Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2019-19023
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry fo…
Harbor
1.8.6 / 1.9.3+
HIGH 8.8
CVE-2019-19025
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.
Harbor
1.8.6 / 1.9.3+
HIGH 7.2
CVE-2019-19029
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for th…
Harbor
1.8.6 / 1.9.3+
CRITICAL 9.1
CVE-2020-1887
Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the …
Osquery
4.2.0+
HIGH 8.6
CVE-2020-5259
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inje…
Dojox
1.11.10 / 1.12.8+
HIGH 7.5
CVE-2019-16297
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the P4 tutorial application (org.onosproject.p4tutorial), the host event lis…
Open Network Operating System
Mitigation only
HIGH 7.5
CVE-2019-16298
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual broadband network gateway application (org.onosproject.virtualbn…
Open Network Operating System
Mitigation only
HIGH 7.5
CVE-2019-16299
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the mobility application (org.onosproject.mobility), the host event listener…
Open Network Operating System
Mitigation only
HIGH 7.5
CVE-2019-16300
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the access control application (org.onosproject.acl), the host event listene…
Open Network Operating System
Mitigation only
HIGH 7.5
CVE-2019-16301
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual tenant network application (org.onosproject.vtn), the host event…
Open Network Operating System
Mitigation only
HIGH 7.5
CVE-2019-16302
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the Ethernet VPN application (org.onosproject.evpnopenflow), the host event …
Open Network Operating System
Mitigation only
CRITICAL 9.8
CVE-2020-6174
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
The Update Framework
after 0.12.1
MEDIUM 5.3
CVE-2020-6173
TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
The Update Framework
after 0.12.1
MEDIUM 6.5
CVE-2019-16097EPSS 22%
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with…
Harbor
Patch available
HIGH 7.5
CVE-2019-13126
An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabl…
Nats Server
2.0.2+
CRITICAL 9.8
CVE-2019-1010234
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands …
Open Network Operating System
after 1.15.0
CRITICAL 9.8
CVE-2019-1010245
The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can ex…
Open Network Operating System
after 1.15
HIGH 8.1
CVE-2019-3567
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a mali…
Osquery
3.4.0+
HIGH 7.8
CVE-2018-6336
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full insp…
Osquery
3.2.7+
MEDIUM 5.3
CVE-2015-1857
The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.
Opendaylight
0.2.4+
HIGH 8.6
CVE-2017-17697
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
Harbor
1.3.0+
MEDIUM 5.8
CVE-2014-4336
The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitra…
Cups Filters
after 1.0.52
HIGH 8.3
CVE-2014-2707
cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model …
Cups Filters
Mitigation only
MEDIUM 6.8
CVE-2011-2964
foomaticrip.c in foomatic-rip in foomatic-filters in Foomatic 4.0.6 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPComma…
Foomatic
Patch available