Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2017-8712
The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fail…
Windows 10
Patch available
MEDIUM 5.3
CVE-2017-8713
The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows S…
Windows 10
Patch available
MEDIUM 5.5
CVE-2017-8677
The Windows GDI+ component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8…
Windows 10
Patch available
MEDIUM 5.5
CVE-2017-8678
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT…
Windows 10
Patch available
MEDIUM 5.5
CVE-2017-8679
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT…
Windows 10
Patch available
MEDIUM 5.3
CVE-2017-11761EPSS 7%
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially re…
Exchange Server
Patch available
HIGH 7.5
CVE-2017-1162
IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM…
Qradar Security Information And Event Manager
Patch available
MEDIUM 6.5
CVE-2017-1000250EPSS 8%
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to o…
Bluez
after 5.46
MEDIUM 5.3
CVE-2015-4688
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests.
Banner Student
No fix yet
HIGH 7.5
CVE-2017-14240
There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter.
Dolibarr
Patch available
CRITICAL 9.8
CVE-2017-14269
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices allow remote attackers to obtain sensitive information via a JSONP endpoint, as demonstrated by pa…
4gee Wifi Mbb Firmware
No fix yet
MEDIUM 5.5
CVE-2017-0776
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-384966…
Android
Patch available
MEDIUM 5.5
CVE-2017-0777
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-38342499.
Android
Patch available
HIGH 7.1
CVE-2017-0778
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.
Android
Patch available
MEDIUM 5.5
CVE-2017-0779
A information disclosure vulnerability in the Android media framework (audioflinger). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.…
Android
Patch available
MEDIUM 6.5
CVE-2017-0792
A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37305578. References: …
Android
Mitigation only
MEDIUM 5.5
CVE-2017-0793
A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946.
Android
after 8.0
HIGH 7.8
CVE-2011-3177
The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network config…
Yast2
Patch available
HIGH 7.5
CVE-2017-2550
Vulnerability in Easy Joomla Backup v3.2.4. The software creates a copy of the backup in the web root with an easily guessable filename.
Easy Joomla Backup
No fix yet
HIGH 8.8
CVE-2017-12216
A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to…
Socialminer
Mitigation only
MEDIUM 6.5
CVE-2017-12224
A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attack…
Meeting Server
Mitigation only
MEDIUM 6.5
CVE-2017-6793
A vulnerability in the Inventory Management feature of Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to v…
Prime Collaboration Provisioning
Mitigation only
MEDIUM 5.3
CVE-2015-8079
qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db.
Qtwebkit
after 5.3.2
HIGH 7.5
CVE-2015-3250EPSS 5%
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
Directory Ldap Api
after 1.0.0
HIGH 7.5
CVE-2015-3454
TelescopeJS before 0.15 leaks user bcrypt password hashes in websocket messages, which might allow remote attackers to obtain password hashes via a c…
Vulcan
after 0.14.3
CRITICAL 9.8
CVE-2015-5959
Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.…
Froxlor
after 0.9.33.1
MEDIUM 5.3
CVE-2015-6250
simple-php-captcha before commit 9d65a945029c7be7bb6bc893759e74c5636be694 allows remote attackers to automatically generate the captcha response by r…
Simple Php Captcha
after 2015-08-31
MEDIUM 5.5
CVE-2017-14156
The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initialize a certain data structure, wh…
Linux Kernel
after 4.12.10
CRITICAL 9.8
CVE-2016-3086
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeM…
Hadoop
Mitigation only
MEDIUM 5.5
CVE-2017-14140
The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local …
Linux Kernel
after 4.12.8