Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2019-4382EPSS 8%
IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the system users using specially craft…
Api Connect
after 5.0.8.6
MEDIUM 5.9
CVE-2019-12813
An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating the fingerprint image exhibit c…
Digital Persona U.are.u 4500 Firmware
No fix yet
MEDIUM 5.3
CVE-2019-10926
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted…
Simatic Mv420 Firmware
Mitigation only
HIGH 8.8
CVE-2019-12504
Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP2002 is prone to keystroke injection attacks. Thus, an at…
Wp2002 Firmware
No fix yet
HIGH 8.8
CVE-2019-12505
Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keystroke injection attacks. Thus,…
Wp1001 Firmware
No fix yet
HIGH 8.8
CVE-2019-12506
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystro…
R700 Laser Presentation Remote Firmware
No fix yet
HIGH 7.5
CVE-2019-4162
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to …
Security Information Queue
Patch available
HIGH 7.5
CVE-2019-5496
Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive …
Oncommand Insight
7.3.5+
HIGH 7.5
CVE-2019-5494
OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obt…
Oncommand Unified Manager
5.2.4+
MEDIUM 5.3
CVE-2019-6613
On BIG-IP 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, SNMP may expose sensitive configuration objects over insecure transmiss…
Big Ip Access Policy Manager
11.5.9 / 11.6.4+
HIGH 8.1
CVE-2019-11220
An authentication flaw in Shenzhen Yunni Technology iLnkP2P allows remote attackers to actively intercept user-to-device traffic in cleartext, includ…
Ilnkp2p
Mitigation only
CRITICAL 9.8
CVE-2019-3801
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building…
Cf Deployment
1.9.10 / 2.1.3+
HIGH 8.1
CVE-2018-1360
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenti…
Fortimanager
after 5.2.7
CRITICAL 9.8
CVE-2019-3793
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an i…
Application Service
665.0.28 / 666.0.21+
CRITICAL 9.8
CVE-2019-6526
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Vers…
Iks G6824a Firmware
after 4.5
HIGH 8.1
CVE-2019-10240
Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent a…
Hawkbit
after 0.2.5
HIGH 8.1
CVE-2019-1010260
Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This att…
Ktlint
0.30.0+
MEDIUM 5.9
CVE-2019-10251
The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft Office files …
Uc Browser
after 2019-03-26
MEDIUM 5.9
CVE-2019-10250
UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks.
Uc Browser
No fix yet
HIGH 7.5
CVE-2019-9860
Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control …
Secvest Wireless Alarm System Fuaa50000 Firmware
Mitigation only
MEDIUM 6.5
CVE-2019-6540
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 P…
Mycarelink Monitor 24950 Firmware
Mitigation only
MEDIUM 5.9
CVE-2019-4063
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An att…
Sterling B2b Integrator
after 6.0.0.0
HIGH 7.5
CVE-2019-7675
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentic…
S14 Firmware
No fix yet
MEDIUM 5.9
CVE-2018-18908
The Sky Go Desktop application 1.0.19-1 through 1.0.23-1 for Windows performs several requests over cleartext HTTP. This makes the data submitted in …
Sky Go
after 1.0.23-1
MEDIUM 5.5
CVE-2019-5489
The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of oth…
Linux Kernel
after 4.19.13
HIGH 7.5
CVE-2018-17195
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack…
Nifi
after 1.7.1
MEDIUM 5.9
CVE-2018-1525
IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP…
I2 Enterprise Insight Analysis
Mitigation only
HIGH 7.4
CVE-2018-7960
There is a SRTP icon display vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to interce…
Espace 7950 Firmware
Mitigation only
MEDIUM 5.3
CVE-2018-19111
The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as d…
Cardboard
Mitigation only
MEDIUM 5.7
CVE-2018-12674
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies o…
H.264 Poe Ip Camera Firmware
No fix yet