Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2019-3653
Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user t…
Endpoint Security
10.6.1+
MEDIUM 6.7
CVE-2019-12670
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the name…
iOS
Mitigation only
HIGH 8.8
CVE-2019-12648
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access t…
iOS
Mitigation only
CRITICAL 9.8
CVE-2019-15068
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/…
Smart Battery A4 Firmware
Mitigation only
HIGH 8.8
CVE-2019-6810
CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the exec…
Bmxnor0200h Firmware
Mitigation only
HIGH 7.5
CVE-2019-11899
An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. With Bosch…
Access
after 3.7
CRITICAL 9.8
CVE-2019-13656EPSS 6%
An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote a…
Ca Client Automation
No fix yet
MEDIUM 5.3
CVE-2018-15513
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
Totemomail
Mitigation only
CRITICAL 9.8
CVE-2018-21007
The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.
User Email Verification For Woocommerce
3.2.0+
HIGH 7.5
CVE-2015-9337
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
Profile Builder
2.1.4+
HIGH 7.5
CVE-2019-12627
A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a…
Secure Firewall Threat Defense
6.4.0.4+
HIGH 7.5
CVE-2019-5036
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specia…
Nest Cam Iq Indoor Firmware
No fix yet
CRITICAL 9.8
CVE-2017-18543
The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
Invite Anyone
1.3.16+
HIGH 8.8
CVE-2018-20957
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.
One\+ Firmware
2018-06-12+
MEDIUM 5.5
CVE-2016-10799
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).
Cpanel
11.52.6.2 / 11.54.0.26+
HIGH 8.8
CVE-2016-10802
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
Cpanel
11.52.6.2 / 11.54.0.26+
HIGH 8.8
CVE-2016-10792
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
Cpanel
11.52.6.6 / 11.54.0.29+
CRITICAL 9.8
CVE-2019-10938
A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 …
Siprotec 5 Digsi Device Driver
Patch available
MEDIUM 6.3
CVE-2017-18403
cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).
Cpanel
62.0.35 / 64.0.42+
MEDIUM 5.5
CVE-2017-18416
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
Cpanel
56.0.52 / 60.0.48+
HIGH 7.8
CVE-2019-10166
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDe…
Libvirt
4.10.1 / 5.4.1+
HIGH 7.8
CVE-2019-10167
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify …
Libvirt
4.10.1 / 5.4.1+
HIGH 7.8
CVE-2019-10168
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emula…
Libvirt
4.10.1 / 5.4.1+
MEDIUM 5.5
CVE-2017-18385
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
Cpanel
62.0.35 / 64.0.42+
HIGH 8.8
CVE-2016-10820
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
Cpanel
11.50.5.2 / 11.52.4.1+
HIGH 8.1
CVE-2016-10830
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
Cpanel
11.50.5.2 / 11.52.4.1+
MEDIUM 6.5
CVE-2018-20930
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
Cpanel
62.0.42 / 68.0.33+
MEDIUM 6.5
CVE-2016-10838
cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).
Cpanel
11.48.5.2 / 11.50.4.3+
HIGH 7.5
CVE-2015-9291
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
Cpanel
11.52.0.13+
MEDIUM 6.5
CVE-2016-10852
cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).
Cpanel
11.48.5.2 / 11.50.4.3+