Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2014-8637
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensi…
Firefox
after 34.0.5
MEDIUM 5.0
CVE-2014-10026
index.cgi in D-Link DAP-1360 with firmware 2.5.4 and earlier allows remote attackers to bypass authentication and obtain sensitive information by set…
Dap 1360 Firmware
after 2.5.4
MEDIUM 5.0
CVE-2014-10005
Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which revea…
Maian Uploader
No fix yet
MEDIUM 5.0
CVE-2014-100009
The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the ins…
Js Multi Hotel
after 2.2.1
MEDIUM 5.0
CVE-2014-8035
The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which …
Webex Meetings Server
Mitigation only
MEDIUM 5.0
CVE-2015-0922EPSS 13%
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows …
Epolicy Orchestrator
after 4.6.8
MEDIUM 5.0
CVE-2014-9579
VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive information by re…
Vdg Sense
No fix yet
MEDIUM 5.0
CVE-2014-9576
VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2) postgre…
Vdg Sense
No fix yet
MEDIUM 5.0
CVE-2014-4638
EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to conduct frame-injection attacks and obtain sensitive information via u…
Documentum Wdk
after 6.7
MEDIUM 5.0
CVE-2011-5314
templates/default/index.php in Redaxscript 0.3.2 allows remote attackers to obtain sensitive information via a direct request, which reveals the full…
Redaxscript
No fix yet
MEDIUM 5.0
CVE-2014-1908EPSS 7%
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plug…
Videowhisper Live Streaming Integration
after 4.27.4
MEDIUM 5.0
CVE-2014-6229
The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key …
Hiphop Virtual Machine
after 3.2.0
MEDIUM 5.0
CVE-2013-6043
The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the …
Webuzo
after 2.1.3
MEDIUM 5.0
CVE-2014-8017
The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted req…
Identity Services Engine Software
Mitigation only
MEDIUM 5.0
CVE-2014-9408
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 uses part of the MAC add…
Activator
No fix yet
MEDIUM 5.0
CVE-2014-6164
IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, a…
Websphere Application Server
Mitigation only
MEDIUM 5.0
CVE-2014-6088
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote a…
Security Access Manager For Web
Mitigation only
MEDIUM 5.0
CVE-2014-6086
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not ensure …
Security Access Manager For Mobile
Mitigation only
MEDIUM 5.0
CVE-2014-6083
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote a…
Security Access Manager For Web
Mitigation only
MEDIUM 5.0
CVE-2014-8553
The mci_account_get_array_by_id function in api/soap/mc_account_api.php in MantisBT before 1.2.18 allows remote attackers to obtain sensitive informa…
Mantisbt
after 1.2.17
MEDIUM 5.0
CVE-2014-9250
Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remot…
Zenoss Core
after 5.0.0
MEDIUM 5.0
CVE-2014-9245
Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name a…
Zenoss Core
after 5.0.0
MEDIUM 5.0
CVE-2014-6114
The Hosted Transparent Decision Service in the Rule Execution Server in IBM WebSphere ILOG JRules 7.1 before MP1 FP5 IF43; WebSphere Operational Deci…
Operational Decision Manager
Mitigation only
MEDIUM 5.0
CVE-2014-6355EPSS 34%
The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows…
Windows 7
Mitigation only
MEDIUM 5.0
CVE-2014-8452EPSS 18%
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to read arbitrary files via an XML ex…
Acrobat Reader
Mitigation only
MEDIUM 5.0
CVE-2014-8451EPSS 9%
An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain …
Acrobat
Mitigation only
MEDIUM 5.0
CVE-2014-8448EPSS 9%
An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain …
Acrobat
Mitigation only
MEDIUM 5.0
CVE-2014-8009
The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log…
Unified Computing System
after 2.1
MEDIUM 5.0
CVE-2014-9279
The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain data…
Mantisbt
Patch available
HIGH 7.8
CVE-2014-9303
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a U…
N5200 Active Network Control Panel
No fix yet