Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-13338
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for…
Growi
3.5.0+
HIGH 7.5
CVE-2019-11020
Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easi…
Dashcom Live Firmware
Mitigation only
HIGH 7.5
CVE-2019-11019
Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely access all claim details by vis…
Dashcom Live Firmware
after 2019-05-08
HIGH 7.8
CVE-2019-12174
hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configFilePath:configFileName method…
Hide.me
2.4.4+
MEDIUM 5.3
CVE-2019-13344EPSS 45%
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change se…
Wp Like Button
after 1.6.0
CRITICAL 9.8
CVE-2019-13131
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.
Superdoctor 5
No fix yet
MEDIUM 5.3
CVE-2019-4337
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in I…
Robotic Process Automation With Automation Anywhere
11.0.0.4+
MEDIUM 5.5
CVE-2019-12919
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal S…
Clever Dog Smart Camera Panorama Dog 2w Firmware
No fix yet
MEDIUM 5.3
CVE-2019-1876
A vulnerability in the HTTPS proxy feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to…
Wide Area Application Services
Mitigation only
MEDIUM 5.3
CVE-2019-1897
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to …
Rv110w Firmware
No fix yet
MEDIUM 5.3
CVE-2019-1629
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker t…
Integrated Management Controller
Mitigation only
MEDIUM 5.3
CVE-2019-1631
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker…
Integrated Management Controller
Mitigation only
CRITICAL 9.8
CVE-2019-12890EPSS 6%
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automation…
Redwoodhq
No fix yet
MEDIUM 5.3
CVE-2019-0312
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to…
Netweaver Process Integration
Mitigation only
MEDIUM 5.3
CVE-2017-15123
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users onl…
Cloudforms Management Engine
after 5.10
HIGH 7.5
CVE-2019-3411
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login…
Mf920 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-9879EPSS 47%
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are al…
Wpgraphql
No fix yet
CRITICAL 9.1
CVE-2019-9880EPSS 35%
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attack…
Wpgraphql
No fix yet
MEDIUM 5.3
CVE-2019-9881EPSS 19%
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow…
Wpgraphql
No fix yet
HIGH 8.8
CVE-2019-12505
Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keystroke injection attacks. Thus,…
Wp1001 Firmware
No fix yet
HIGH 8.8
CVE-2019-12506
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystro…
R700 Laser Presentation Remote Firmware
No fix yet
CRITICAL 9.8
CVE-2019-11523
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully …
M3 Firmware
No fix yet
HIGH 7.5
CVE-2019-6451
On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.
Ar 727h Firmware
No fix yet
MEDIUM 5.3
CVE-2019-10046
An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.
Pydio
No fix yet
HIGH 7.5
CVE-2019-9105
The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of AP…
Tebe Small Firmware
No fix yet
CRITICAL 9.8
CVE-2019-9871EPSS 6%
Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.
Fm K75 Firmware
No fix yet
MEDIUM 6.5
CVE-2019-12500
The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands …
M365 Firmware
1.5.1+
CRITICAL 9.1
CVE-2019-6958
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7…
Access Professional Edition
1.7.6.079 / 6.10+
CRITICAL 9.8
CVE-2019-12288
An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network…
C7824iwp Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-12289
An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices.…
C7824wip Firmware
Mitigation only