Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2019-4311
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The information can be used to mount …
Security Guardium Big Data Intelligence
Patch available
MEDIUM 6.5
CVE-2019-6144
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web prot…
One Endpoint
after 19.08
CRITICAL 9.8
CVE-2019-15900
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used withou…
Doas
6.2+
HIGH 7.5
CVE-2019-14832
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authent…
Keycloak
7.0.1+
HIGH 7.5
CVE-2019-17191
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, v…
Private Messenger
4.47.7+
MEDIUM 5.5
CVE-2019-9272
In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to…
Android
Mitigation only
HIGH 7.8
CVE-2019-12671
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execu…
Ios Xe
Mitigation only
CRITICAL 9.8
CVE-2019-15941
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorizat…
Debian Linux
after 2.0.5
HIGH 8.8
CVE-2019-12648
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access t…
iOS
Mitigation only
HIGH 7.5
CVE-2019-16884
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux…
Docker
after 19.03.2
MEDIUM 5.3
CVE-2016-10996
The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak.
Optinmonster
1.1.4.6+
HIGH 7.5
CVE-2019-6836
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Pl…
Meg6501 0001 Firmware
1.3.7+
MEDIUM 6.5
CVE-2019-6838
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Pl…
Meg6501 0001 Firmware
1.3.7+
HIGH 7.5
CVE-2019-15729
An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information ab…
GitLab
12.0.8 / 12.1.8+
CRITICAL 9.8
CVE-2019-14237
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can…
Kinetis Kv1x Firmware
No fix yet
CRITICAL 9.8
CVE-2019-14236
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP p…
Stm32l0 Firmware
No fix yet
MEDIUM 5.5
CVE-2019-1289
An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'W…
Windows 10
Patch available
MEDIUM 5.3
CVE-2019-14995
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name e…
Jira Server
8.4.0+
CRITICAL 9.8
CVE-2019-16114
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain a…
Atutor
after 2.2.4
CRITICAL 9.8
CVE-2019-14813EPSS 11%
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en…
Openshift Container Platform
Patch available
HIGH 7.8
CVE-2019-2175
In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could…
Android
Patch available
HIGH 7.8
CVE-2019-14811
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls…
Openshift Container Platform
9.50+
HIGH 7.8
CVE-2019-14817
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged ca…
Openshift Container Platform
9.50+
HIGH 8.1
CVE-2019-11247
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced.…
Kubernetes
1.13.9 / 1.14.5+
MEDIUM 5.3
CVE-2019-8445
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time…
Jira Server
7.13.7 / 8.3.2+
MEDIUM 5.3
CVE-2019-8446EPSS 18%
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation c…
Jira Server
8.3.2+
MEDIUM 5.3
CVE-2019-13417
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for…
Search Guard
24.0+
HIGH 7.5
CVE-2019-14924
An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but…
Gcdwebserver
3.5.3+
CRITICAL 9.1
CVE-2019-1912EPSS 17%
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to …
Sf 220 24 Firmware
1.1.4.4+
HIGH 8.8
CVE-2019-13386
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell comman…
Centos Web Panel
No fix yet