Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-11307EPSS 6%
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows…
Openshift Container Platform
2.6.7.3 / 2.7.9.4+
HIGH 7.8
CVE-2019-13314
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password…
Virt Bootstrap
No fix yet
CRITICAL 9.8
CVE-2019-10137
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthen…
Satellite
after 2.9
MEDIUM 6.5
CVE-2019-10177
A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is no…
Cloudforms Management Engine
Mitigation only
HIGH 7.8
CVE-2012-6711
A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment …
Enterprise Linux
after 4.3
HIGH 8.8
CVE-2019-7845EPSS 6%
Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successf…
Enterprise Linux Desktop
after 32.0.0.192
CRITICAL 9.8
CVE-2019-3888
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector…
Undertow
2.0.21+
CRITICAL 9.0
CVE-2019-3873
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.4
CVE-2019-3872
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. …
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.9
CVE-2019-10150
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during…
Openshift Container Platform
after 4.1
MEDIUM 5.5
CVE-2019-10157
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel l…
Keycloak
4.8.3 / 7.3.2+
MEDIUM 5.3
CVE-2017-15123
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users onl…
Cloudforms Management Engine
after 5.10
HIGH 7.0
CVE-2019-9755
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafte…
Enterprise Linux
Mitigation only
HIGH 8.0
CVE-2019-3895
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker c…
Openstack
0.9.0+
HIGH 7.7
CVE-2019-10144
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capab…
Rkt
after 1.30.0
HIGH 7.7
CVE-2019-10145
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` do not have seccomp…
Rkt
after 1.30.0
HIGH 7.7
CVE-2019-10147
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are not limited by …
Rkt
after 1.30.0
HIGH 8.8
CVE-2019-7837EPSS 10%
Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successfu…
Enterprise Linux Desktop
after 32.0.0.171
HIGH 8.8
CVE-2019-10132
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati…
Libvirt
after 4.1.0
HIGH 7.5
CVE-2019-0820EPSS 6%
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial…
Enterprise Linux
Patch available
CRITICAL 9.8
CVE-2016-7043
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any…
Kie Server
7.21.0+
HIGH 8.8
CVE-2019-3894
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread …
Wildfly
after 16.0.0
HIGH 7.1
CVE-2019-10131
An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local…
Enterprise Linux
6.9.9-40 / 7.0.7-28+
HIGH 8.3
CVE-2019-9900
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers c…
Openshift Service Mesh
after 1.9.0
HIGH 8.1
CVE-2019-2698EPSS 12%
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Diffi…
Openshift Container Platform
Patch available
MEDIUM 5.9
CVE-2019-2684EPSS 38%
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u2…
Openshift Container Platform
Patch available
HIGH 7.5
CVE-2019-2602
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java S…
Openshift Container Platform
Patch available
CRITICAL 9.8
CVE-2019-3899
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i…
Openshift Container Platform
Mitigation only
HIGH 7.5
CVE-2019-10245
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causi…
Satellite
0.14.0+
HIGH 7.5
CVE-2016-10746
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was …
Libvirt
1.3.1+