Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2018-1999032
A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier in GlobalConfig.java that al…
Pangolin Connector For Testrail
after 2.1
HIGH 8.8
CVE-2018-0613
NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX…
Calsos Csdx Firmware
after 4.37210411
HIGH 7.8
CVE-2018-10906
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root use…
Debian Linux
2.9.8 / 3.2.5+
HIGH 8.8
CVE-2018-0343
A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arb…
Vbond Orchestrator
18.3.0+
HIGH 8.8
CVE-2016-9489
In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own …
Manageengine Applications Manager
Mitigation only
HIGH 7.8
CVE-2018-0024
An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain …
Junos
Mitigation only
HIGH 8.2
CVE-2018-3682
BMC Firmware in Intel server boards, compute modules, and systems potentially allow an attacker with administrative privileges to make unauthorized r…
Bmc Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-9853
Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process by leveraging the ability to …
Freesshd
Mitigation only
HIGH 8.4
CVE-2018-5884
Improper Access Control in Multimedia in Snapdragon Mobile and Snapdragon Wear, Non-standard applications without permission may acquire permission o…
Mdm9607 Firmware
Mitigation only
HIGH 7.8
CVE-2018-13405
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, i…
Linux Kernel
after 3.16
MEDIUM 5.5
CVE-2018-9334
The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allo…
Pan Os
after 8.0.8
HIGH 8.8
CVE-2018-4845
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens …
Rapidpoint 400 Firmware
3.3+
HIGH 7.2
CVE-2018-0610
Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code…
Zenphoto
after 1.4.14
MEDIUM 5.3
CVE-2018-0573
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a con…
Basercms
after 4.1.0.1
MEDIUM 6.5
CVE-2018-12884
In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastruc…
Octopus Deploy
Mitigation only
HIGH 8.8
CVE-2017-2672
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file woul…
Satellite
1.15+
CRITICAL 9.8
CVE-2018-9021EPSS 10%
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with s…
Privileged Access Manager
after 2.8.2
CRITICAL 9.8
CVE-2018-9022EPSS 13%
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or command…
Privileged Access Manager
after 2.8.2
HIGH 7.8
CVE-2018-1460
IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writable file, which could be used…
Puredata System For Analytics
No fix yet
HIGH 7.5
CVE-2018-5166
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access …
Ubuntu Linux
60.0+
HIGH 7.5
CVE-2017-7803
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforc…
Enterprise Linux Desktop
52.3.0 / 55.0+
MEDIUM 5.5
CVE-2017-7767
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater,…
Firefox
52.2.0 / 54.0+
MEDIUM 5.3
CVE-2017-7782
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. No…
Firefox
52.3.0 / 55.0+
MEDIUM 5.5
CVE-2017-5409
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parame…
Firefox
45.8.0 / 52.0+
HIGH 8.8
CVE-2018-11190
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 2 of 6).
Disk Backup
4.0.3.1+
MEDIUM 6.5
CVE-2018-1495
IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a…
Flashsystem 900 Firmware
No fix yet
MEDIUM 6.5
CVE-2018-1134
An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by chan…
Moodle
after 3.4.2
MEDIUM 6.2
CVE-2017-14187
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions al…
Fortios
after 5.6.2
HIGH 8.8
CVE-2018-11323
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissi…
Joomla\!
3.8.8+
HIGH 8.8
CVE-2018-1000400
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities th…
Cri O
1.9.0+