Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2019-7434
PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory.
Rental Bike Script
No fix yet
MEDIUM 6.5
CVE-2019-7436
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory.
Opensource Classified Ads Script
No fix yet
CRITICAL 9.8
CVE-2018-20555EPSS 10%
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, con…
Social Network Tabs
No fix yet
HIGH 7.5
CVE-2018-19487
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the adm…
Wp Jobhunt
2.4+
MEDIUM 6.5
CVE-2018-18762EPSS 6%
SaltOS 3.1 r8126 contains a database download vulnerability.
Saltos
No fix yet
MEDIUM 5.5
CVE-2018-17482
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the …
Lobby Track
Mitigation only
MEDIUM 5.5
CVE-2018-17483
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the …
Lobby Track
Mitigation only
HIGH 7.1
CVE-2018-17484
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk m…
Lobby Track
Mitigation only
HIGH 7.8
CVE-2018-17956
In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samb…
Yast2 Samba Provision
after 1.0.1
HIGH 7.5
CVE-2018-18205
Topvision CC8800 CMTS C-E devices allow remote attackers to obtain sensitive information via a direct request for /WebContent/startup.tar.gz with use…
Cc8800ce Firmware
Mitigation only
CRITICAL 9.1
CVE-2015-2254
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to capture and change patch loading information resu…
Oceanstor Uds Firmware
100r002c01spc102+
MEDIUM 6.8
CVE-2019-3615
Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose…
Database Security
after 4.6.6
MEDIUM 6.5
CVE-2018-2009
IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a lis…
Api Connect
after 2018.4.1.0
HIGH 7.5
CVE-2018-11783
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plug…
Traffic Server
after 8.0.1
HIGH 8.8
CVE-2019-3781
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remo…
Command Line Interface
6.43.0+
CRITICAL 9.8
CVE-2019-6206
An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.…
Iphone Os
12.1.3+
MEDIUM 5.3
CVE-2018-12400
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows informati…
Firefox
63.0+
HIGH 7.1
CVE-2018-12397
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being…
Firefox
60.3.0 / 63.0+
MEDIUM 5.3
CVE-2019-4061EPSS 23%
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to …
Bigfix Platform
after 9.5.11
MEDIUM 6.5
CVE-2018-1775
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated u…
Spectrum Virtualize Software
after 8.2
MEDIUM 5.5
CVE-2018-11845
Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdragon Auto, Snapdragon Compute,…
Mdm9150 Firmware
Mitigation only
HIGH 7.5
CVE-2019-9126
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is an information disclosure vulnerability via requests for the router_info.xml d…
Dir 825 Rev.b Firmware
No fix yet
MEDIUM 5.3
CVE-2014-10079EPSS 9%
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML so…
Storegrid
No fix yet
HIGH 7.5
CVE-2019-1681EPSS 6%
A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could allow an unauthenticated, remote attacker to retri…
Ios Xr
6.5.2+
MEDIUM 5.5
CVE-2019-3610
Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidenti…
True Key
after 3.1.9211.0
MEDIUM 5.5
CVE-2018-12006
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potenti…
Android
Patch available
HIGH 7.5
CVE-2018-20776
Frog CMS 0.9.5 provides a directory listing for a /public request.
Frog Cms
No fix yet
MEDIUM 5.9
CVE-2019-7628
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to …
Pagure
Patch available
HIGH 7.5
CVE-2018-1296
In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs,…
Hadoop
after 2.7.5
MEDIUM 5.3
CVE-2019-7535
index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and…
Testrail
Mitigation only