Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-7668
TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.
Testlink
after 1.9.16
MEDIUM 5.3
CVE-2018-7662EPSS 47%
Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/php…
Couch
after 2.0
MEDIUM 5.3
CVE-2018-7661
Papenmeier WiFi Baby Monitor Free & Lite before 2.02.2 allows remote attackers to obtain audio data via certain requests to TCP ports 8258 and 8257.
Wifi Baby Monitor
2.02.2+
HIGH 7.5
CVE-2017-9280
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of use…
Identity Manager
4.5.6.1+
HIGH 7.1
CVE-2017-14461EPSS 17%
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive info…
Debian Linux
Patch available
HIGH 8.1
CVE-2017-6926
In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access t…
Drupal
8.4.5+
HIGH 7.5
CVE-2017-5188
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source director…
Open Build Service
after 2.7.3
MEDIUM 5.3
CVE-2016-0299
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive informati…
Tririga Application Platform
3.3.2.6 / 3.4.2.3+
CRITICAL 9.1
CVE-2018-7556
LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installatio…
Debian Linux
2.6.7 / 2.73.1+
MEDIUM 6.5
CVE-2017-16770
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.…
Surveillance Station
8.1.2-5469+
HIGH 7.5
CVE-2017-11635
An issue was discovered on Wireless IP Camera 360 devices. Attackers can read recordings by navigating to /mnt/idea0 or /mnt/idea1 on the SD memory c…
Wireless Ip Camera 360
No fix yet
MEDIUM 5.5
CVE-2018-7250
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped i…
Windows 7
Mitigation only
MEDIUM 5.3
CVE-2017-1774
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 discloses sensitive information to unauthorized users. The information can be used to mount …
Security Guardium Big Data Intelligence
Mitigation only
HIGH 7.5
CVE-2017-15696
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration req…
Geode
after 1.3.0
HIGH 7.8
CVE-2017-15518
All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password.…
Oncommand Api Services
after 2.0
MEDIUM 5.3
CVE-2017-16769
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from pa…
Photo Station
Mitigation only
HIGH 7.5
CVE-2018-7317EPSS 8%
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
Proclaim
No fix yet
HIGH 7.5
CVE-2018-7276
An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain potentially sensitive inform…
Quantum Bacnet Integration Firmware
No fix yet
MEDIUM 6.5
CVE-2018-7272
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding…
Access Management
5.5.0+
MEDIUM 5.5
CVE-2018-7273
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the fu…
Linux Kernel
after 4.15.4
HIGH 7.5
CVE-2018-6487
Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, …
Universal Cmdb Foundation Software
No fix yet
MEDIUM 5.8
CVE-2018-5477
An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior,…
Netcadops
7.2.10+
MEDIUM 5.3
CVE-2015-9255
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machine…
Alto 3 Firmware
Mitigation only
MEDIUM 5.3
CVE-2015-9256
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not…
Alto 3 Firmware
Mitigation only
HIGH 7.5
CVE-2017-18192
smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to ac…
Photo\,video Locker Calculator
after 18.0
CRITICAL 9.8
CVE-2018-7251EPSS 72%
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQ…
Anchor
No fix yet
MEDIUM 5.3
CVE-2018-6591
Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe p…
Converse.js
after 3.3
HIGH 7.5
CVE-2018-7209
An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idashboards/conf…
Idashboards
after 9.6b
HIGH 7.5
CVE-2018-7210
An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idb/config?CMD=i…
Idashboards
after 9.6b
MEDIUM 5.3
CVE-2018-1000068
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to acces…
Jenkins
after 2.106