Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-12301
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.…
Nas Os
Mitigation only
MEDIUM 5.3
CVE-2019-5437
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp …
Harp
after 0.29.0
HIGH 7.5
CVE-2018-7083
If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time i…
Aruba Instant
4.2.4.12 / 6.5.4.11+
HIGH 7.5
CVE-2017-12884
OX Software GmbH App Suite 7.8.4 and earlier is affected by: Information Exposure.
Open Xchange Appsuite
after 7.8.4
MEDIUM 5.3
CVE-2018-1990
IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration information using a specially …
Cloud App Management
Patch available
HIGH 7.5
CVE-2016-1600
The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.
Identity Manager
4.6+
HIGH 7.5
CVE-2018-19456
The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive information from server folders…
Wpbackupplus
after 2018-11-22
MEDIUM 5.3
CVE-2018-13991
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images.
Fl Switch 3005 Firmware
after 1.34
HIGH 7.5
CVE-2018-18975
An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communications between the app and Asce…
Contour Diabetes
2.4.30+
HIGH 7.5
CVE-2018-18977
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reverse engineer the codebase to …
Contour Diabetes
2.5.0+
MEDIUM 6.5
CVE-2018-4067
An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.…
Airlink Es450 Firmware
No fix yet
HIGH 8.8
CVE-2018-4070EPSS 18%
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…
Airlink Es450 Firmware
No fix yet
HIGH 8.8
CVE-2018-4071EPSS 19%
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…
Airlink Es450 Firmware
No fix yet
MEDIUM 5.3
CVE-2018-4068EPSS 11%
An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request …
Airlink Es450 Firmware
Mitigation only
HIGH 7.5
CVE-2018-4069
An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManag…
Airlink Es450 Firmware
No fix yet
MEDIUM 5.3
CVE-2019-3797
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘…
Spring Data Java Persistence Api
after 2.1.5
MEDIUM 5.3
CVE-2019-1692
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenti…
Application Policy Infrastructure Controller
4.1+
HIGH 7.5
CVE-2019-11633
HoneyPress through 2016-09-27 can be fingerprinted by attackers because of the ingrained unique www.atxsec.com and ayylmao.wpengine.com hostnames wit…
Honeypress
after 2016-09-27
MEDIUM 5.5
CVE-2018-20509
The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address informat…
Linux Kernel
Mitigation only
MEDIUM 5.5
CVE-2018-20510
The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address …
Linux Kernel
Mitigation only
MEDIUM 5.3
CVE-2018-1961
IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from error messages. IBM X-Force …
Emptoris Contract Management
after 10.1.3.0
MEDIUM 5.3
CVE-2019-10246
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource dir…
Jetty
after 3.1.3
MEDIUM 5.3
CVE-2019-10247EPSS 6%
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combinati…
Debian Linux
after 3.1.3
HIGH 8.6
CVE-2011-3147
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesyst…
Nova
2012.1+
CRITICAL 9.8
CVE-2019-11403
In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings …
Build Cache Node
5.2 / 2018.5.2+
MEDIUM 5.3
CVE-2018-1729
IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-…
Qradar Security Information And Event Manager
after 7.3.2
MEDIUM 5.3
CVE-2019-9225
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect A…
GitLab
11.6.10 / 11.7.6+
MEDIUM 5.3
CVE-2019-9175
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Informat…
GitLab
11.6.10 / 11.7.6+
HIGH 7.2
CVE-2018-13378
An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source…
Fortisiem
after 5.2.0
CRITICAL 9.1
CVE-2018-13808
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). An attacker with network access to port 23/tcp could extract i…
Cp 1604 Firmware
after 2.8