Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2019-13272 KEVEPSS 52%
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptr…
Linux Kernel
3.16.71 / 4.2+
HIGH 8.8
CVE-2019-12991 KEVEPSS 74%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
Netscaler Sd Wan
10.0.8 / 10.2.3+
CRITICAL 9.8
CVE-2019-12989 KEVEPSS 94%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
Netscaler Sd Wan
10.0.8 / 10.2.3+
HIGH 7.8
CVE-2019-1132 KEVEPSS 10%
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation…
Windows 7
Patch available
HIGH 7.8
CVE-2019-1130 KEV
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…
Windows 10 1507
Patch available
HIGH 7.8
CVE-2019-1129 KEV
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…
Windows 10 1703
Patch available
HIGH 7.8
CVE-2019-0880 KEV
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnera…
Windows 10 1507
Patch available
HIGH 7.5
CVE-2018-18325 KEVEPSS 74%
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete…
Dotnetnuke
after 9.2.2
HIGH 7.5
CVE-2018-15811 KEVEPSS 74%
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
Dotnetnuke
after 9.2.1
CRITICAL 9.8
CVE-2019-7256 KEVEPSS 97%
Linear eMerge E3-Series devices allow Command Injections.
Linear Emerge Essential Firmware
after 1.00-06
MEDIUM 6.5
CVE-2019-5786 KEVEPSS 62%
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access v…
Chrome
72.0.3626.121+
HIGH 7.8
CVE-2019-1069 KEVEPSS 6%
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully …
Windows 10 1507
Patch available
HIGH 7.8
CVE-2019-1064 KEVEPSS 7%
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successf…
Windows 10 1607
Patch available
CRITICAL 9.8
CVE-2010-5330 KEVEPSS 35%
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitize…
Airos
4.0.1 / 5.3.5+
CRITICAL 9.8
CVE-2019-10149 KEVEPSS 100%
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c …
Ubuntu Linux
after 4.91
HIGH 7.5
CVE-2018-13382 KEVEPSS 82%
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, …
Fortiproxy
1.2.9 / 5.4.11+
CRITICAL 9.8
CVE-2018-13379 KEVEPSS 100%
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4…
Fortiproxy
1.2.9 / 5.4.13+
CRITICAL 9.8
CVE-2019-11580 KEVEPSS 95%
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthentic…
Crowd
3.0.5 / 3.1.6+
HIGH 8.8
CVE-2019-9875 KEVEPSS 14%
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendi…
Cms
after 9.1
CRITICAL 9.8
CVE-2019-9874 KEVEPSS 84%
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allo…
Cms
after 8.2
CRITICAL 9.8
CVE-2019-9670 KEVEPSS 100%
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstr…
Zimbra Collaboration Suite
8.7.11+
MEDIUM 6.5
CVE-2018-13383 KEVEPSS 34%
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, …
Fortiproxy
1.2.9 / 5.2.15+
CRITICAL 9.8
CVE-2018-7841 KEVEPSS 73%
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper s…
U.motion Builder
Mitigation only
CRITICAL 9.8
CVE-2019-11634 KEVEPSS 8%
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
Receiver
1904+
HIGH 8.8
CVE-2019-0903 KEVEPSS 22%
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Rem…
Windows 10 1507
Patch available
HIGH 7.8
CVE-2019-0863 KEVEPSS 5%
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Priv…
Windows 10 1507
Patch available
CRITICAL 9.8
CVE-2019-0708 KEVEPSS 100%
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects…
Windows 7
Patch available
CRITICAL 9.8
CVE-2018-14839 KEVEPSS 89%
LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with p…
N1a1 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-3568 KEVEPSS 39%
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target ph…
Whatsapp
2.18.15 / 2.18.348+
CRITICAL 10.0
CVE-2019-11510 KEVEPSS 100%
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can se…
Connect Secure
Patch available