Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2015-4450
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…
Acrobat
10.1.15 / 11.0.12+
MEDIUM 5.0
CVE-2015-4449
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…
Acrobat
15.006.30060 / 15.008.20082+
MEDIUM 5.0
CVE-2014-8450
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…
Acrobat
10.1.15 / 11.0.12+
MEDIUM 5.0
CVE-2015-1887
IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Co…
Websphere Portal
Patch available
MEDIUM 5.0
CVE-2015-1011
Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecifie…
Lifecare Pcainfusion Firmware
after 5.0
MEDIUM 5.0
CVE-2015-1914
IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permissio…
Java
5.0.16.10 / 6.0.16.4+
MEDIUM 5.0
CVE-2015-2141
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Willia…
Crypto\+\+ Library
Patch available
HIGH 7.8
CVE-2015-1941EPSS 6%
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an un…
Tivoli Storage Manager Fastback
Mitigation only
MEDIUM 5.0
CVE-2015-4229
The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsm…
Unified Communications Domain Manager
Mitigation only
MEDIUM 5.0
CVE-2015-4216
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual A…
Content Security Management Virtual Appliance
Mitigation only
MEDIUM 6.8
CVE-2015-1851
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users t…
Ubuntu Linux
after 2014.1.4
MEDIUM 5.0
CVE-2015-4218
The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information…
Jabber
Mitigation only
MEDIUM 5.0
CVE-2015-4212
Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credential…
Webex Meeting Center
No fix yet
HIGH 7.5
CVE-2015-4208
Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive informat…
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2014-4875
CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to dis…
Chec
after 6.6
MEDIUM 6.4
CVE-2015-4209
Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive i…
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2015-4207
Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive information and bypass intend…
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2015-3236EPSS 7%
cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset…
Curl
Patch available
MEDIUM 5.0
CVE-2015-4202
Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service,…
iOS
Mitigation only
MEDIUM 5.0
CVE-2015-4194
The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether…
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2015-4345
The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for auth…
Restful Web Services
Patch available
MEDIUM 5.0
CVE-2015-3951
RLE Nova-Wind Turbine HMI devices store cleartext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.
Nova Wind Turbine Hmi Firmware
No fix yet
MEDIUM 5.0
CVE-2015-3923
Coppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.
Coppermine Photo Gallery
after 1.5.4
MEDIUM 5.0
CVE-2014-8604EPSS 7%
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which …
Xcloner
No fix yet
MEDIUM 5.0
CVE-2015-3108
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1…
Flash Player
after 17.0.0.172
MEDIUM 5.0
CVE-2015-3102
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1…
Air
after 17.0.0.172
MEDIUM 5.0
CVE-2015-3099
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1…
Air
after 17.0.0.172
MEDIUM 5.0
CVE-2015-3098
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1…
Air
after 17.0.0.172
MEDIUM 5.0
CVE-2015-3097EPSS 12%
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe…
Air
after 17.0.0.172
MEDIUM 5.0
CVE-2015-2998EPSS 26%
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstr…
Sysaid
after 15.1