Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2012-3331
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID…
Sametime
Mitigation only
MEDIUM 5.3
CVE-2018-6846
Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php.
Z Blogphp
Mitigation only
MEDIUM 6.5
CVE-2018-0140
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated…
Email Security Appliance Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-0127EPSS 77%
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unau…
Rv132w Firmware
Mitigation only
MEDIUM 5.3
CVE-2018-0134
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subs…
Mobility Services Engine
Mitigation only
HIGH 7.5
CVE-2018-1388
GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.
Websphere Mq
Mitigation only
MEDIUM 6.5
CVE-2018-6806
Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview…
Marked 2
after 2.5.11
MEDIUM 5.3
CVE-2018-6790
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover …
Plasma Workspace
5.12.0+
MEDIUM 5.5
CVE-2016-3954
web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: t…
Web2py
2.14.2+
MEDIUM 6.5
CVE-2017-6200
Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is…
Sandstorm
0.203+
HIGH 7.5
CVE-2018-6610EPSS 8%
Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.
Jlike
No fix yet
HIGH 7.8
CVE-2015-1418
The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1…
FreeBSD
Mitigation only
HIGH 7.5
CVE-2018-6188
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensiti…
Django
Patch available
CRITICAL 9.1
CVE-2018-6596
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which al…
Debian Linux
1.2.1+
HIGH 7.5
CVE-2016-0312
IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated…
Tririga Application Platform
after 3.3.1
MEDIUM 5.3
CVE-2018-6526
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parame…
Mantisbt
after 2.10.0
HIGH 8.8
CVE-2018-1192
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x version…
Cloud Foundry Uaa
1.7 / 4.5.5+
MEDIUM 6.5
CVE-2015-2203
Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by l…
Evergreen
Patch available
HIGH 7.5
CVE-2015-2204
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensit…
Evergreen
2.5.9 / 2.6.7+
MEDIUM 6.5
CVE-2013-7435
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive setting…
Evergreen
2.5.9 / 2.6.7+
MEDIUM 5.3
CVE-2018-6470
Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.
Nibbleblog
Mitigation only
HIGH 7.5
CVE-2018-6460EPSS 11%
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including …
Hotspot Shield
No fix yet
HIGH 7.5
CVE-2018-6412
In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary…
Linux Kernel
after 4.15
MEDIUM 5.5
CVE-2017-1784
IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-…
Cognos Analytics
Patch available
HIGH 7.5
CVE-2018-6008EPSS 37%
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.
Jtag Members Directory
No fix yet
HIGH 7.5
CVE-2018-6015
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=e…
Email Subscribers \& Newsletters
3.4.8+
MEDIUM 5.5
CVE-2018-5750
The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information…
Linux Kernel
after 4.14.15
MEDIUM 6.5
CVE-2017-1000505
In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coerc…
Script Security
after 1.36
MEDIUM 5.3
CVE-2018-4835
A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's port 8000/t…
Telecontrol Server Basic
3.1+
HIGH 7.5
CVE-2018-5319EPSS 12%
RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request.
Filehub Firmware
No fix yet