Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2017-11706
The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the l…
Boozt
after 2.3.3
MEDIUM 5.5
CVE-2015-3171
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive informati…
Sos
Patch available
MEDIUM 6.5
CVE-2015-5187
Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.
Candlepin
Mitigation only
HIGH 7.5
CVE-2017-8035
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-releas…
Capi Release
1.35.0 / 268+
MEDIUM 5.3
CVE-2017-9554EPSS 77%
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumer…
Diskstation Manager
after 6.1.1-15101-4
HIGH 7.5
CVE-2017-11325
An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php.
Tilde Cms
No fix yet
MEDIUM 6.5
CVE-2017-11327
An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP …
Tilde Cms
No fix yet
MEDIUM 6.5
CVE-2017-1374
Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to t…
Tririga Application Platform
Patch available
HIGH 7.5
CVE-2015-3198
The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…
Jboss Wildfly Application Server
Mitigation only
CRITICAL 9.8
CVE-2017-11502EPSS 7%
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.
Dpc3928ad Docsis Wireless Router Firmware
No fix yet
MEDIUM 5.5
CVE-2017-7028
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. w…
Iphone Os
3.2.3 / 10.2.2+
MEDIUM 5.5
CVE-2017-7029
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. w…
Iphone Os
3.2.3 / 10.2.2+
CRITICAL 9.8
CVE-2017-11435EPSS 10%
The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management conso…
Hg100r Firmware
Mitigation only
MEDIUM 6.5
CVE-2017-11448
The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized …
Imagemagick
6.9.9-0 / 7.0.6-1+
HIGH 7.5
CVE-2017-9245
The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging …
News And Weather
3.3.1+
MEDIUM 6.5
CVE-2017-7947
NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging …
Clustered Data Ontap
Mitigation only
HIGH 7.5
CVE-2017-9812EPSS 11%
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before M…
Anti Virus For Linux Server
after 8.0.3.297
HIGH 7.5
CVE-2017-9933
Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.
Joomla\!
Mitigation only
MEDIUM 6.5
CVE-2017-2642
Moodle 3.x has user fullname disclosure on the user preferences page.
Moodle
Patch available
HIGH 7.5
CVE-2017-7683
Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.
Openmeetings
Mitigation only
CRITICAL 9.8
CVE-2017-1000362
The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup direct…
Jenkins
after 1.498
MEDIUM 5.9
CVE-2017-1000007
txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.
Txaws
Mitigation only
HIGH 7.5
CVE-2017-1000025
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password…
Epiphany
Mitigation only
HIGH 7.5
CVE-2017-1000029EPSS 8%
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include …
Glassfish Server
Mitigation only
MEDIUM 6.5
CVE-2017-0196EPSS 18%
An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via…
Edge
Patch available
HIGH 8.1
CVE-2015-5152
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote atta…
Foreman
Mitigation only
CRITICAL 9.1
CVE-2017-9788EPSS 57%
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…
HTTP Server
after 2.4.26
CRITICAL 9.8
CVE-2016-8964
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-F…
Bigfix Inventory
9.2.8+
CRITICAL 9.8
CVE-2017-11165EPSS 64%
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /servic…
Dt80 Dex Firmware
No fix yet
MEDIUM 5.5
CVE-2017-8564
Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows …
Windows 10
Patch available