Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2018-11645
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine…
Ghostscript
after 9.20
HIGH 8.8
CVE-2016-10533
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3…
Express Restify Mongoose
after 3.0.1
MEDIUM 5.3
CVE-2015-9236
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allo…
Hapi
11.0.0+
HIGH 7.5
CVE-2016-10519
A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a listening peer and get it to…
Bittorrent Dht
5.1.3+
MEDIUM 5.9
CVE-2016-10530
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys …
Airbrake
after 0.3.8
CRITICAL 9.1
CVE-2018-11036
Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and …
Vsz Firmware
Mitigation only
MEDIUM 5.3
CVE-2018-11565
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by pe…
Mahara
17.04.8 / 17.10.5+
MEDIUM 6.5
CVE-2018-11435
The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access vi…
Libmobi
No fix yet
MEDIUM 6.5
CVE-2018-11437
The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) v…
Libmobi
No fix yet
HIGH 7.5
CVE-2017-16047
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Mysqljs
Mitigation only
HIGH 7.5
CVE-2017-16061
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Tkinter
Mitigation only
HIGH 7.5
CVE-2017-16062
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Node Tkinter
Mitigation only
MEDIUM 5.3
CVE-2018-10732
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of …
Data Science Studio
4.2.3+
MEDIUM 5.3
CVE-2018-11517
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t…
Mypro
No fix yet
MEDIUM 5.5
CVE-2018-11508
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel mem…
Linux Kernel
4.16.9+
HIGH 7.5
CVE-2018-11505EPSS 9%
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
Werewolf Online
No fix yet
MEDIUM 5.3
CVE-2017-14185
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to ac…
Fortios
after 5.6.2
MEDIUM 5.5
CVE-2018-6234
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose s…
Antivirus\+
after 12.0
MEDIUM 5.9
CVE-2018-11469
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to ac…
Ubuntu Linux
after 1.8.9
HIGH 7.5
CVE-2018-1467
The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. IBM X-Force ID: 140398.
Storwize Unified V7000 Software
Mitigation only
MEDIUM 6.5
CVE-2018-1135
An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by chan…
Moodle
after 3.4.2
MEDIUM 5.3
CVE-2013-3018
The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote at…
Tivoli Application Dependency Discovery Manager
after 7.2.1.4
HIGH 8.1
CVE-2013-3023
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive informat…
Tivoli Application Dependency Discovery Manager
after 7.2.1.4
HIGH 7.5
CVE-2018-10652
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
Xenmobile Server
No fix yet
MEDIUM 5.5
CVE-2018-7268
MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in whic…
Sysinfo
10-h81+
HIGH 7.5
CVE-2018-4925
Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability. Successful exploitation could lead to informati…
Digital Editions
after 4.5.7
HIGH 7.5
CVE-2018-5256
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ w…
Tectonic
1.7.9-tectonic.4 / 1.8.4-tectonic.3+
HIGH 7.5
CVE-2018-1433
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…
Storwize V7000 Firmware
7.5.0.14 / 7.7.1.9+
HIGH 7.5
CVE-2018-1438
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…
Storwize V7000 Firmware
7.5.0.14 / 7.7.1.9+
MEDIUM 6.5
CVE-2018-1464
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…
Storwize V7000 Firmware
7.5.0.14 / 7.7.1.9+