Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2017-5372
The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system informati…
Netweaver
No fix yet
HIGH 7.5
CVE-2016-6668
The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat …
Confluence Server
No fix yet
HIGH 7.5
CVE-2017-5182
Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that …
Open Enterprise Server
Mitigation only
HIGH 7.5
CVE-2016-10143
A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner U…
Tikiwiki Cms\/groupware
Patch available
MEDIUM 5.3
CVE-2016-5012
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
Moodle
Patch available
MEDIUM 5.4
CVE-2016-5014
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
Moodle
Patch available
MEDIUM 6.5
CVE-2016-5201
A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Ma…
Chrome
after 54.0.2840.87
MEDIUM 6.5
CVE-2016-5212
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insufficiently sanitized DevTools URLs, which allowed a …
Chrome
after 54.0.2840.99
MEDIUM 6.5
CVE-2016-5220
PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, wh…
Chrome
after 54.0.2840.99
HIGH 7.5
CVE-2016-9680
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.
Provisioning Services
Mitigation only
MEDIUM 5.3
CVE-2016-9677
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
Provisioning Services
Mitigation only
MEDIUM 5.5
CVE-2017-5223
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an em…
Phpmailer
after 5.2.21
HIGH 7.1
CVE-2017-2584
arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel memory or cause a denial of s…
Linux Kernel
after 4.9.3
MEDIUM 5.3
CVE-2017-5487EPSS 87%
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly rest…
WordPress
after 4.7
MEDIUM 5.5
CVE-2017-0398
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. Th…
Android
Mitigation only
MEDIUM 5.9
CVE-2016-6887
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to pred…
Matrixssl
after 3.8.6
MEDIUM 5.9
CVE-2016-8671
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to pred…
Matrixssl
after 3.8.6
HIGH 7.5
CVE-2016-9107
The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecifi…
Gajim Otr
Patch available
MEDIUM 5.5
CVE-2016-10135
An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA Voyager Tablet, BLU Advance 5…
Lg Mobile
Mitigation only
HIGH 7.5
CVE-2016-10140EPSS 7%
Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29…
Zoneminder
Patch available
HIGH 8.1
CVE-2016-3130
An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote atta…
Enterprise Service
Mitigation only
CRITICAL 9.8
CVE-2016-3152
Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the fir…
Clickshare Csc 1 Firmware
after 01.09.02.03
MEDIUM 5.5
CVE-2017-0388
An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD…
Android
Mitigation only
MEDIUM 5.5
CVE-2017-0396
An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaserver could enable a local malicious application to…
Android
Patch available
MEDIUM 5.5
CVE-2017-0397
An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data out…
Android
Patch available
MEDIUM 5.5
CVE-2017-0399
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a loca…
Android
after 7.1.1
MEDIUM 5.5
CVE-2017-0400
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious applicatio…
Android
Patch available
MEDIUM 5.5
CVE-2017-0401
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a loca…
Android
after 7.1.1
MEDIUM 5.5
CVE-2017-0402
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious applicatio…
Android
after 7.1.1
MEDIUM 5.5
CVE-2016-8460
An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permissio…
Linux Kernel
Mitigation only