Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2013-2086
The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an u…
Owncloud Server
Patch available
MEDIUM 6.6
CVE-2014-0323
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2…
Windows 7
Patch available
HIGH 7.8
CVE-2014-2264
The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remot…
Diskstation Manager
Mitigation only
MEDIUM 5.0
CVE-2013-6656
The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, processe…
Chrome
after 33.0.1750.116
MEDIUM 5.0
CVE-2014-1962
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE)…
Customer Relationship Management
Mitigation only
MEDIUM 5.0
CVE-2013-6440
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expand…
Opensaml
after 2.6.0
HIGH 7.1
CVE-2014-0266EPSS 19%
The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server…
Windows 7
Patch available
HIGH 7.1
CVE-2013-7130
The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, w…
Compute
Patch available
MEDIUM 5.0
CVE-2014-1484
Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitiv…
Firefox
after 26.0
MEDIUM 5.0
CVE-2013-2074
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal…
Kdelibs
after 4.10.3
MEDIUM 5.5
CVE-2011-4327
ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allow…
Openssh
after 5.8
MEDIUM 5.0
CVE-2013-4043
The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attacke…
Spss Collaboration And Deployment Services
Mitigation only
MEDIUM 5.0
CVE-2013-7299
framework/common/messageheaderparser.cpp in Tntnet before 2.2.1 allows remote attackers to obtain sensitive information via a header that ends in \n …
Tntnet
after 2.2
MEDIUM 5.0
CVE-2014-1664
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain use…
Gotomeeting
No fix yet
MEDIUM 5.0
CVE-2013-6447
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Re…
Jboss Seam 2 Framework
after 2.3.1
MEDIUM 5.0
CVE-2014-1637EPSS 7%
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to dow…
Command School Student Management System
No fix yet
MEDIUM 5.0
CVE-2013-6419
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a reques…
Havana
Patch available
MEDIUM 5.0
CVE-2013-6953
BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file.
Blogengine.net
after 2.8
MEDIUM 5.0
CVE-2013-7224
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, …
Fat Free Crm
after 0.12.0
MEDIUM 5.0
CVE-2013-7249
Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, a…
Fat Free Crm
after 0.12.0
MEDIUM 5.0
CVE-2013-4069
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read …
Spss Collaboration And Deployment Services
Mitigation only
MEDIUM 5.0
CVE-2013-4070
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to disco…
Spss Collaboration And Deployment Services
Mitigation only
HIGH 7.8
CVE-2013-4775EPSS 15%
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, G…
Prosafe Firmware
after 5.4.1.14
MEDIUM 5.0
CVE-2013-6968
Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows …
Webex Training Center
Mitigation only
MEDIUM 5.0
CVE-2013-6970
Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information by reading verbose error messages within server responses, aka Bug…
Webex Meeting Center
Mitigation only
MEDIUM 5.0
CVE-2013-6972
Cisco WebEx Training Center allows remote attackers to discover session numbers, and bypass host approval for audio-conference attendance, by reading…
Webex Training Center
Mitigation only
MEDIUM 5.0
CVE-2013-6709
The registration component in Cisco WebEx Training Center provides the training-session URL before payment is completed, which allows remote attacker…
Webex Training Center
Mitigation only
MEDIUM 5.0
CVE-2013-6052
OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read.
Openjpeg
after 1.3
HIGH 7.8
CVE-2012-0425
LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows contex…
Opensuse
Mitigation only
MEDIUM 5.0
CVE-2013-4617
Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it easier for remote attacker…
Jahia Xcm
after 6.6.1