Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.7
CVE-2011-2910
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping …
Debian Linux
0.0.8-13+
HIGH 8.8
CVE-2019-15799
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, w…
Gs1900 8 Firmware
2.50+
MEDIUM 5.5
CVE-2019-14590
Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially ena…
Graphics Driver
26.20.100.7209+
HIGH 8.8
CVE-2019-3651
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO …
Advanced Threat Defense
4.8+
HIGH 8.8
CVE-2010-4664
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their…
Debian Linux
0.4.2+
HIGH 7.8
CVE-2019-2193
In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lea…
Android
Mitigation only
HIGH 7.8
CVE-2019-1405 KEVEPSS 30%
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Wi…
Windows 10 1507
Patch available
HIGH 7.8
CVE-2019-1388 KEVEPSS 9%
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Cert…
Windows 10 1507
Patch available
HIGH 7.1
CVE-2019-18845
The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbi…
Viper Rgb Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-18623
Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public da…
Energycap
after 7.5.6
CRITICAL 9.8
CVE-2006-4243
linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.
Linux Vserver
2.6.17+
HIGH 7.8
CVE-2013-4251
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
Fedora
0.12.1+
HIGH 7.3
CVE-2013-2012
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.
Debian Linux
21.5.8+
CRITICAL 9.8
CVE-2019-18425
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. Ther…
Debian Linux
after 4.12.1
HIGH 8.8
CVE-2018-18931
An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permissions on the C:\TRMS\Service…
Carousel Digital Signage
after 7.0.4.104
HIGH 8.8
CVE-2019-4546
After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allo…
Maximo For Oil And Gas
Mitigation only
CRITICAL 9.8
CVE-2019-16897
In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120…
K7 Antivirus Premium
after 16.0.0120
HIGH 7.7
CVE-2019-10716
An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /in…
Director
after 3.5.3.1
HIGH 8.8
CVE-2019-15901
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, p…
Doas
6.2+
CRITICAL 9.1
CVE-2019-17631
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…
Satellite
after 0.16.0
HIGH 7.8
CVE-2019-16519
ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in schedu…
Cyber Security
after 6.7.900.0
HIGH 7.8
CVE-2019-9745
CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service…
Hip Integrator Recognition Configuration Tool
No fix yet
CRITICAL 9.8
CVE-2018-21025
In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configura…
Centreon Vm
after 19.04.3
HIGH 8.8
CVE-2019-15747
SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role due to in…
Sitos Six
Mitigation only
HIGH 7.8
CVE-2018-9425
In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of pri…
Android
Mitigation only
MEDIUM 6.5
CVE-2019-14220
An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual mac…
Bluestacks
after 4.120
HIGH 8.8
CVE-2019-11280
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x…
Pivotal Application Service
2.3.18 / 2.4.14+
HIGH 8.8
CVE-2016-11002
The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.
Extra
1.2.4+
HIGH 8.8
CVE-2016-11003
The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.
Bloom
1.1.1+
HIGH 8.8
CVE-2016-11004
The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation.
Monarch
1.2.7+