Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2016-5416
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …
Enterprise Linux Desktop
Mitigation only
MEDIUM 5.5
CVE-2016-3111
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers…
Pulp
after 2.8.2-1
HIGH 7.5
CVE-2015-2251
The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information…
Oceanstor Uds Firmware
Mitigation only
MEDIUM 5.0
CVE-2015-2253
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive inform…
Oceanstor Uds Firmware
Mitigation only
MEDIUM 5.3
CVE-2016-5959
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if u…
Security Privileged Identity Manager
Patch available
MEDIUM 5.5
CVE-2016-5960
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…
Security Privileged Identity Manager
Mitigation only
MEDIUM 5.5
CVE-2016-8939
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can…
Tivoli Storage Manager
Mitigation only
MEDIUM 5.3
CVE-2016-9710
IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially…
Cognos Business Intelligence Server
Patch available
MEDIUM 6.5
CVE-2015-7514
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
Ironic
Patch available
HIGH 7.5
CVE-2017-7313
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, m…
Personify360 E Business
after 7.6.1
MEDIUM 6.5
CVE-2016-3066
The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.
Spice Gtk
Mitigation only
MEDIUM 5.5
CVE-2014-9947
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.
Android
Patch available
MEDIUM 5.5
CVE-2014-9951
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentia…
Android
Patch available
MEDIUM 5.3
CVE-2017-8840
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw…
B305hw2 Firmware
Patch available
HIGH 7.5
CVE-2016-8230
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and produc…
Lenovo Service Bridge
Mitigation only
MEDIUM 5.9
CVE-2017-2309
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricte…
Junos Space
after 16.1
HIGH 7.5
CVE-2017-2304
Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X5…
Junos
Mitigation only
HIGH 7.5
CVE-2017-7338
A password management vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to carry out information disclosure via the F…
Fortiportal
after 4.0.0
MEDIUM 5.3
CVE-2017-1292
IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks agains…
Maximo Asset Management
Patch available
HIGH 7.5
CVE-2017-7439
NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving e…
Oncommand Unified Manager Core Package
Patch available
HIGH 7.5
CVE-2016-10073EPSS 84%
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and…
Vanilla
after 2.3.0
MEDIUM 5.5
CVE-2016-7977
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use …
Ghostscript
after 9.20
MEDIUM 6.5
CVE-2015-5382
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary file…
Roundcube Webmail
after 1.0.5
HIGH 7.5
CVE-2015-5383
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) log…
Roundcube Webmail
Patch available
HIGH 7.5
CVE-2015-6586
The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive in…
Wlan Acu2 Firmware
Mitigation only
MEDIUM 5.5
CVE-2017-9150
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting th…
Linux Kernel
after 4.10.9
HIGH 7.5
CVE-2017-9149
Metadata Anonymisation Toolkit (MAT) 0.6 and 0.6.1 silently fails to perform "Clean metadata" actions upon invocation from the Nautilus contextual me…
Metadata Anonymisation Toolkit
Patch available
MEDIUM 5.5
CVE-2017-6987
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…
Iphone Os
after 10.12.4
MEDIUM 5.5
CVE-2017-2507
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…
Iphone Os
3.2.2 / 10.2.1+
MEDIUM 5.3
CVE-2017-6642
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensiti…
Remote Expert Manager
No fix yet