Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2017-8405
An issue was discovered on D-Link DCS-1130 and DCS-1100 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections rece…
Dcs 1100 Firmware
No fix yet
HIGH 8.8
CVE-2019-7666EPSS 15%
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may …
Flexair
after 2.3.38
HIGH 7.1
CVE-2019-10964
Medtronic MiniMed Insulin Pumps
are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor tr…
Minimed 508 Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-14868
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the pas…
Odoo
Patch available
CRITICAL 9.8
CVE-2018-15556
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password b…
Web6000q Firmware
No fix yet
HIGH 8.8
CVE-2019-7226EPSS 5%
The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged …
Pb610 Panel Builder 600 Firmware
after 2.8.0.367
HIGH 7.3
CVE-2019-11272
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an appli…
Spring Security
4.2.13+
MEDIUM 6.5
CVE-2019-10689
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier p…
Better Together Over Ethernet Connector
after 5.9.2
HIGH 8.8
CVE-2019-2018
In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password reset protection due to an unusual root cause. Re…
Android
No fix yet
CRITICAL 9.8
CVE-2019-11232
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element…
Biyan
after 2.8
HIGH 8.8
CVE-2018-18877
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.p…
Weather Microserver Firmware
Mitigation only
MEDIUM 6.8
CVE-2019-10998
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices…
Axc F 2152 Firmware
2019.0_lts+
CRITICAL 9.9
CVE-2017-9383
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are available on port 3480 and c…
Veraedge Firmware
after 1.7.481
HIGH 8.8
CVE-2017-9389
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage t…
Veraedge Firmware
after 1.7.481
HIGH 7.5
CVE-2019-7579
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.…
Wrt1900acs Firmware
No fix yet
MEDIUM 5.9
CVE-2019-10150
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during…
Openshift Container Platform
after 4.1
MEDIUM 5.5
CVE-2019-10157
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel l…
Keycloak
4.8.3 / 7.3.2+
HIGH 7.8
CVE-2018-19999
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authenticati…
Serv U Ftp Server
Mitigation only
MEDIUM 5.4
CVE-2019-1842
A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfu…
Ios Xr Firmware
Mitigation only
CRITICAL 9.1
CVE-2018-18571
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patc…
Xenmobile Server
Mitigation only
CRITICAL 9.8
CVE-2018-7121EPSS 8%
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Intelligent Management Center
7.3+
HIGH 7.5
CVE-2018-7123EPSS 58%
A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Intelligent Management Center
7.3+
MEDIUM 6.8
CVE-2019-5298
There is an improper authentication vulnerability in some Huawei AP products before version V200R009C00SPC800. Due to the improper implementation of …
Ap4050dn E Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-12564
In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/Dyyyymm…
Douphp
No fix yet
CRITICAL 9.8
CVE-2019-12530
Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf…
Glpi Dashboard
after 0.9.7
CRITICAL 9.8
CVE-2019-12440
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore R…
Rocks
2.1.149+
MEDIUM 5.3
CVE-2019-12395
In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without logi…
Dynmap
3.0+
CRITICAL 9.8
CVE-2018-11271
Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon Compute, Snapdra…
Mdm9206 Firmware
Mitigation only
HIGH 7.8
CVE-2018-12013
Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Consu…
Mdm9206 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-12300
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker…
Buildbot
1.8.2 / 2.3.1+