Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2017-14820
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…
Foxit Reader
Patch available
MEDIUM 6.5
CVE-2017-14821
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…
Foxit Reader
Patch available
MEDIUM 6.5
CVE-2017-14822
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…
Foxit Reader
Patch available
HIGH 7.5
CVE-2017-17793
Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a fil…
Blogotext
after 3.7.6
MEDIUM 5.3
CVE-2017-17776
Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.
Paid To Read Script
No fix yet
MEDIUM 6.5
CVE-2017-16786
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to …
Lantime Firmware
after 6.24.003
HIGH 8.8
CVE-2017-15700
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the…
Sling Authentication Service
Mitigation only
HIGH 7.8
CVE-2017-15104
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi serv…
Enterprise Linux
Mitigation only
CRITICAL 9.8
CVE-2017-17734
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.
Cms Made Simple
2.2.5+
CRITICAL 9.8
CVE-2017-17735
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
Cms Made Simple
2.2.5+
CRITICAL 9.8
CVE-2017-3185
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to proces…
Camera Firmware
Mitigation only
HIGH 8.1
CVE-2017-3194
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to con…
Pandora
8.3.2+
HIGH 8.8
CVE-2017-14184
An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below version…
Forticlient
4.4.2334 / 5.6.0+
MEDIUM 5.9
CVE-2017-12373EPSS 13%
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unau…
Adaptive Security Appliance 5505 Firmware
Mitigation only
MEDIUM 5.1
CVE-2017-17556
A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by…
Synaptics Touchpad Driver
Mitigation only
MEDIUM 6.5
CVE-2017-16787EPSS 7%
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging…
Lantime Firmware
6.24.004+
HIGH 7.2
CVE-2017-7738
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_adm…
Fortios
after 5.6.2
MEDIUM 5.9
CVE-2017-17549
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.1…
Application Delivery Controller Firmware
Mitigation only
MEDIUM 6.5
CVE-2017-11939EPSS 6%
Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permi…
Office
Patch available
MEDIUM 5.3
CVE-2017-11919EPSS 6%
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and…
Chakracore
1.7.5+
MEDIUM 6.5
CVE-2017-11927EPSS 10%
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi…
Windows 10
Patch available
MEDIUM 5.5
CVE-2017-11934EPSS 13%
Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certa…
Office
Patch available
MEDIUM 5.3
CVE-2017-16687
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00,…
Hana Database
Mitigation only
MEDIUM 5.3
CVE-2017-1613
IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non-sensitive Engagement Center …
Connections
Mitigation only
MEDIUM 5.9
CVE-2017-8865
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 do not provide sufficient protections against capture-replay attacks, all…
Stemosaur Firmware
after 0.0.794
MEDIUM 6.5
CVE-2015-8470
The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes i…
Puppet Enterprise
after 2015.2.3
HIGH 7.5
CVE-2017-3111EPSS 7%
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstance…
Experience Manager
Mitigation only
MEDIUM 6.5
CVE-2017-16369EPSS 7%
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and ear…
Acrobat
after 17.012.20098
MEDIUM 5.5
CVE-2017-11273
An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. Adobe Digital Editions parses crafted XML files in an unsafe manner, wh…
Digital Editions
after 4.5.6
MEDIUM 6.5
CVE-2017-16854
In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a custo…
Debian Linux
after 6.0.1