 5.3
CVE-2017-9809
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.
Open Xchange Appsuite
after 7.8.4
MEDIUM 5.3
CVE-2017-6514
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/o…
WordPress
Mitigation only
CRITICAL 9.1
CVE-2019-7353
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to …
GitLab
11.7.4+
MEDIUM 5.3
CVE-2019-10109
An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.…
GitLab
11.7.8 / 11.8.4+
CRITICAL 9.1
CVE-2019-6572
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 1…
Simatic Hmi Comfort Panels Firmware
15.1+
HIGH 7.5
CVE-2019-6574
A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with opti…
Sinamics Perfect Harmony Gh180 With Nxg I Control Mlfb 6sr2 Firmware
Mitigation only
HIGH 7.5
CVE-2018-16656
DoBox_CstmBox_Info.model.htm on Kyocera TASKalfa 4002i and 6002i devices allows remote attackers to read the documents of arbitrary users via a modif…
Taskalfa 4002i Firmware
No fix yet