Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-15725
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure…
GitLab
12.0.8 / 12.1.8+
HIGH 7.5
CVE-2019-14724
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an e-mail forwarding destination…
Webpanel
No fix yet
MEDIUM 6.5
CVE-2019-14721
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a target user from phpMyAdmin …
Webpanel
No fix yet
MEDIUM 6.5
CVE-2019-14245
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) fr…
Centos Web Panel
No fix yet
MEDIUM 6.5
CVE-2019-14246
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any…
Centos Web Panel
No fix yet
HIGH 7.5
CVE-2019-14932
The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website vi…
Humatrix 7
No fix yet
HIGH 7.5
CVE-2019-7950
An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthentica…
Magento
2.1.18 / 2.2.9+
HIGH 7.3
CVE-2019-7890
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to…
Magento
2.1.18 / 2.2.9+
MEDIUM 5.3
CVE-2019-7864
An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento …
Magento
2.1.18 / 2.2.9+
MEDIUM 6.5
CVE-2019-7872
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.…
Magento
2.1.18 / 2.2.9+
HIGH 7.5
CVE-2019-7854
An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can l…
Magento
2.1.18 / 2.2.9+
CRITICAL 9.8
CVE-2019-13360EPSS 24%
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge …
Webpanel
No fix yet
HIGH 8.8
CVE-2019-13605EPSS 15%
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveragi…
Webpanel
No fix yet
HIGH 7.5
CVE-2018-19584
GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerabili…
GitLab
11.3.11 / 11.4.8+
HIGH 7.5
CVE-2019-13337
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used b…
Growi
3.5.0+
HIGH 7.5
CVE-2019-13461
In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulne…
Prestashop
after 1.7.5.2
HIGH 8.1
CVE-2019-12782
An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write ac…
Thoughtspot
after 5.1.1
MEDIUM 5.4
CVE-2019-5966
Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and alter/disclose th…
Joruri Mail
after 2.1.4
CRITICAL 9.8
CVE-2019-12866
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed…
Youtrack
2018.4.49168+
HIGH 8.8
CVE-2019-12742
Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin. This occurs because of bl-kernel/admin/con…
Bludit
3.9.1+
MEDIUM 6.5
CVE-2019-12252EPSS 8%
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to th…
Manageengine Servicedesk Plus
after 10.5
MEDIUM 5.4
CVE-2019-10108
An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x …
GitLab
11.7.8 / 11.8.4+
MEDIUM 5.3
CVE-2018-18976
An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medica…
Contour Diabetes
2.4.30 / 2.5.0+
CRITICAL 9.8
CVE-2019-9756
An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.…
GitLab
11.6.10 / 11.8.1+
MEDIUM 5.3
CVE-2019-9170
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect A…
GitLab
11.6.10 / 11.7.6+
MEDIUM 6.5
CVE-2019-9921
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by …
Je Messenger
No fix yet
MEDIUM 5.3
CVE-2019-9938
The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by th…
Shareit
4.0.42+
CRITICAL 9.4
CVE-2019-6716EPSS 10%
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote att…
Nervepoint Access Manager
No fix yet
HIGH 8.8
CVE-2018-16608
In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&u…
Monstra
No fix yet
MEDIUM 6.5
CVE-2018-16606EPSS 6%
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and th…
Proconf
6.1+