Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2018-16838
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the ser…
Enterprise Linux
Mitigation only
HIGH 7.5
CVE-2019-5415
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has…
Serve
No fix yet
HIGH 7.4
CVE-2018-11767
In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-d…
Hadoop
after 2.9.1
HIGH 7.8
CVE-2018-18252
An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe provides "NT AUTHORITY\SYSTEM" access to unprivileged users via the -…
Access Manager
No fix yet
MEDIUM 5.5
CVE-2019-6601
In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of i…
Big Ip Application Acceleration Manager
after 12.1.3
HIGH 8.1
CVE-2019-3785
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with…
Capi Release
1.78.0+
HIGH 7.8
CVE-2019-9624EPSS 24%
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a…
Webmin
No fix yet
CRITICAL 9.8
CVE-2018-19725
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypa…
Acrobat Dc
after 19.010.20069
HIGH 7.1
CVE-2018-5839
Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon C…
Snapdragon Auto Firmware
Mitigation only
HIGH 7.8
CVE-2019-3475
A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege us…
Filr
No fix yet
MEDIUM 6.5
CVE-2019-5768
DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user…
Chrome
72.0.3626.81+
HIGH 7.8
CVE-2018-19012
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a spec…
Kappa Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-19635
CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.
Service Desk Manager
Patch available
HIGH 7.4
CVE-2017-6924
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the us…
Drupal
8.3.7+
MEDIUM 6.7
CVE-2018-0671
Privilege escalation vulnerability in INplc-RT 3.08 and earlier allows an attacker with administrator rights to execute arbitrary code on the Windows…
Inplc Rt
after 3.08
HIGH 7.5
CVE-2018-1000624
Battelle V2I Hub 2.5.1 is vulnerable to a denial of service, caused by the failure to restrict access to a sensitive functionality. By visiting http:…
V2i Hub
Mitigation only
HIGH 8.8
CVE-2018-20193
Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow pri…
Secure Access Series Ssl Vpn Sa 4000
No fix yet
HIGH 7.8
CVE-2018-15331
On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, w…
Big Ip Application Acceleration Manager
after 12.1.3
HIGH 7.8
CVE-2018-11965
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Anyone can execute proptrigger.sh which wi…
Android
Patch available
HIGH 7.2
CVE-2018-1973
IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level acce…
Api Connect
after 5.0.8.4
CRITICAL 9.8
CVE-2018-10143EPSS 25%
The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level com…
Expedition
No fix yet
MEDIUM 6.5
CVE-2018-18344
Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote at…
Chrome
71.0.3578.80+
HIGH 8.8
CVE-2018-1000865
A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTr…
Script Security
after 1.47
HIGH 8.8
CVE-2018-1000866
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxT…
Pipeline\
after 2.59
HIGH 7.8
CVE-2018-1941
IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-For…
Campaign
9.1.0.13 / 9.1.2.7+
HIGH 8.8
CVE-2018-19853
An issue was discovered in hitshop through 2014-07-15. There is an elevation-of-privilege vulnerability (that allows control over the whole web site)…
Hitshop
after 2014-07-15
HIGH 7.8
CVE-2018-11911
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of script may lead …
Android
Patch available
HIGH 7.8
CVE-2018-11912
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of daemons may lead…
Android
Patch available
HIGH 8.8
CVE-2018-19411
PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (incl…
Prtg Network Monitor
18.2.40.1683+
MEDIUM 6.5
CVE-2018-6080
Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer p…
Chrome
65.0.3325.146+