Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-20494
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A…
GitLab
11.4.13 / 11.5.6+
MEDIUM 6.5
CVE-2019-4343
IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private informati…
Cognos Analytics
Mitigation only
HIGH 7.5
CVE-2013-4985EPSS 9%
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
Ip7160 Firmware
No fix yet
MEDIUM 5.3
CVE-2018-20492
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A…
GitLab
11.4.13 / 11.5.6+
HIGH 8.8
CVE-2019-19681
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to defin…
Pandora Fms
Mitigation only
MEDIUM 6.3
CVE-2019-19984
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settin…
Email Subscribers \& Newsletters
4.2.3+
CRITICAL 9.8
CVE-2012-6094
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
Debian Linux
1.5.4-1.1+
MEDIUM 5.7
CVE-2019-8512
This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise administrator to remotely wi…
Iphone Os
12.2+
HIGH 8.8
CVE-2019-0383
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.…
Enterprise Extension Financial Services
Mitigation only
HIGH 8.8
CVE-2019-0384
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.…
Enterprise Extension Financial Services
Mitigation only
CRITICAL 9.8
CVE-2019-7192 KEVEPSS 88%
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP reco…
Photo Station
5.2.11 / 5.4.9+
HIGH 8.8
CVE-2019-19597EPSS 21%
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an …
Dap 1860 Firmware
No fix yet
HIGH 7.8
CVE-2019-19520
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xeno…
OpenBSD
No fix yet
HIGH 7.5
CVE-2013-4410
ReviewBoard: has an access-control problem in REST API
Fedora
1.6.19 / 1.7.15+
MEDIUM 6.5
CVE-2016-3131
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
Cdh
5.3.10 / 5.4.10+
HIGH 8.8
CVE-2016-4572
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
Cdh
Mitigation only
MEDIUM 6.5
CVE-2016-6353
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security…
Cdh
5.7.0+
MEDIUM 6.5
CVE-2011-3617
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
Debian Linux
after 1.8.2
MEDIUM 6.5
CVE-2019-5879
Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious …
Chrome
77.0.3865.75+
MEDIUM 6.5
CVE-2015-1780
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
Ovirt Engine
Mitigation only
HIGH 8.8
CVE-2019-16538
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closure…
Script Security
after 1.67
HIGH 7.5
CVE-2012-2238
trytond 2.4: ModelView.button fails to validate authorization
Trytond
2.4.2+
HIGH 7.5
CVE-2011-2726
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type i…
Drupal
7.5+
HIGH 7.5
CVE-2019-18949
SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a cha…
Snowhaze
2.6.6+
HIGH 7.8
CVE-2011-1070
v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mod…
Debian Linux
0.1.10+
MEDIUM 5.3
CVE-2018-18819
A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8…
Micollab
after 8.0.2.202
CRITICAL 9.8
CVE-2019-12419EPSS 14%
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne…
Cxf
3.2.11 / 3.3.4+
CRITICAL 9.1
CVE-2010-2548
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
Icedtea6
1.7.4+
MEDIUM 5.3
CVE-2018-21030
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload ca…
Notebook
5.5.0+
HIGH 7.5
CVE-2009-3723
asterisk allows calls on prohibited networks
Debian Linux
1.6.1.8+