Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
MEDIUM 6.5
CVE-2016-1444
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.…
Telepresence Video Communication Server
Mitigation only
HIGH 8.8
CVE-2016-1442
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via …
Prime Infrastructure
Mitigation only
MEDIUM 6.5
CVE-2016-6170EPSS 41%
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary D…
Enterprise Linux
after 9.10.3
MEDIUM 5.3
CVE-2016-4465EPSS 10%
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a n…
Struts
Mitigation only
CRITICAL 9.8
CVE-2016-4438EPSS 17%
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
Struts
Mitigation only
HIGH 7.5
CVE-2016-4433EPSS 10%
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted …
Struts
Mitigation only
HIGH 7.5
CVE-2016-4431EPSS 10%
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging …
Struts
Mitigation only
HIGH 7.5
CVE-2016-3092EPSS 36%
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.…
Tomcat
after 1.3.1
HIGH 8.2
CVE-2016-1182EPSS 26%
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to con…
Struts
Patch available
HIGH 7.5
CVE-2015-0899EPSS 21%
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modi…
Struts
Patch available
HIGH 7.5
CVE-2016-1336EPSS 9%
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter…
Epc3928 Firmware
No fix yet
HIGH 7.5
CVE-2016-1328EPSS 9%
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless paramete…
Epc3928 Firmware
No fix yet
HIGH 8.2
CVE-2016-1441
Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem…
Cloud Network Automation Provisioner
Mitigation only
HIGH 8.8
CVE-2016-1408
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute ar…
Prime Infrastructure
Mitigation only
HIGH 8.4
CVE-2016-3646EPSS 18%
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…
Norton Security
after 2016.0
HIGH 8.4
CVE-2016-3644EPSS 18%
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…
Norton Security
after 2016.0
HIGH 8.4
CVE-2016-2207EPSS 18%
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…
Mail Security For Microsoft Exchange
after 10.6.1-3
HIGH 7.5
CVE-2016-5301
The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP respon…
Leap
after 1.1
HIGH 7.5
CVE-2015-8899
Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA re…
Ubuntu Linux
after 2.75
HIGH 7.2
CVE-2016-5840EPSS 8%
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbit…
Deep Discovery Inspector
No fix yet
HIGH 7.8
CVE-2016-5828
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, whi…
Linux Kernel
3.10.103 / 3.14.74+
MEDIUM 5.6
CVE-2016-4825
The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary…
Welcart E Commerce
1.8.3+
HIGH 7.5
CVE-2016-1438
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable co…
Asyncos
Mitigation only
MEDIUM 6.5
CVE-2016-1434
The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files v…
Ip Phone 8800 Series Firmware
Mitigation only
MEDIUM 6.5
CVE-2016-4530
OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and data loss)…
Pi Sql Data Access Server 2016
Mitigation only
MEDIUM 6.5
CVE-2016-4518
OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message.
Pi Af Server 2016
after 2.7.0
CRITICAL 9.8
CVE-2016-1395
The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W dev…
Rv130w Wireless N Multifunction Vpn Router Firmware
Mitigation only
MEDIUM 6.1
CVE-2016-5433
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.
Ios Receiver
after 6.1.5
MEDIUM 6.0
CVE-2016-2841
The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause …
Ubuntu Linux
after 2.5.0
HIGH 7.5
CVE-2016-5361
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (…
Libreswan
after 3.16