Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2016-2388 KEVEPSS 52%
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP req…
Netweaver Application Server Java
after 7.50
MEDIUM 5.8
CVE-2016-1321
Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to…
Universal Small Cell Firmware
Mitigation only
MEDIUM 5.3
CVE-2015-7444
The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to…
Websphere Commerce
Patch available
MEDIUM 5.9
CVE-2015-3197EPSS 11%
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-m…
OpenSSL
Patch available
MEDIUM 5.3
CVE-2015-2005
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attacker…
Qradar Security Information And Event Manager
Mitigation only
HIGH 8.1
CVE-2016-1526
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before…
Debian Linux
after 38.5.1
MEDIUM 5.3
CVE-2016-0864
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitiv…
Smartgrid Lighthouse Sensor Management System
after 5.0
HIGH 7.5
CVE-2016-0958
Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object.
Experience Manager
Patch available
HIGH 7.5
CVE-2016-0956EPSS 46%
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sen…
Sling
Patch available
MEDIUM 5.3
CVE-2015-7680
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allo…
Moveit Dmz
after 8.1
MEDIUM 6.5
CVE-2015-7675
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authoriz…
Moveit Dmz
after 8.1
HIGH 7.5
CVE-2016-0047EPSS 21%
WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process …
.net Framework
Mitigation only
MEDIUM 5.3
CVE-2016-1319
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communication…
Opensolaris
2.50+
MEDIUM 5.3
CVE-2016-1316
Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain se…
Telepresence Video Communication Server Software
Mitigation only
MEDIUM 6.8
CVE-2016-0723
Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information…
Linux Kernel
after 4.4.1
HIGH 7.5
CVE-2016-0811
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows …
Android
Mitigation only
CRITICAL 9.8
CVE-2015-7915
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffin…
Moduweb Vision
after 1.5.5
MEDIUM 6.5
CVE-2016-0862EPSS 10%
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive…
Snmp\/web Adapter Firmware
after 4.7
MEDIUM 5.4
CVE-2016-1730
WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal.
Iphone Os
after 9.2
MEDIUM 5.3
CVE-2016-1939
Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive informati…
Firefox
after 43.0.4
HIGH 7.5
CVE-2016-0867
CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request.
Plantvisor Enhanced
Mitigation only
MEDIUM 5.3
CVE-2015-8792
The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process h…
Libmatroska
after 1.4.3
HIGH 7.5
CVE-2015-8618
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes …
Go
Patch available
MEDIUM 5.9
CVE-2015-7488
IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover…
Spectrum Scale
Mitigation only
HIGH 8.0
CVE-2016-1489
Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) ob…
Shareit
after 3.0.18_ww
MEDIUM 6.5
CVE-2016-1618
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, whi…
Chrome
after 47.0.2526.106
MEDIUM 5.9
CVE-2016-0201
GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collisio…
Security Network Protection Firmware
Patch available
HIGH 7.5
CVE-2015-7470
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-…
Jazz Reporting Service
Patch available
MEDIUM 5.3
CVE-2016-1295
Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt…
Adaptive Security Appliance Software
Mitigation only
MEDIUM 5.3
CVE-2016-1910EPSS 6%
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.
Netweaver
No fix yet