Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2015-0844
The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1)…
Fedora
Mitigation only
MEDIUM 5.0
CVE-2015-2935
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user …
Mediawiki
after 1.19.23
MEDIUM 5.0
CVE-2015-1148
Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sens…
Mac Os X
after 10.10.2
MEDIUM 5.0
CVE-2015-1147
Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates…
Mac Os X
10.10.3+
MEDIUM 5.0
CVE-2015-1128
The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsin…
Safari
after 6.2.4
MEDIUM 5.0
CVE-2015-1112
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, as used on iOS before 8.3 and other platforms, does not properly delete browsing-h…
Safari
after 8.2
MEDIUM 5.0
CVE-2015-1111
Safari in Apple iOS before 8.3 does not delete Recently Closed Tabs data in response to a history-clearing action, which allows attackers to obtain s…
Iphone Os
after 8.2
MEDIUM 5.0
CVE-2015-1110
The Podcasts component in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to discover unique identifiers by reading asset-downlo…
Iphone Os
after 8.2
MEDIUM 5.0
CVE-2015-1090
CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing ac…
Iphone Os
after 8.2
MEDIUM 5.0
CVE-2015-1089
CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, wh…
Mac Os X
after 10.10.2
MEDIUM 5.0
CVE-2015-0991
Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception,…
Ignition
Mitigation only
MEDIUM 5.0
CVE-2015-0902
The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Me…
All In One Seo Pack
after 2.2.5.1
HIGH 9.0
CVE-2014-5405
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypas…
Mednet
after 5.8
MEDIUM 5.0
CVE-2015-2817
The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Secu…
Netweaver
No fix yet
MEDIUM 5.0
CVE-2015-0800
The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for quer…
Firefox
after 36.0.4
MEDIUM 5.0
CVE-2015-2809
The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses t…
Diskstation Manager
after 3.0
MEDIUM 5.0
CVE-2015-1892
The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to un…
Security Access Manager For Web 7.0 Firmware
after 7.0.0.11
MEDIUM 5.0
CVE-2015-0997
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user int…
Aveva Edge
7.1 / 7.1.3.4+
MEDIUM 5.0
CVE-2014-5427
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Cont…
Metsys
Mitigation only
MEDIUM 5.0
CVE-2015-2771
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain …
Triton Ap Email
after 7.8.3
MEDIUM 5.0
CVE-2015-2762
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication.
Triton Ap Web
after 7.8.3
MEDIUM 5.0
CVE-2015-2748
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive in…
Triton Ap Data
after 7.8.3
MEDIUM 5.0
CVE-2015-2335
A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.
Mybb
after 1.8.3
MEDIUM 5.0
CVE-2015-0089EPSS 21%
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…
Windows 7
Patch available
MEDIUM 5.0
CVE-2015-0087EPSS 23%
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…
Windows 7
Patch available
MEDIUM 5.0
CVE-2015-2184EPSS 8%
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.
Zeuscart
No fix yet
MEDIUM 5.0
CVE-2014-8105
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows r…
Fedora
after 1.3.2.26
MEDIUM 5.0
CVE-2015-2206
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values …
Fedora
Patch available
MEDIUM 5.0
CVE-2015-1165
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket…
Debian Linux
Mitigation only
MEDIUM 5.0
CVE-2015-2214
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.
Netcat
after 5.01