Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2017-14617
In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malici…
Poppler
Mitigation only
MEDIUM 5.9
CVE-2016-8738
In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to …
Struts
Patch available
CRITICAL 9.8
CVE-2017-12611EPSS 95%
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can …
Struts
Patch available
HIGH 7.5
CVE-2017-9793EPSS 8%
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allo…
Struts
Patch available
HIGH 7.5
CVE-2017-9804EPSS 8%
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is us…
Struts
Patch available
HIGH 7.5
CVE-2015-5179
FreeIPA might display user data improperly via vectors involving non-printable characters.
Freeipa
after 4.5.0
MEDIUM 6.5
CVE-2015-5248
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
Feedhenry Enterprise Mobile Application Platform
No fix yet
HIGH 7.5
CVE-2017-7924EPSS 21%
An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-…
1763 L16bwa Firmware
Mitigation only
MEDIUM 6.5
CVE-2017-14604
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .de…
Debian Linux
3.23.90+
CRITICAL 9.8
CVE-2017-6315EPSS 15%
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.
Astaro Security Gateway Firmware
No fix yet
HIGH 7.2
CVE-2014-5362
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages…
Landesk Management Suite
after 9.6
MEDIUM 6.5
CVE-2015-3419
vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vecto…
Vbulletin
Mitigation only
CRITICAL 9.8
CVE-2017-10700
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of …
Qts
Mitigation only
HIGH 8.8
CVE-2017-9333
OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the U…
Openwebif
Patch available
HIGH 7.8
CVE-2017-14518
In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
Poppler
No fix yet
HIGH 7.8
CVE-2017-14520
In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling mal…
Poppler
No fix yet
HIGH 8.8
CVE-2017-14509
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote fil…
Sugarcrm
after 7.7.2.2
HIGH 7.5
CVE-2017-14511
An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/…
E Recruiting
Mitigation only
MEDIUM 5.5
CVE-2017-14489
The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (p…
Linux Kernel
after 4.13.2
MEDIUM 6.5
CVE-2017-1556
IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and ca…
Api Connect
Mitigation only
HIGH 7.5
CVE-2017-14430
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allow remote attackers to …
Dir 850l Firmware
No fix yet
HIGH 8.8
CVE-2017-8682EPSS 43%
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Window…
Office 2007
Patch available
HIGH 7.0
CVE-2017-8699EPSS 20%
Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold…
Windows 10
Patch available
MEDIUM 5.3
CVE-2017-8704
The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows a denial of service vulnerability when it fails to properly…
Windows 10
Patch available
HIGH 7.8
CVE-2017-8714EPSS 6%
The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote co…
Windows 10
Patch available
MEDIUM 5.9
CVE-2017-1519
IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a p…
Db2
Patch available
HIGH 7.8
CVE-2017-14344
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to …
Windriver
after 12.5.1
HIGH 7.5
CVE-2017-14335EPSS 21%
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/…
Hb7024xt Firmware
No fix yet
CRITICAL 9.1
CVE-2017-14230
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused…
Imap
after 3.0.3
MEDIUM 5.3
CVE-2017-14231
GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username subst…
Genixcms
after 1.0.2