Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-16491
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.proto…
Node.extend
1.1.7 / 2.0.1+
CRITICAL 9.8
CVE-2018-16492
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.pro…
Extend
2.0.2 / 3.0.2+
CRITICAL 9.8
CVE-2018-16486
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
Defaults Deep
after 0.2.4
CRITICAL 9.8
CVE-2018-16489
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functio…
Just Extend
4.0.0+
MEDIUM 6.1
CVE-2019-6802
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
Pypiserver
after 1.2.5
MEDIUM 6.5
CVE-2019-3498
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Down…
Django
1.11.18 / 2.0.10+
MEDIUM 6.1
CVE-2018-16627
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
Kirby
No fix yet
CRITICAL 9.8
CVE-2018-1000854
esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (…
Esigate
after 5.2
HIGH 7.5
CVE-2018-18250
Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation ite…
Icinga Web 2
2.6.2+
HIGH 7.8
CVE-2018-20167
Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn…
Terminology
1.3.1+
MEDIUM 5.4
CVE-2018-1896
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-…
Connections
Patch available
MEDIUM 6.1
CVE-2018-18207
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
Virtualmin
No fix yet
CRITICAL 9.8
CVE-2018-16763EPSS 83%
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Cod…
Fuel Cms
after 1.4.2
MEDIUM 5.4
CVE-2017-1115
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exec…
Campaign
Patch available
MEDIUM 6.8
CVE-2018-9062
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
E42 80 Firmware
0zcn48ww / 2wcn40ww+
MEDIUM 5.4
CVE-2018-1549
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could explo…
Rational Quality Manager
after 6.0.5
CRITICAL 9.8
CVE-2018-4995EPSS 7%
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST inject…
Acrobat Dc
after 18.011.20038
HIGH 8.8
CVE-2018-0313
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the managem…
Nx Os
Mitigation only
HIGH 8.8
CVE-2017-7846
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in th…
Enterprise Linux Desktop
52.5.2+
MEDIUM 5.3
CVE-2017-7848
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
Enterprise Linux
52.5.2+
CRITICAL 9.8
CVE-2017-7788
When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content S…
Firefox
55.0+
MEDIUM 5.5
CVE-2018-4235
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watch…
Apple Tv
4.3.1 / 10.13.5+
MEDIUM 6.1
CVE-2017-16043
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the…
Shout
0.50.0+
HIGH 7.8
CVE-2017-6015
Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may …
Factorytalk Activation
after 4.00.02
HIGH 8.8
CVE-2017-18266
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER enviro…
Debian Linux
1.1.3+
CRITICAL 9.8
CVE-2016-10498
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205,…
Mdm9206 Firmware
Mitigation only
CRITICAL 9.8
CVE-2014-2294
Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_even…
Open Web Analytics
1.5.7+
CRITICAL 9.8
CVE-2017-0372EPSS 11%
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
Debian Linux
after 1.23.15
HIGH 7.8
CVE-2015-1975
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 3…
Tivoli Directory Server
Mitigation only
HIGH 8.8
CVE-2018-4106
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" co…
Mac Os X
10.13.4+