Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 9.3
CVE-2015-3704EPSS 9%
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows at…
Mac Os X
after 10.10.3
HIGH 7.2
CVE-2015-3673EPSS 6%
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root …
Mac Os X
after 10.10.3
MEDIUM 6.8
CVE-2015-3659
The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple i…
Safari
after 10.10.3
HIGH 7.5
CVE-2014-9735EPSS 76%
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not prope…
Showbiz Pro
after 3.0.95
HIGH 7.2
CVE-2015-1900
IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obta…
Infosphere Datastage
Patch available
MEDIUM 6.5
CVE-2015-1974
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6…
Tivoli Directory Server
Patch available
HIGH 7.2
CVE-2015-4211
Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a cr…
Anyconnect Secure Mobility Client
Mitigation only
HIGH 10.0
CVE-2015-0546
EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by providing a valid account name.
Unified Infrastructure Manager\/provisioning
Mitigation only
MEDIUM 5.0
CVE-2015-4394
The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private fi…
Services
Patch available
MEDIUM 5.0
CVE-2015-4344
The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vect…
Services Basic Authentication
after 7.x-1.3
MEDIUM 6.4
CVE-2015-2958
Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and modify s…
Milkystep Light
after 1.82
MEDIUM 5.0
CVE-2015-2953
Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and read fil…
Milkystep Light
after 1.82
MEDIUM 6.9
CVE-2015-4185
The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session ver…
iOS
Mitigation only
MEDIUM 5.5
CVE-2015-4182
The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restr…
Identity Services Engine Software
Mitigation only
MEDIUM 6.5
CVE-2015-0768
The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implem…
Prime Network Control System
Mitigation only
MEDIUM 5.5
CVE-2015-0773
Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deleti…
Firesight System Software
Mitigation only
MEDIUM 5.0
CVE-2014-8605EPSS 7%
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient…
Xcloner
No fix yet
HIGH 7.2
CVE-2014-7872
Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges by connecting to the server.
Geekbuddy
after 4.18.120
HIGH 7.5
CVE-2015-2993EPSS 55%
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator ac…
Sysaid
after 15.1
HIGH 7.5
CVE-2014-6284
SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the challenge and response mechani…
Adaptive Server Enterprise
after 15.7
HIGH 7.2
CVE-2015-0767
Cisco Edge 300 software 1.0 and 1.1 on Edge 340 devices allows local users to obtain root privileges via unspecified commands, aka Bug ID CSCur18132.
Edge 340 Firmware
Mitigation only
HIGH 7.2
CVE-2015-0761
Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement unspecified internal functions…
Anyconnect Secure Mobility Client
after 3.1
HIGH 7.8
CVE-2015-4104
Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (…
Xen
Mitigation only
MEDIUM 6.5
CVE-2015-4038EPSS 8%
The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_sett…
Wpmembership
No fix yet
HIGH 7.5
CVE-2015-4161
SAP Afaria does not properly restrict access to unspecified functionality, which allows remote attackers to obtain sensitive information, gain privil…
Afaria
No fix yet
MEDIUM 6.8
CVE-2015-2851
client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary f…
Cloud Station
Mitigation only
HIGH 10.0
CVE-2015-4032
projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary files, and consequently exec…
Netcharts Server
Mitigation only
MEDIUM 5.8
CVE-2015-2694
The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validat…
Kerberos 5
Patch available
HIGH 9.0
CVE-2015-0160
IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbit…
Security Siteprotector System
Mitigation only
MEDIUM 5.0
CVE-2015-1895
IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 relies on client-side code to verify authorization, which allows remote attackers to bypass i…
Optim Workload Replay
Patch available