Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-12457
expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.
Expresscart
1.1.6+
HIGH 7.0
CVE-2018-0982
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulne…
Windows 10
Patch available
HIGH 7.0
CVE-2018-1036
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Wind…
Windows 10
Mitigation only
MEDIUM 6.8
CVE-2018-12259
An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full …
Momentum Axel 720p Firmware
No fix yet
CRITICAL 9.8
CVE-2017-7821
A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific…
Firefox
after 55.0.3
CRITICAL 9.8
CVE-2017-5456
A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for…
Enterprise Linux
52.1.0 / 53.0+
MEDIUM 5.3
CVE-2017-5426
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be ap…
Firefox
52.0+
MEDIUM 5.5
CVE-2018-4251
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Firmware" component. It allows attackers…
Mac Os X
10.13.5+
HIGH 8.8
CVE-2018-4220
An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is affected. The issue involves the "Swift for Ubuntu"…
Swift
4.1.1+
MEDIUM 5.5
CVE-2012-0433
The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allo…
Crowbar
after 1.0
MEDIUM 6.7
CVE-2018-0352
A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local a…
Wide Area Application Services
Mitigation only
HIGH 7.1
CVE-2017-18284
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to k…
Burp
2.1.32+
HIGH 7.1
CVE-2017-18285
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain re…
Burp
2.1.32+
HIGH 8.8
CVE-2018-11191
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 3 of 6).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11192
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 4 of 6).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11193
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 5 of 6).
Disk Backup
4.0.3.1+
HIGH 8.8
CVE-2018-11194
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 6 of 6).
Disk Backup
4.0.3.1+
MEDIUM 5.4
CVE-2018-1370
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way that allows that resource to…
Security Guardium Big Data Intelligence
Patch available
HIGH 7.8
CVE-2018-11334
Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pipe\Windscr…
Windscribe
Mitigation only
MEDIUM 5.4
CVE-2017-2612
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds…
Jenkins
2.32.2 / 2.44+
CRITICAL 9.1
CVE-2018-1115
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same …
PostgreSQL
9.6.9 / 10.4+
HIGH 7.5
CVE-2017-4952
VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authenticat…
Xenon
after 1.5.3
HIGH 7.8
CVE-2018-10645
Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVPN" service. This service esta…
Vyprvpn
Mitigation only
HIGH 7.8
CVE-2018-10646
CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service. This service establishes…
Cyberghost
Mitigation only
HIGH 7.8
CVE-2018-10647
SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. The "SaferVPN.Service" service…
Safervpn
Mitigation only
MEDIUM 6.5
CVE-2018-10518
In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that c…
Cms Made Simple
after 2.2.7
HIGH 8.8
CVE-2018-10519
CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value withi…
Cms Made Simple
No fix yet
MEDIUM 6.5
CVE-2018-10520
In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that…
Cms Made Simple
after 2.2.7
CRITICAL 9.8
CVE-2018-10381
TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service est…
Tunnelbear
Mitigation only
CRITICAL 9.8
CVE-2018-10285EPSS 13%
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attac…
Ipecs Nms
No fix yet