Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2019-4558
A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4…
Spectrum Scale
after 5.0.3.2
MEDIUM 6.1
CVE-2019-15259
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response s…
Unified Contact Center Express
11.6+
HIGH 7.5
CVE-2019-17068
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.
Putty
0.73+
MEDIUM 6.1
CVE-2019-16532
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
Yzmcms
No fix yet
HIGH 8.1
CVE-2019-11277
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authentic…
Cf Deployment
1.7.11 / 2.3.0+
CRITICAL 9.8
CVE-2017-18634
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
Newspaper
6.7.2+
MEDIUM 6.1
CVE-2019-5314
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able t…
Arubaos
6.4.4.20 / 6.5.4.11+
CRITICAL 9.8
CVE-2019-10074
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This …
Ofbiz
after 16.11.05
CRITICAL 9.8
CVE-2017-18605
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
Gravitate Qa Tracker
after 1.2.1
HIGH 7.5
CVE-2017-18604
The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
Sitebuilder Dynamic Components
after 1.0
HIGH 8.8
CVE-2019-12463
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/gr…
Librenms
1.53+
CRITICAL 9.8
CVE-2019-10665
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes…
Librenms
after 1.47
HIGH 8.8
CVE-2019-1939
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affec…
Webex Teams
3.0.12427.0+
MEDIUM 6.1
CVE-2014-10386
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
Live Chat
4.1.0+
MEDIUM 6.1
CVE-2014-10391
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
Wp Support Plus Responsive Ticket System
4.1+
MEDIUM 6.1
CVE-2014-10394
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
Rich Counter
1.2.0+
CRITICAL 9.8
CVE-2017-18583
The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
Post Pay Counter
2.731+
CRITICAL 9.8
CVE-2019-11581 KEVEPSS 85%
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. A…
Jira Server
7.6.14 / 7.13.5+
HIGH 8.8
CVE-2019-5404
A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
3par Storeserv Management Console
3.5.0.1+
HIGH 8.8
CVE-2016-10801
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
Cpanel
11.54.0.26 / 56.0.27+
MEDIUM 6.5
CVE-2019-7889
An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magen…
Magento
1.9.4.2 / 1.14.4.2+
HIGH 7.2
CVE-2017-18386
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
Cpanel
62.0.35 / 64.0.42+
HIGH 7.2
CVE-2017-18387
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
Cpanel
62.0.35 / 64.0.42+
MEDIUM 6.3
CVE-2017-18389
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
Cpanel
64.0.42 / 66.0.34+
HIGH 8.1
CVE-2016-10845
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
Cpanel
11.48.5.2 / 11.50.4.3+
HIGH 8.1
CVE-2016-10847
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
Cpanel
11.48.5.2 / 11.50.4.3+
HIGH 7.3
CVE-2018-20914
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
Cpanel
70.0.23+
MEDIUM 5.3
CVE-2018-20885
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
Cpanel
74.0.0+
MEDIUM 6.1
CVE-2019-1020006
invenio-app before 1.1.1 allows host header injection.
Invenio App
1.1.1+
HIGH 8.3
CVE-2019-9811
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser fea…
Firefox
60.8 / 68.0+