Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2015-5463
AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and earlier allows remote attackers…
Axiom
after 9.5.3
HIGH 8.8
CVE-2019-3849
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content…
Moodle
3.4.8 / 3.5.5+
CRITICAL 9.8
CVE-2015-3954
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and…
Plum A\+ Infusion System Firmware
after 13.6
HIGH 8.1
CVE-2019-3785
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with…
Capi Release
1.78.0+
HIGH 7.8
CVE-2019-1603
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrat…
Nx Os
7.0+
HIGH 7.8
CVE-2019-1604
A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privil…
Nx Os
6.2 / 7.0+
MEDIUM 5.5
CVE-2018-9867
In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the Sonic…
Sonicosv
after 5.9.1.10
HIGH 7.2
CVE-2018-14666
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered…
Satellite
after 6.4
MEDIUM 5.7
CVE-2018-14662
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d…
Ceph
13.2.4+
HIGH 8.1
CVE-2018-15465
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (le…
Adaptive Security Appliance Software
9.4.4.29 / 9.6.4.20+
HIGH 8.1
CVE-2018-14637
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th…
Keycloak
4.6.0+
HIGH 8.8
CVE-2018-17933
VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execut…
Vgo Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-10734
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
Projectsend
Mitigation only
MEDIUM 6.5
CVE-2018-15405
A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director coul…
Ucs Director
Mitigation only
MEDIUM 6.5
CVE-2018-0460
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any fil…
Network Functions Virtualization Infrastructure
Mitigation only
MEDIUM 6.5
CVE-2018-0459
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote at…
Network Functions Virtualization Infrastructure
Mitigation only
MEDIUM 5.3
CVE-2018-3829
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles…
Elastic Cloud Enterprise
1.1.4+
HIGH 7.8
CVE-2016-7035
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged accou…
Enterprise Linux Server
after 1.1.16
HIGH 8.8
CVE-2016-7071
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authent…
Cloudforms Management Engine
5.6.2.2 / 5.7.0.7+
MEDIUM 5.3
CVE-2018-3778
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
Aedes
0.35.0+
MEDIUM 6.5
CVE-2018-0391
A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the …
Prime Collaboration
after 12.2
MEDIUM 6.5
CVE-2018-12466
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
Open Build Service
9.2.4+
MEDIUM 6.5
CVE-2018-12467
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDe…
Open Build Service
2.9.4+
CRITICAL 9.0
CVE-2017-2589
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored …
Jboss Fuse
Mitigation only
HIGH 7.8
CVE-2018-10906
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root use…
Debian Linux
2.9.8 / 3.2.5+
MEDIUM 6.5
CVE-2018-0393
A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to m…
Mobility Services Engine 3365 Firmware
Mitigation only
HIGH 8.1
CVE-2018-10861
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po…
Ceph Storage
Patch available
HIGH 8.8
CVE-2017-16773
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass …
Universal Search
1.0.5-0135+
MEDIUM 5.3
CVE-2018-1113
setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates sec…
Setup
2.11.4+
CRITICAL 9.1
CVE-2017-16726
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to…
Twincat
Mitigation only