Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2018-15668
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send ar…
Airmail 3
Mitigation only
HIGH 7.5
CVE-2018-15661
An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker controls an application with access…
Ola Money
Mitigation only
CRITICAL 9.8
CVE-2018-15534EPSS 32%
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a …
Re Porter 16 Firmware
7.8.974.20+
MEDIUM 5.3
CVE-2018-15599
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validi…
Debian Linux
after 2018.76
MEDIUM 5.5
CVE-2015-5160
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sen…
Virtualization
Mitigation only
HIGH 7.5
CVE-2018-14079
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to obtain sensitive information via /Status/SystemStatusRpm.esp.
Smart Hp Wmt
Mitigation only
MEDIUM 6.5
CVE-2018-1000645
LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file dis…
Librehealth Ehr
2.0.0+
MEDIUM 6.7
CVE-2018-1000635
The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vulnerability in OMERO.server t…
Omero
after 5.4.6
HIGH 7.2
CVE-2018-1000633
The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the login form a…
Omero
5.4.7+
MEDIUM 5.5
CVE-2018-15594
arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectr…
Debian Linux
4.18.1+
MEDIUM 5.3
CVE-2017-1732
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attacke…
Security Access Manager For Enterprise Single Sign On
Patch available
MEDIUM 6.5
CVE-2018-15357
An authenticated attacker with low privileges can extract password hash information for all users in Eltex ESP-200 firmware version 1.2.0.
Esp 200 Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-8398EPSS 8%
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…
Windows 10
Mitigation only
MEDIUM 6.5
CVE-2018-8394EPSS 8%
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…
Windows 10
Mitigation only
MEDIUM 5.5
CVE-2018-8382EPSS 12%
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information…
Excel
Patch available
HIGH 7.5
CVE-2018-8360EPSS 9%
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environ…
.net Framework
Patch available
MEDIUM 5.6
CVE-2018-3646EPSS 8%
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in th…
Core I3
Mitigation only
HIGH 8.1
CVE-2018-14348
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.
Debian Linux
after 0.41
HIGH 7.5
CVE-2018-15125
Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface.
Zipabox Firmware
No fix yet
MEDIUM 5.0
CVE-2017-15138
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook…
Openshift Container Platform
Patch available
MEDIUM 6.5
CVE-2017-1286
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has b…
Urbancode Deploy
after 6.9.6.0
HIGH 7.5
CVE-2018-14782
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and pr…
Nwl 25 Firmware
after 2.0.29.11
HIGH 7.5
CVE-2018-14785
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly without a…
Nwl 25 Firmware
after 2.0.29.11
HIGH 7.5
CVE-2018-7686
Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.
Edirectory
after 9.1.1
HIGH 7.5
CVE-2018-10915EPSS 5%
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections…
Openstack
Patch available
HIGH 7.5
CVE-2018-14735
An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of mes…
Compute Systems Manager
8.6.0-02 / 8.6.1-02+
MEDIUM 5.5
CVE-2018-5953
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by re…
Linux Kernel
after 4.14.14
MEDIUM 5.5
CVE-2018-5995
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by …
Linux Kernel
after 4.14.14
HIGH 7.5
CVE-2018-15132EPSS 5%
An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The link…
PHP
5.6.37 / 7.0.31+
MEDIUM 5.3
CVE-2017-2654
jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically…
Email Extension
2.57.1+