Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2018-1423
IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the syst…
Rational Collaborative Lifecycle Management
after 6.0.5
CRITICAL 9.8
CVE-2018-1337EPSS 5%
In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before…
Directory Ldap Api
1.0.2+
HIGH 7.5
CVE-2018-4993EPSS 87%
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft …
Acrobat Dc
after 18.011.20038
HIGH 7.5
CVE-2018-4965EPSS 10%
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Memory Corruption vul…
Acrobat Dc
15.006.30418 / 17.011.30080+
HIGH 8.8
CVE-2016-6538
The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, versio…
Trackr Bravo Firmware
2.2.5 / 5.1.6+
MEDIUM 6.5
CVE-2016-6540
Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by usi…
Trackr Bravo Firmware
2.2.5 / 5.1.6+
HIGH 7.8
CVE-2017-15851
Lack of copy_from_user and information leak in function "msm_ois_subdev_do_ioctl, file msm_ois.c can lead to a camera crash in all Android releases(A…
Android
Mitigation only
HIGH 7.5
CVE-2018-5892
The Touch Pal application can collect user behavior data without awareness by the user in Snapdragon Mobile and Snapdragon Wear.
Mdm9206 Firmware
No fix yet
MEDIUM 5.9
CVE-2018-1546
IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP …
Api Connect
after 5.0.8.3
MEDIUM 5.3
CVE-2017-1239
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID:…
Rational Quality Manager
after 6.0.5
MEDIUM 5.3
CVE-2017-1488
An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627.
Rational Collaborative Lifecycle Management
after 6.0.5
MEDIUM 6.5
CVE-2018-9998
Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names i…
Open Xchange Appsuite
after 7.6.3
MEDIUM 6.5
CVE-2018-12021
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, …
Singularity
after 2.5.1
HIGH 8.1
CVE-2018-9185
An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file…
Fortios
after 6.0.0
CRITICAL 9.8
CVE-2018-13123
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&…
Onefilecms
after 2017-10-09
HIGH 7.1
CVE-2018-10596
Medtronic 2090 CareLink Programmer
uses a virtual private network connection to securely download updates. It does not verify it is still connected…
2090 Carelink Programmer Firmware
Mitigation only
CRITICAL 9.9
CVE-2018-12892
An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl…
Debian Linux
after 4.10.1
MEDIUM 5.3
CVE-2018-12990
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
Phpwcms
No fix yet
HIGH 7.5
CVE-2018-12997EPSS 7%
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before bui…
Firewall Analyzer
No fix yet
HIGH 7.5
CVE-2018-12920
Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettings or bas…
Brickstream 2300 Firmware
Mitigation only
HIGH 7.5
CVE-2018-12921
Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_info…
Gaugetech Nexus Firmware
No fix yet
HIGH 7.5
CVE-2018-12923
BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request for the #!/system URI.
Ha Bridge
Mitigation only
HIGH 7.5
CVE-2018-12926
Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the default/index.lsp or default/…
Pharos Firmware
Mitigation only
HIGH 7.5
CVE-2018-12927
Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/…
Northern Electric \& Power Inverter Firmware
Mitigation only
HIGH 7.5
CVE-2018-1306EPSS 44%
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive i…
Pluto
No fix yet
HIGH 7.5
CVE-2018-1553
IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of ex…
Websphere Application Server
18.0.0.2+
CRITICAL 9.8
CVE-2018-12908EPSS 11%
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct r…
Brynamics
No fix yet
HIGH 8.8
CVE-2018-5436
The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multi…
Spotfire Analytics Platform For Aws
after 7.12.0
HIGH 7.5
CVE-2018-12907
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of an…
Rclone
Mitigation only
HIGH 7.5
CVE-2018-1614
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker …
Websphere Application Server
Mitigation only