Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2015-2997EPSS 57%
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFi…
Sysaid
after 15.1
MEDIUM 5.0
CVE-2015-0764
Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603.
Unified Meetingplace
Mitigation only
MEDIUM 5.0
CVE-2015-0763
Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session in…
Unified Meetingplace
Mitigation only
MEDIUM 5.0
CVE-2014-0999EPSS 7%
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessi…
Sendio
after 7.2.3
MEDIUM 5.0
CVE-2015-0745
Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, …
Headend Digital Broadband Delivery System
Mitigation only
HIGH 7.8
CVE-2015-4069
The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP reques…
Arcserve Unified Data Protection
after 5.0
MEDIUM 5.0
CVE-2015-0757
The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote…
Identity Services Engine Software
Mitigation only
HIGH 7.8
CVE-2015-2121
HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename…
Network Virtualization
Mitigation only
MEDIUM 5.0
CVE-2014-6190
The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL o…
Workload Deployer
Patch available
MEDIUM 5.0
CVE-2015-1909
The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before F…
Infosphere Master Data Management Server
Patch available
MEDIUM 5.0
CVE-2015-3912
Huawei E355s Mobile WiFi with firmware before 22.158.45.02.625 and WEBUI before 13.100.04.01.625 allows remote attackers to obtain sensitive configur…
Webui
after 22.158.01.00.625
MEDIUM 5.0
CVE-2014-1900
Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 …
Ycb002 Firmware
Patch available
MEDIUM 5.0
CVE-2015-3092
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 1…
Flash Player
after 17.0.0.144
MEDIUM 5.0
CVE-2015-3091
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 1…
Flash Player
after 17.0.0.144
MEDIUM 5.0
CVE-2015-3058EPSS 10%
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to obtain sensitive information from process…
Acrobat Reader
Patch available
MEDIUM 5.0
CVE-2015-1716EPSS 21%
Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows …
Windows 7
Patch available
MEDIUM 5.0
CVE-2015-3981
SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 2084037.
Netweaver Rfc Sdk
No fix yet
MEDIUM 5.0
CVE-2015-3153EPSS 7%
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow re…
Curl
after 12.1.3
MEDIUM 5.0
CVE-2015-0113
The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through…
Rational Software Architect Design Manager
Patch available
MEDIUM 5.0
CVE-2015-0846
django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote attackers to include and rea…
Django Markupfield
after 1.3.1
MEDIUM 5.0
CVE-2015-3391
The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote attackers to bypass intended access restrictions and obtain sensitive node titles…
Path Breadcrumbs
after 7.x-3.1
MEDIUM 5.0
CVE-2014-8111EPSS 7%
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to acce…
Tomcat Connectors
after 1.2.40
MEDIUM 5.0
CVE-2015-3373
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote a…
Amazon Aws
after 7.x-1.2
MEDIUM 5.0
CVE-2015-1247
The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does …
Chrome
after 42.0.2311.60
MEDIUM 5.0
CVE-2015-1244
The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the w…
Ubuntu Linux
after 42.0.2311.60
MEDIUM 5.0
CVE-2015-0969EPSS 13%
SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/health URI.
Searchblox
after 8.1
MEDIUM 5.0
CVE-2015-0938
search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to bypass intended access …
Malware Analysis Appliance
after 4.2.3.20150129
MEDIUM 5.0
CVE-2015-3319
Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obt…
Hotex Billing Manager
No fix yet
MEDIUM 5.0
CVE-2015-3044EPSS 9%
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…
Enterprise Linux Desktop Supplementary
Patch available
MEDIUM 5.0
CVE-2015-3040
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly r…
Enterprise Linux Desktop Supplementary
after 13.0.0.264