Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2017-10793
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, configures an…
U Verse Firmware
No fix yet
HIGH 7.5
CVE-2017-14099
In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17…
Asterisk
Patch available
MEDIUM 6.5
CVE-2017-14114
RTPproxy through 2.2.alpha.20160822 has a NAT feature that results in not properly determining the IP address and port number of the legitimate recip…
Rtpproxy
after 2.2
MEDIUM 5.9
CVE-2017-12872
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote att…
Debian Linux
after 1.14.11
HIGH 7.5
CVE-2017-14053
NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, wh…
Oncommand Unified Manager For Clustered Data Ontap
after 7.2
MEDIUM 5.9
CVE-2017-12870
SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt …
Simplesamlphp
after 1.14.12
HIGH 7.5
CVE-2014-8675EPSS 13%
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtai…
Soplanning
after 1.32
MEDIUM 5.5
CVE-2016-5001
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A lo…
Hadoop
after 2.6.3
HIGH 7.5
CVE-2017-12734
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with network access to the integrated…
Logo\!8 Bm Fs 05 Firmware
after 1.81.1
HIGH 7.8
CVE-2017-13774
Hikvision iVMS-4200 devices before v2.6.2.7 allow local users to generate password-recovery codes via unspecified vectors.
Ivms 4200
after 2.6.2.6
HIGH 7.5
CVE-2017-0379
Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, rela…
Debian Linux
after 1.8.0
MEDIUM 5.3
CVE-2016-2964
IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the applica…
Sametime
Patch available
MEDIUM 5.3
CVE-2013-7431
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.
Googlemaps
after 3.0
HIGH 7.5
CVE-2017-3154
Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
Atlas
Mitigation only
MEDIUM 5.3
CVE-2016-2971
IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. …
Sametime
Mitigation only
HIGH 7.5
CVE-2015-7255
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which …
Ox 330p Firmware
Mitigation only
MEDIUM 6.5
CVE-2017-1110
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the i…
Curam Social Program Management
Patch available
MEDIUM 5.3
CVE-2017-9978
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on…
Quantastor
after 4.3.0
HIGH 7.5
CVE-2015-1600
Information disclosure vulnerability in Netatmo Indoor Module firmware 100 and earlier.
Indoor Module Firmware
after 100.0
HIGH 7.5
CVE-2014-9483
Emacs 24.4 allows remote attackers to bypass security restrictions.
Emacs
No fix yet
HIGH 8.8
CVE-2017-12857
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affecte…
Unified Communications Software
after 5.5.1
MEDIUM 5.3
CVE-2014-7860EPSS 10%
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which …
Dns 327l Firmware
after 1.03b04
MEDIUM 5.5
CVE-2017-13693
The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and cause…
Linux Kernel
after 4.12.9
MEDIUM 5.5
CVE-2017-13694
The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext ca…
Linux Kernel
after 4.12.9
MEDIUM 5.5
CVE-2017-13695
The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kern…
Linux Kernel
after 4.12.9
HIGH 7.5
CVE-2015-1800
The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive informat…
Galaxy S4 Firmware
No fix yet
HIGH 7.5
CVE-2017-9512
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive in…
Crucible
after 4.4.0
HIGH 7.5
CVE-2017-13143
In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote att…
Imagemagick
after 6.9.7-5
MEDIUM 5.5
CVE-2016-6310
oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
Enterprise Virtualization
after 3.6
MEDIUM 5.3
CVE-2016-6311
Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.
Jboss Enterprise Application Platform
Mitigation only