Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2019-2102
In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were to use this as a hardcoded LTK…
Android
Mitigation only
HIGH 8.8
CVE-2017-18376
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to esc…
Thehive
2.13.4 / 3.3.1+
HIGH 8.8
CVE-2019-10132
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati…
Libvirt
after 4.1.0
MEDIUM 6.7
CVE-2019-1727
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser an…
Nx Os
7.0 / 7.3+
MEDIUM 6.7
CVE-2019-1730
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command …
Nx Os
7.0 / 8.3+
MEDIUM 6.7
CVE-2019-1803
A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allo…
Nexus 9000 Series Application Centric Infrastructure
Mitigation only
HIGH 7.8
CVE-2019-1592
A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software c…
Nx Os
Mitigation only
HIGH 7.8
CVE-2019-1682
A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authentica…
Application Policy Infrastructure Controller
4.1+
CRITICAL 9.8
CVE-2016-1579
UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functiona…
Ubuntu Download Manager
Mitigation only
HIGH 7.8
CVE-2015-1341
Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Ap…
Ubuntu Linux
2.19.2+
HIGH 7.8
CVE-2019-0730
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privi…
Windows 10
Patch available
HIGH 7.8
CVE-2019-0731
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privi…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-0796
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privi…
Windows 10
Patch available
HIGH 7.8
CVE-2019-10885
An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed se…
Workspace Control
10.3.90.0+
HIGH 8.8
CVE-2015-3965
Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privi…
Symbiq Infusion System Firmware
after 3.13
HIGH 7.5
CVE-2016-9166
NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.
Netiq Edirectory
9.0+
HIGH 7.8
CVE-2019-0121
Improper permissions in Intel(R) Matrix Storage Manager 8.9.0.1023 and before may allow an authenticated user to potentially enable escalation of pri…
Matrix Storage Manager
after 8.9.0.1023
HIGH 7.8
CVE-2019-0129
Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially enable escalation of privilege …
Usb 3.0 Creator Utility
Mitigation only
HIGH 7.8
CVE-2019-0135
Improper permissions in the installer for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an authenticated …
Rapid Storage Technology Enterprise
5.5.0.2015+
HIGH 7.5
CVE-2019-9768EPSS 12%
Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for…
Canarytokens
after 2019-03-01
CRITICAL 9.8
CVE-2019-1723EPSS 6%
A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device b…
Common Services Platform Collector
2.7.4.6 / 2.8.1.2+
HIGH 7.5
CVE-2019-9637EPSS 7%
An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented,…
PHP
7.1.27 / 7.2.16+
HIGH 7.8
CVE-2019-1602
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that coul…
Nx Os
7.0+
HIGH 8.8
CVE-2019-3779
Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust …
Container Runtime
0.29.0+
HIGH 7.8
CVE-2019-1596
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege le…
Nx Os
7.0+
HIGH 7.8
CVE-2019-1591
A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local atta…
Nx Os
14.0+
HIGH 7.8
CVE-2019-1593
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege le…
Nx Os
7.0 / 8.2+
HIGH 7.4
CVE-2019-1594
A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service …
Nx Os
5.2 / 6.2+
HIGH 7.8
CVE-2019-3475
A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege us…
Filr
No fix yet
MEDIUM 5.3
CVE-2019-1660
A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, rem…
Telepresence Management Suite
Mitigation only