Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2017-2154
Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Packag…
Hanako
Mitigation only
MEDIUM 6.3
CVE-2017-2100
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.1 and earlier allows remote attackers to conduct DNS rebinding attacks via un…
Appgoat
after 3.0.1
HIGH 8.1
CVE-2017-8288
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With thes…
Gnome Shell
Patch available
HIGH 7.3
CVE-2017-3162EPSS 5%
HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validate…
Hadoop
after 2.6.5
MEDIUM 6.5
CVE-2017-8219
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to th…
C2 Firmware
after 0.9.1_4.2_v0032.0_build_160706
HIGH 7.5
CVE-2017-2313
Juniper Networks devices running affected Junos OS versions may be impacted by the receipt of a crafted BGP UPDATE which can lead to an rpd (routing …
Junos
Mitigation only
MEDIUM 5.3
CVE-2017-2340
On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DH…
Junos
Mitigation only
CRITICAL 9.8
CVE-2016-2173EPSS 6%
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
Fedora
1.5.5+
CRITICAL 9.8
CVE-2016-3109EPSS 13%
The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
Shopware
after 5.1.4
HIGH 8.8
CVE-2017-7220
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.d…
Documentum Content Server
No fix yet
HIGH 7.7
CVE-2017-6610
A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to caus…
Adaptive Security Appliance Software
Mitigation only
MEDIUM 5.8
CVE-2017-6613
A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS …
Prime Network Registrar
Mitigation only
HIGH 8.8
CVE-2017-6616
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute…
Integrated Management Controller Supervisor
Mitigation only
HIGH 8.8
CVE-2017-6619
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute…
Integrated Management Controller Supervisor
Mitigation only
MEDIUM 6.5
CVE-2016-7536
magick/profile.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted profile.
Imagemagick
6.9.4-0+
HIGH 8.8
CVE-2016-4862
Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to exec…
Cs Cart
after 4.3.9
HIGH 8.8
CVE-2017-7692EPSS 28%
SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mis…
Squirrelmail
No fix yet
HIGH 8.8
CVE-2017-7283
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /a…
Enterprise Backup
after 9.1.1
HIGH 7.8
CVE-2017-7979
The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlatt…
Linux Kernel
Patch available
MEDIUM 6.5
CVE-2014-9907
coders/dds.c in ImageMagick allows remote attackers to cause a denial of service via a crafted DDS file.
Imagemagick
6.9.4-0+
HIGH 7.5
CVE-2017-7645EPSS 6%
The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) …
Linux Kernel
3.2.89 / 3.10.107+
HIGH 7.3
CVE-2017-1161
IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Deve…
Api Connect
Mitigation only
HIGH 7.5
CVE-2017-7892
Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit l…
Capnproto
after 0.5.3
HIGH 7.5
CVE-2017-5659
Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.
Traffic Server
after 6.2.0
HIGH 7.2
CVE-2017-6554EPSS 13%
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and co…
Privilege Manager
No fix yet
HIGH 8.8
CVE-2015-6567EPSS 9%
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does n…
Wolf Cms
after 0.8.3
HIGH 8.8
CVE-2015-6568EPSS 9%
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does n…
Wolf Cms
after 0.8.3
HIGH 7.8
CVE-2017-7218
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request p…
Pan Os
after 7.1.8
HIGH 7.5
CVE-2017-7408
Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revo…
Traps
after 3.4.3
HIGH 7.5
CVE-2017-7456EPSS 23%
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.
Mxview
No fix yet