Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-15967EPSS 8%
Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information discl…
Enterprise Linux Desktop
after 31.0.0.108
MEDIUM 5.3
CVE-2018-15962EPSS 6%
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerability. …
Coldfusion
Mitigation only
HIGH 7.5
CVE-2018-15964EPSS 8%
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known v…
Coldfusion
Mitigation only
MEDIUM 5.5
CVE-2018-10498
This vulnerability allows local attackers to disclose sensitive information on vulnerable installations of Samsung Email Fixed in version 5.0.02.16. …
Samsung Email
5.0.02.16+
MEDIUM 5.3
CVE-2018-17402
The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to discover the Credit/Debit card number,…
Phonepe
after 3.3.26
MEDIUM 5.3
CVE-2018-17404
The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow an attacker to sniff private information such as mobile number, P…
Sbi Buddy
No fix yet
HIGH 7.5
CVE-2018-14731
An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because the origin of requests is not …
Parcel
Patch available
HIGH 7.5
CVE-2018-14730
An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocke…
Browserify Hot Module Replacement
No fix yet
MEDIUM 5.5
CVE-2013-7203
gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running git…
Gitolite
after 3.5.3
MEDIUM 5.9
CVE-2018-8023
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2…
Mesos
1.4.2+
MEDIUM 5.5
CVE-2018-1685
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a l…
Db2
Mitigation only
HIGH 8.8
CVE-2018-3831
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API…
Elasticsearch
5.6.12 / 6.4.1+
MEDIUM 6.5
CVE-2018-3826
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are …
Elasticsearch
after 6.2.4
MEDIUM 5.3
CVE-2018-16671EPSS 9%
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/…
Circarlife Scada
4.3+
MEDIUM 5.5
CVE-2018-11275
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when flashing image using FastbootLib if …
Android
Patch available
MEDIUM 5.3
CVE-2018-14642
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flus…
Undertow
Patch available
MEDIUM 5.3
CVE-2018-16959
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile commun…
Webcenter Interaction
Mitigation only
MEDIUM 6.5
CVE-2017-14443
An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks …
Hub 2245 222 Firmware
No fix yet
MEDIUM 5.4
CVE-2018-17091
An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via a direct request for files/te…
Donlinkage
No fix yet
HIGH 8.6
CVE-2018-16288EPSS 36%
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
Supersign Cms
No fix yet
MEDIUM 5.3
CVE-2018-1698
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information from error messages. IBM X-Forc…
Maximo Asset Management
after 7.6.3
MEDIUM 5.5
CVE-2018-8446
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…
Windows 10
Patch available
MEDIUM 5.5
CVE-2018-8442
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…
Windows 10
Patch available
MEDIUM 5.5
CVE-2018-8443
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…
Windows 10
Patch available
MEDIUM 5.9
CVE-2018-8444EPSS 6%
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka "W…
Windows 10
Patch available
MEDIUM 5.5
CVE-2018-8445
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…
Windows 10
Patch available
MEDIUM 5.5
CVE-2018-8429EPSS 12%
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information…
Excel
Patch available
MEDIUM 5.4
CVE-2018-8434
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated…
Windows 10
Patch available
MEDIUM 6.5
CVE-2018-8422EPSS 6%
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…
Windows 7
Patch available
MEDIUM 6.5
CVE-2018-8424EPSS 13%
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…
Windows 10
Patch available