Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2018-16224EPSS 7%
Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to retrieve them via a specifically…
Cubeone Firmware
after 2.2.4.10
MEDIUM 5.5
CVE-2018-1841
IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150…
Cloud Private
Mitigation only
MEDIUM 6.5
CVE-2018-1639
The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user to obtain sensitive informatio…
Jazz Reporting Service
after 6.0.6
MEDIUM 6.5
CVE-2018-7360
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may allow an unauthenticated attac…
Zxhn F670 Firmware
1.1.10p3t18+
MEDIUM 5.3
CVE-2018-9071
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authenticat…
Chassis Management Module Firmware
2.0.0+
MEDIUM 5.5
CVE-2018-9543
In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a factory reset. This could lead to local informati…
Android
Patch available
HIGH 7.5
CVE-2018-9526
In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device location. User interaction is…
Android
Patch available
MEDIUM 6.5
CVE-2018-6066
Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-orig…
Chrome
65.0.3325.146+
MEDIUM 6.5
CVE-2018-6075
Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin da…
Chrome
65.0.3325.146+
MEDIUM 6.5
CVE-2018-6077
Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacke…
Chrome
65.0.3325.146+
MEDIUM 6.5
CVE-2018-6079
Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to …
Chrome
65.0.3325.146+
MEDIUM 6.5
CVE-2018-17468
Incorrect handling of timer information during navigation in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obtain cross o…
Chrome
70.0.3538.67+
MEDIUM 6.5
CVE-2018-3621
Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable informat…
Driver\&support Assistant
3.6.0.4+
MEDIUM 6.5
CVE-2018-8558EPSS 6%
An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the SharePoint Onl…
Office
Patch available
MEDIUM 5.5
CVE-2018-8565
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Win32k Information Disclosure V…
Windows 10
Patch available
MEDIUM 5.5
CVE-2018-8454
An information disclosure vulnerability exists when Windows Audio Service fails to properly handle objects in memory, aka "Windows Audio Service Info…
Windows 10
Patch available
MEDIUM 5.5
CVE-2018-6260
NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the …
Gpu Driver
Mitigation only
MEDIUM 5.5
CVE-2018-15771
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability. A…
Recoverpoint
5.1.2.1 / 5.2.0.2+
MEDIUM 6.5
CVE-2018-18591
A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9.30, 9.31, 9.32, 9.33, 9.34, …
Service Manager
No fix yet
HIGH 7.5
CVE-2018-19246EPSS 22%
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their…
Php Proxy
No fix yet
MEDIUM 5.3
CVE-2018-19226
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to list .txt files via a direct request for the /data/0/admin.txt URI.
Laobancms
No fix yet
HIGH 7.5
CVE-2018-19205
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a rel…
Webmail
1.3.7+
MEDIUM 5.3
CVE-2018-19194
An issue was discovered in XiaoCms 20141229. /admin/index.php?c=database allows full path disclosure in a "failed to open stream" error message.
Xiaocms
No fix yet
MEDIUM 5.3
CVE-2018-19133
In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address.
Flarum
Patch available
MEDIUM 6.5
CVE-2018-1857
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn…
Db2
Mitigation only
HIGH 7.5
CVE-2018-19045
keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.
Keepalived
Patch available
HIGH 7.5
CVE-2018-15446
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is…
Meeting Server
Mitigation only
MEDIUM 5.3
CVE-2018-19075
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…
I5 Application Firmware
No fix yet
HIGH 8.8
CVE-2018-18590
A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge containerized suite versions 2017.…
Operations Bridge
Mitigation only
HIGH 7.5
CVE-2018-9489
When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including detailed wifi network informa…
Android
Mitigation only