Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
HIGH 7.5
CVE-2012-1010EPSS 9%
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitra…
Allwebmenus Plugin
after 1.1.7
HIGH 8.5
CVE-2012-0992
interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file …
Openemr
Patch available
HIGH 8.5
CVE-2011-4879EPSS 13%
miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; th…
Wincc Flexible
No fix yet
HIGH 7.1
CVE-2011-4877EPSS 8%
HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and M…
Wincc Flexible
No fix yet
MEDIUM 5.8
CVE-2011-4314
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework …
Jboss Enterprise Application Platform
after 1.0.1
MEDIUM 5.0
CVE-2012-0193
IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values fo…
Websphere Application Server
Patch available
HIGH 9.3
CVE-2012-0267EPSS 39%
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter tha…
Ntr Activex Control
after 1.1.8
HIGH 7.5
CVE-2011-3597EPSS 14%
Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new c…
Digest
Patch available
MEDIUM 5.0
CVE-2011-4530
Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers …
Automation License Manager
after 5.1
MEDIUM 5.0
CVE-2011-4531EPSS 8%
Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and …
Automation License Manager
after 5.1
MEDIUM 5.0
CVE-2011-5055
MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which…
Maradns
Patch available
MEDIUM 5.0
CVE-2011-4462
Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows…
Plone
after 4.1.3
HIGH 7.8
CVE-2011-4815
Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-…
Ruby
after 1.8.7-p352
HIGH 7.8
CVE-2011-5034EPSS 81%
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, wh…
Geronimo
after 2.2.1
MEDIUM 5.0
CVE-2011-5035EPSS 68%
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other pr…
Glassfish Server
after 3.1.1
MEDIUM 5.0
CVE-2011-5037
Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attack…
V8
Mitigation only
HIGH 9.3
CVE-2011-4783
The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to imp…
Idapython
after 1.5.2
HIGH 7.2
CVE-2011-4784
The NVIDIA Stereoscopic 3D driver before 7.17.12.7565 does not properly handle commands sent to a named pipe, which allows local users to gain privil…
Stereoscopic 3d Driver
after 7.17.12.7536
MEDIUM 5.0
CVE-2011-4601
family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, wh…
Pidgin
after 2.10.0
MEDIUM 5.0
CVE-2011-4603
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 valid…
Pidgin
after 2.10.0
MEDIUM 5.0
CVE-2011-4602
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, w…
Pidgin
after 2.10.0
HIGH 10.0
CVE-2011-4755
Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remo…
Parallels Plesk Small Business Panel
Mitigation only
HIGH 10.0
CVE-2011-4727
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended for storag…
Parallels Plesk Panel
Mitigation only
HIGH 9.3
CVE-2011-3410EPSS 29%
Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher fi…
Publisher
Mitigation only
MEDIUM 5.0
CVE-2011-4539EPSS 15%
dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote a…
Ubuntu Linux
Mitigation only
MEDIUM 5.0
CVE-2011-4685
Dragonfly in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unspecified content on a web page, as de…
Opera Browser
after 11.60
MEDIUM 5.5
CVE-2011-4554
One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an o…
One Click Orgs
after 1.2.2
MEDIUM 5.8
CVE-2011-4553
Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct…
One Click Orgs
after 1.2.2
HIGH 10.0
CVE-2011-2397EPSS 5%
The Agent service in Iron Mountain Connected Backup 8.4 allows remote attackers to execute arbitrary code via a crafted opcode 13 request that trigge…
Connected Backup
Mitigation only
MEDIUM 5.0
CVE-2011-3367
Arora, possibly 0.11 and other versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote atta…
Arora
Mitigation only