Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2015-6759
The shouldTreatAsUniqueOrigin function in platform/weborigin/SecurityOrigin.cpp in Blink, as used in Google Chrome before 46.0.2490.71, does not ensu…
Chrome
after 45.0.2454.101
MEDIUM 5.0
CVE-2015-7628
Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Ad…
Flash Player
after 19.0.0.190
MEDIUM 5.0
CVE-2015-7624
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Ac…
Acrobat
15.006.30094 / 15.009.20069+
MEDIUM 5.0
CVE-2015-6706
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Ac…
Acrobat
15.006.30094 / 15.009.20069+
MEDIUM 5.0
CVE-2015-6705
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Ac…
Acrobat
15.006.30094 / 15.009.20069+
MEDIUM 5.0
CVE-2015-6057EPSS 16%
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Di…
Edge
Mitigation only
MEDIUM 6.8
CVE-2015-6328
The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and r…
Prime Collaboration Assurance
Mitigation only
MEDIUM 5.0
CVE-2015-7761
Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecifi…
Mac Os X
after 10.10.5
CRITICAL 10.0
CVE-2015-0987
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which al…
Cx Programmer
after 9.5
MEDIUM 5.0
CVE-2015-7322
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 befo…
Pulse Connect Secure
No fix yet
MEDIUM 5.0
CVE-2015-6474
IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML source code.
Danfoss Tlx Pro\+
Mitigation only
MEDIUM 5.0
CVE-2015-6469
The interpreter in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allows remote attackers to discover script source code via unspecified vectors.
Danfoss Tlx Pro\+
Mitigation only
MEDIUM 5.0
CVE-2015-4503
The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open…
Firefox
after 40.0.3
MEDIUM 5.0
CVE-2015-6940
The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x…
Data Integration
Patch available
MEDIUM 5.0
CVE-2015-6679EPSS 5%
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ad…
Air
after 18.0.0.199
MEDIUM 5.0
CVE-2015-5576EPSS 5%
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ad…
Air
after 18.0.0.199
MEDIUM 5.0
CVE-2015-5572
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ad…
Air
after 18.0.0.199
MEDIUM 5.0
CVE-2015-7305
The Scald module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to fields, which allows remote attackers to obtain sensitive ato…
Scald
Patch available
MEDIUM 5.0
CVE-2015-5909
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain pote…
Xcode
after 6.4
MEDIUM 5.0
CVE-2015-5906
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make…
Iphone Os
after 8.4.1
MEDIUM 5.0
CVE-2015-5885
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.
Iphone Os
after 10.10.5
MEDIUM 5.0
CVE-2015-5860
The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing…
Iphone Os
after 8.4.1
MEDIUM 5.0
CVE-2015-5858
The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain s…
Iphone Os
after 8.4.1
MEDIUM 5.0
CVE-2015-5831
NetworkExtension in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows attackers to obtain sen…
Mac Os X
after 10.10.5
MEDIUM 5.0
CVE-2015-5827
WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an object reference via vectors involving a (1) cust…
Safari
after 8.4.1
MEDIUM 5.0
CVE-2015-7226
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the dis…
Administration Views
Patch available
MEDIUM 5.0
CVE-2015-6830EPSS 10%
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass…
phpMyAdmin
Patch available
MEDIUM 5.0
CVE-2015-2505EPSS 18%
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace i…
Exchange Server
Mitigation only
MEDIUM 5.0
CVE-2015-6276
Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which …
Telepresence System Software Ix
Mitigation only
MEDIUM 5.0
CVE-2015-6727
The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determin…
Ubuntu Linux
after 1.23.9