Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2019-15001EPSS 11%
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before…
Jira Server
7.6.16 / 7.13.8+
CRITICAL 9.8
CVE-2019-13558
In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote …
Webaccess
after 8.4.1
HIGH 8.1
CVE-2019-3759
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerab…
Rsa Identity Governance And Lifecycle
No fix yet
HIGH 7.2
CVE-2019-0355
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6…
Netweaver Application Server Java
Mitigation only
HIGH 8.8
CVE-2019-15873
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php reque…
Profilegrid
2.8.6+
HIGH 7.8
CVE-2019-2390
An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs ship…
MongoDB
3.4.22 / 3.6.14+
CRITICAL 9.8
CVE-2018-21005
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
Bbpress Move Topics
1.1.6+
HIGH 8.8
CVE-2019-15647
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
Groundhogg
1.3.5+
HIGH 8.8
CVE-2019-15642EPSS 35%
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call.…
Webmin
after 1.920
HIGH 7.5
CVE-2018-20988
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
Google Forms
0.94+
HIGH 7.2
CVE-2018-18573
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.…
Oscommerce
Mitigation only
CRITICAL 9.8
CVE-2019-15318
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
Easy Forms For Mailchimp
6.5.3+
CRITICAL 9.8
CVE-2019-15224
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Ver…
Rest Client
after 1.6.13
HIGH 7.8
CVE-2019-1157
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully …
Windows 10
Patch available
HIGH 8.8
CVE-2019-1150EPSS 26%
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succe…
Windows 10
Patch available
HIGH 7.5
CVE-2019-1057
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exp…
Windows 10
Patch available
HIGH 8.8
CVE-2019-0343
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject …
Commerce Cloud
Mitigation only
CRITICAL 9.8
CVE-2015-9298
The events-manager plugin before 5.6 for WordPress has code injection.
Events Manager
5.6+
CRITICAL 9.8
CVE-2019-14965
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
Frappe
12.0.4+
CRITICAL 9.8
CVE-2019-14746
A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.…
Kuaifancms
No fix yet
MEDIUM 6.3
CVE-2017-18468
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
Cpanel
56.0.46 / 58.0.45+
HIGH 8.8
CVE-2019-7871
A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbit…
Magento
2.1.18 / 2.2.9+
HIGH 8.1
CVE-2019-9140
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascrip…
Happypoint
Mitigation only
MEDIUM 6.3
CVE-2018-20931
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
Cpanel
62.0.42 / 68.0.33+
HIGH 7.2
CVE-2019-0193 KEVEPSS 84%
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh…
Solr
7.7.3 / 8.1.2+
MEDIUM 6.5
CVE-2019-10182
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a vi…
Enterprise Linux Desktop
after 1.7.2
HIGH 8.0
CVE-2019-11201
Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that th…
Dolibarr Erp\/crm
No fix yet
CRITICAL 9.8
CVE-2019-14281
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
Datagrid
Mitigation only
CRITICAL 9.8
CVE-2019-14282
The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
Simple Captcha2
Mitigation only
CRITICAL 9.8
CVE-2019-10173EPSS 95%
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has…
Xstream
after 8.2.2