Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2016-9720
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Referen…
Qradar Incident Forensics
Patch available
MEDIUM 5.3
CVE-2016-9725
IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources fr…
Qradar Security Information And Event Manager
Patch available
MEDIUM 5.3
CVE-2016-4947
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.
Hue
after 3.9.0
HIGH 7.5
CVE-2016-4949
Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename…
Manager
after 5.5.0
HIGH 7.5
CVE-2016-4950
Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions.
Manager
after 5.5.0
MEDIUM 5.5
CVE-2013-5653
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted p…
Debian Linux
Patch available
HIGH 7.5
CVE-2016-3127
An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote…
Good Control Server
after 2.2.511.26
MEDIUM 5.9
CVE-2016-6882
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information …
Matrixssl
after 3.8.6
MEDIUM 5.9
CVE-2016-6883EPSS 14%
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack.
Matrixssl
after 3.8.2
MEDIUM 5.5
CVE-2016-7409
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument…
Dropbear Ssh
after 2016.73
HIGH 7.5
CVE-2017-5995
The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified …
Ontap Select Deploy Administration Utility
Mitigation only
HIGH 7.4
CVE-2017-2685
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (ex…
Sinumerik Integrate Access Mymachine\/ethernet
Mitigation only
MEDIUM 6.5
CVE-2016-8507
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facet…
Yandex Browser
16.10.0.2357+
HIGH 7.5
CVE-2017-5925
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors…
A64
No fix yet
HIGH 7.5
CVE-2017-5926
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. …
A64
No fix yet
HIGH 7.5
CVE-2017-5927
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. …
A64
No fix yet
MEDIUM 5.3
CVE-2016-4042
Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.
Plone
Mitigation only
MEDIUM 5.5
CVE-2017-6076
In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to …
Wolfssl
3.10.2+
HIGH 7.5
CVE-2017-6206EPSS 16%
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31…
Websmart Dgs 1510 Series Firmware
after 1.31.b001
MEDIUM 5.9
CVE-2016-3052
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man…
Websphere Mq
after 8.0.0.5
MEDIUM 6.5
CVE-2016-9384
Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.
Xen
Patch available
HIGH 7.5
CVE-2017-3841
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sens…
Secure Access Control System
Mitigation only
MEDIUM 5.3
CVE-2017-3842
A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, r…
Intrusion Prevention System Device Manager
Mitigation only
HIGH 7.5
CVE-2015-4057
The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon a request for the Settings sc…
Vce Vision Intelligent Operations
after 2.6.4
HIGH 7.8
CVE-2016-9314
Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6…
Interscan Web Security Virtual Appliance
after 6.5
CRITICAL 9.8
CVE-2017-6070
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template p…
Form Builder
after 1.12.2
MEDIUM 5.3
CVE-2017-6071
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
Form Builder
after 1.12.2
MEDIUM 5.3
CVE-2017-6072
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.
Form Builder
after 1.12.2
MEDIUM 5.5
CVE-2017-0038EPSS 82%
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows …
Windows 10
Patch available
MEDIUM 5.3
CVE-2016-6249
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in…
Big Ip Access Policy Manager
Mitigation only