Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-15896EPSS 7%
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is…
Lifterlms
after 3.34.5
CRITICAL 9.1
CVE-2019-10668
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authenticatio…
Librenms
after 1.47
HIGH 7.5
CVE-2019-15895
search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.
Search Exclude
1.2.4+
CRITICAL 9.8
CVE-2019-15102
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication …
Sahi Pro
after 8.0.0
HIGH 7.5
CVE-2019-15043EPSS 63%
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack ag…
Grafana
5.4.5 / 6.3.4+
HIGH 8.8
CVE-2019-15858EPSS 18%
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demons…
Woody Ad Snippets
2.2.5+
CRITICAL 9.8
CVE-2019-15819
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
Restaurant Reservations
after 1.3
CRITICAL 9.8
CVE-2019-13405
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to …
Vd 1 Firmware
No fix yet
HIGH 7.5
CVE-2019-13406
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to…
Vd 1 Firmware
after 230
HIGH 8.1
CVE-2019-11061
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devic…
Hg100 Firmware
4.00.09+
HIGH 8.8
CVE-2019-11063
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the sa…
Smarthome
2.0.22 / 3.0.42_190515+
MEDIUM 5.3
CVE-2019-9935
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
Cs31x Firmware
No fix yet
MEDIUM 5.3
CVE-2019-9934
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
Cs31x Firmware
No fix yet
HIGH 7.5
CVE-2019-15506
An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An una…
Virtual System Administrator
after 9.4.0.37
HIGH 7.5
CVE-2019-14511
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a fir…
Sphinx
No fix yet
HIGH 7.5
CVE-2019-12634
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D…
Integrated Management Controller Supervisor
after 6.7.2.0
MEDIUM 5.3
CVE-2019-15129
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo…
Humatrix 7
No fix yet
CRITICAL 9.8
CVE-2019-15106EPSS 25%
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on t…
Manageengine Opmanager
after 12.4.034
CRITICAL 9.8
CVE-2019-9585
eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, res…
Homematic Ccu2 Firmware
2.47.10 / 3.47.10+
HIGH 8.1
CVE-2019-14984EPSS 6%
eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to t…
Homematic Ccu2 Firmware
after 1.2.0
CRITICAL 9.8
CVE-2019-13101EPSS 67%
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lea…
Dir 600m Firmware
No fix yet
CRITICAL 9.8
CVE-2019-1895
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an …
Enterprise Network Function Virtualization Infrastructure
3.12.1+
MEDIUM 6.5
CVE-2019-10198
An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, w…
Satellite
0.15.7+
HIGH 7.5
CVE-2019-3948EPSS 25%
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and D…
Ip2m 841b Firmware
2018-05-18+
HIGH 7.5
CVE-2019-1010136
ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's …
Gpn2.4p21 C Cn Firmware
No fix yet
CRITICAL 9.8
CVE-2019-13983
Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endp…
Directus 7 Api
2.2.2+
HIGH 7.8
CVE-2019-10915
A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA Administra…
Tia Administrator
Patch available
CRITICAL 9.8
CVE-2019-12468
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow…
Debian Linux
after 1.32.1
CRITICAL 9.8
CVE-2019-10119
eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attack…
Ccu3 Firmware
2.41.8 / 3.43.16+
CRITICAL 9.8
CVE-2019-10121
eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attack…
Ccu3 Firmware
2.41.8 / 3.43.15+