Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2016-6686
The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka i…
Android
after 7.0
MEDIUM 5.5
CVE-2016-6685
The kernel in Android before 2016-10-05 on Nexus 6P devices allows attackers to obtain sensitive information via a crafted application, aka internal …
Android
after 7.0
MEDIUM 5.5
CVE-2016-6684
The kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 9, Nexus Player, and Android One devices allows attackers to o…
Android
Mitigation only
MEDIUM 5.5
CVE-2016-6683
The kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug…
Android
after 7.0
MEDIUM 5.5
CVE-2016-6682
drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices does…
Android
after 7.0
MEDIUM 5.5
CVE-2016-6681
drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices does…
Android
after 7.0
HIGH 7.8
CVE-2016-6680
CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obtain…
Android
after 7.0
MEDIUM 5.5
CVE-2016-6679
CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obt…
Android
after 7.0
MEDIUM 5.5
CVE-2016-6678
The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application…
Android
after 7.0
MEDIUM 5.5
CVE-2016-6677
The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka…
Android
after 7.0
MEDIUM 5.5
CVE-2016-3924
services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 …
Android
Patch available
MEDIUM 5.5
CVE-2016-3918
email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7…
Android
Patch available
MEDIUM 5.5
CVE-2016-3902
drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 on Nexus 5X and 6P devices allows attackers to obt…
Android
after 7.0
MEDIUM 5.5
CVE-2016-3860
sound/soc/msm/qdsp6v2/audio_calibration.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices al…
Android
after 7.0
MEDIUM 5.5
CVE-2015-8950
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain…
Linux Kernel
after 4.0.2
HIGH 7.5
CVE-2015-2080EPSS 75%
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via i…
Fedora
No fix yet
HIGH 7.5
CVE-2015-1000012EPSS 9%
Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin
Mypixs
No fix yet
MEDIUM 5.3
CVE-2015-1000008
Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2
Mp3 Jplayer
Mitigation only
HIGH 7.5
CVE-2015-1000007
Remote file download vulnerability in wptf-image-gallery v1.03
Wptf Image Gallery
No fix yet
HIGH 7.5
CVE-2016-6653
The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-release 27 and 28 allows remote attackers to obtain sensitive information …
Cloud Foundry Cf Mysql
Mitigation only
MEDIUM 6.5
CVE-2016-6435EPSS 37%
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug …
Secure Firewall Management Center
No fix yet
MEDIUM 5.3
CVE-2016-6026
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle att…
Sterling Secure Proxy
Mitigation only
HIGH 7.5
CVE-2016-1455
Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attacker…
Nx Os
Mitigation only
HIGH 7.2
CVE-2016-7561
Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by…
Fortiwlc
after 6.1-2-29
MEDIUM 6.5
CVE-2016-6420
Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks …
Firesight System Software
Mitigation only
HIGH 7.5
CVE-2016-2307
American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End So…
Aspect Matrix Building Automation Front End Solutions Application
after 2.0
HIGH 7.5
CVE-2016-7031
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
Ceph Storage
after 10.0.0
MEDIUM 5.5
CVE-2016-6494
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by rea…
MongoDB
3.0.15 / 3.2.14+
HIGH 7.5
CVE-2016-5986
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16…
Websphere Application Server
Patch available
MEDIUM 5.3
CVE-2016-6146
The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security No…
Trex
No fix yet