Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2014-7259
SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain…
Kaku San Sei Million Aruthur
after 1.0.1
MEDIUM 5.0
CVE-2014-7243
LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, which allows remote attackers…
L 04d
Mitigation only
MEDIUM 5.0
CVE-2014-9018
Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to sh…
Icecast
after 2.4.0
MEDIUM 5.0
CVE-2014-8775
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote …
Modx Revolution
No fix yet
MEDIUM 5.0
CVE-2014-9177
The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html…
Html5 Mp3 Player With Playlist Free
after 2.6
MEDIUM 5.0
CVE-2014-8874
The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, which makes it easier for remot…
Ke Questionnaire
after 2.5.2
HIGH 7.8
CVE-2014-8425
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.
Vap2500 Firmware
after 08.41
MEDIUM 5.0
CVE-2014-6075
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2…
Qradar Risk Manager
Patch available
MEDIUM 5.0
CVE-2014-8552
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through S…
Simatic Pcs 7
Mitigation only
HIGH 7.8
CVE-2014-8678
The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related …
Oputils
after 7.0
MEDIUM 5.0
CVE-2014-7848
lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct re…
Moodle
after 2.4.11
MEDIUM 5.0
CVE-2014-5325
The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x throu…
Direct Web Remoting
after 2.0.10
MEDIUM 6.8
CVE-2014-6477
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote au…
Database Server
Patch available
MEDIUM 5.0
CVE-2014-9025
The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email add…
Commerce
Mitigation only
MEDIUM 6.8
CVE-2014-6624
The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unsp…
Clearpass
after 6.3.4
MEDIUM 5.0
CVE-2014-6622
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors.
Clearpass
after 6.3.4
MEDIUM 5.0
CVE-2014-6621
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which a…
Clearpass
after 6.3.4
MEDIUM 5.0
CVE-2014-4458
The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might all…
Mac Os X
after 10.10.0
MEDIUM 5.0
CVE-2014-4453
Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight o…
Iphone Os
after 10.10.0
MEDIUM 5.0
CVE-2014-7992EPSS 27%
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information fro…
iOS
Mitigation only
HIGH 7.2
CVE-2013-0347
The Gentoo init script for webfs uses world-readable permissions for /var/log/webfsd.log, which allows local users to have unspecified impact by read…
Webfs
No fix yet
MEDIUM 5.0
CVE-2013-3737
The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (…
Request Tracker
Patch available
MEDIUM 6.4
CVE-2014-8566
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via…
Linux
after 0.8.0
MEDIUM 5.0
CVE-2014-8736
The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been…
Open Atrium
after 7.x-2.21
MEDIUM 5.0
CVE-2014-8437
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.…
Flash Player
11.2.202.418 / 13.0.0.252+
MEDIUM 5.0
CVE-2014-8709
The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allow…
Linux Kernel
after 3.13.4
MEDIUM 5.0
CVE-2014-8665
The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files.
Business Intelligence Development Workbench
Mitigation only
MEDIUM 5.0
CVE-2014-8666
The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain …
Business Intelligence Development Workbench
Mitigation only
HIGH 7.5
CVE-2014-2374
The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors…
Axm Net
Patch available
MEDIUM 5.0
CVE-2014-6130
The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for …
Notes Traveler
after 9.0.1.2