Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2017-8037
In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an…
Capi Release
Mitigation only
HIGH 7.5
CVE-2017-9679
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory contents …
Android
Mitigation only
HIGH 7.5
CVE-2017-9680
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a driver may …
Android
Mitigation only
MEDIUM 5.5
CVE-2017-8254
In all Qualcomm products with Android releases from CAF using the Linux kernel, an audio client pointer is dereferenced before being checked if it is…
Android
Patch available
MEDIUM 5.3
CVE-2015-4071EPSS 10%
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target tick…
Helpdesk Pro
after 1.3.0
HIGH 7.5
CVE-2015-7945EPSS 9%
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.1…
Ganeti
after 2.9.6
MEDIUM 5.9
CVE-2017-1501
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web servic…
Websphere Application Server
Patch available
HIGH 7.5
CVE-2017-6771
A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensi…
Ultra Services Framework
Mitigation only
MEDIUM 6.5
CVE-2017-6778
A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote atta…
Ultra Services Platform
Mitigation only
MEDIUM 5.3
CVE-2017-6784
A vulnerability in the web interface of the Cisco RV340, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attack…
Small Business Rv340 Firmware
Mitigation only
MEDIUM 6.3
CVE-2017-6786
A vulnerability in Cisco Elastic Services Controller could allow an authenticated, local, unprivileged attacker to access sensitive information, incl…
Elastic Services Controller
Mitigation only
MEDIUM 6.5
CVE-2017-12855
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant de…
Xen
Mitigation only
MEDIUM 5.9
CVE-2016-6029
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure …
Emptoris Strategic Supply Management
Patch available
HIGH 7.5
CVE-2015-3614
Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspeci…
Fortimanager Firmware
Mitigation only
HIGH 7.5
CVE-2017-3107EPSS 7%
Adobe Experience Manager 6.3 and earlier has a misconfiguration vulnerability.
Experience Manager
after 6.3
HIGH 7.5
CVE-2017-3110EPSS 5%
Adobe Experience Manager 6.1 and earlier has a sensitive data exposure vulnerability.
Experience Manager
after 6.1
MEDIUM 6.5
CVE-2017-3115EPSS 6%
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an information d…
Acrobat
11.0.21 / 15.006.30355+
MEDIUM 6.5
CVE-2017-3118EPSS 9%
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypas…
Acrobat
11.0.21 / 15.006.30355+
HIGH 7.5
CVE-2017-11272EPSS 13%
Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.
Digital Editions
after 4.5.5
MEDIUM 6.5
CVE-2017-11232EPSS 8%
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable u…
Acrobat
after 17.011.30066
MEDIUM 5.5
CVE-2017-8258
An array out-of-bounds access in all Qualcomm products with Android releases from CAF using the Linux kernel can potentially occur in a camera driver.
Android
Patch available
MEDIUM 5.5
CVE-2017-8269
Userspace-controlled non null terminated parameter for IPA WAN ioctl in all Qualcomm products with Android releases from CAF using the Linux kernel c…
Android
Patch available
HIGH 7.5
CVE-2017-3130
An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting…
Fortios
Mitigation only
MEDIUM 5.5
CVE-2017-0738
A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0…
Android
Patch available
MEDIUM 5.5
CVE-2017-0739
A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.…
Android
Patch available
HIGH 7.5
CVE-2015-3277
The mod_nss module before 1.0.11 in Fedora allows remote attackers to obtain cipher lists due to incorrect parsing of multi-keyword cipherstring.
Mod Nss
after 1.0.10
MEDIUM 6.5
CVE-2015-0783
The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename var…
Zenworks Configuration Management
Mitigation only
HIGH 7.5
CVE-2015-0784EPSS 7%
Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLo…
Zenworks Configuration Management
Mitigation only
HIGH 7.5
CVE-2015-0785EPSS 7%
com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary…
Zenworks Configuration Management
Mitigation only
MEDIUM 6.5
CVE-2017-8652EPSS 23%
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that…
Edge
Patch available