Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2014-3852
Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potent…
Pyplate
No fix yet
MEDIUM 5.0
CVE-2014-3853
Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attackers to capture this cookie by…
Pyplate
No fix yet
MEDIUM 5.0
CVE-2014-2356
Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain s…
Mguard Firmware
after 7.5.0
MEDIUM 5.0
CVE-2014-3056
The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive…
Websphere Portal
Mitigation only
MEDIUM 5.0
CVE-2014-3304
The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the …
Webex Meetings Server
Mitigation only
MEDIUM 5.0
CVE-2014-5107
concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.…
Concrete5
No fix yet
MEDIUM 5.0
CVE-2014-3301
The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by…
Webex Meetings Server
after 1.5
MEDIUM 5.0
CVE-2014-4682
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive informat…
Simatic Pcs7
after 8.0
MEDIUM 5.0
CVE-2014-4980
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information…
Nessus
after 2.3.4
HIGH 7.5
CVE-2014-3530
The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform …
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.8
CVE-2014-2519
The default configuration of EMC RecoverPoint Appliance (RPA) 4.1 before 4.1.0.1 does not enable a firewall, which allows remote attackers to obtain …
Recoverpoint Appliance
Mitigation only
MEDIUM 5.0
CVE-2014-2368
The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a craft…
Advantech Webaccess
after 7.1
MEDIUM 6.3
CVE-2014-3064
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Managemen…
Infosphere Master Data Management Collaboration Server
Mitigation only
MEDIUM 5.0
CVE-2014-4347
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x be…
Netscaler Access Gateway Firmware
No fix yet
MEDIUM 5.0
CVE-2014-4942
The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/…
Wp Easycart
after 2.0.5
MEDIUM 6.8
CVE-2014-2510
The JAXB XML parser in EMC Documentum Foundation Services (DFS) 6.6 before P39, 6.7 SP1 before P28, and 6.7 SP2 before P15, as used in My Documentum …
Centerstage
Mitigation only
MEDIUM 5.0
CVE-2014-3481
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion…
Jboss Enterprise Application Platform
after 6.2.3
MEDIUM 5.0
CVE-2013-5423
IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unspecified vectors.
Flex System Manager
Mitigation only
MEDIUM 5.0
CVE-2014-3066
IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declarat…
Tivoli Endpoint Manager
Mitigation only
MEDIUM 5.0
CVE-2014-1361
Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only …
Mac Os X
after 7.1.1
MEDIUM 5.0
CVE-2014-0891
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensit…
Websphere Application Server
Patch available
HIGH 7.8
CVE-2014-4153EPSS 7%
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.
Open Source Security Information Management
after 4.7.0
MEDIUM 5.0
CVE-2014-3249
Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.
Puppet Enterprise
Mitigation only
MEDIUM 5.0
CVE-2013-5760
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
Photo Station Firmware
after 4.0.3
MEDIUM 5.0
CVE-2013-4724
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag in a Set-C…
Cm3 Acora Content Management System
Mitigation only
MEDIUM 5.0
CVE-2013-4725
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecifi…
Cm3 Acora Content Management System
Mitigation only
MEDIUM 5.0
CVE-2013-4727
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive i…
Cm3 Acora Content Management System
Mitigation only
MEDIUM 5.0
CVE-2013-4728
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive i…
Cm3 Acora Content Management System
Mitigation only
MEDIUM 5.0
CVE-2013-1818
maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote attackers to read arbitrary files via unspecified vectors.
Mediawiki
after 1.20.2
MEDIUM 5.0
CVE-2014-3867
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspe…
Sametime
Mitigation only