Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2014-7837
mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remo…
Moodle
after 2.4.11
MEDIUM 5.0
CVE-2014-8000
Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a user…
Unified Communications Manager Im And Presence Service
Mitigation only
MEDIUM 6.4
CVE-2014-7194
TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before…
Managed File Transfer Internet Server
after 7.2.3
HIGH 7.5
CVE-2014-9024
The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path.
Protected Pages
Patch available
MEDIUM 5.5
CVE-2014-9023
The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authent…
Twilio
Mitigation only
MEDIUM 6.4
CVE-2014-9022
The Webform Component Roles module 6.x-1.x before 6.x-1.8 and 7.x-1.x before 7.x-1.8 for Drupal allows remote attackers to bypass the "disabled" rest…
Web Component Roles
Patch available
MEDIUM 5.0
CVE-2014-8493EPSS 8%
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.
Zxhn H108l Firmware
No fix yet
HIGH 10.0
CVE-2014-9002EPSS 5%
Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in …
Xprintserver
Mitigation only
MEDIUM 6.5
CVE-2014-9000EPSS 9%
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to…
Mule Enterprise Management Console
No fix yet
HIGH 7.5
CVE-2014-4457
The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intend…
Iphone Os
after 8.1
HIGH 7.2
CVE-2014-4451
Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lo…
Iphone Os
after 8.1
MEDIUM 5.0
CVE-2014-2268EPSS 31%
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-in…
Vtiger Crm
No fix yet
MEDIUM 6.4
CVE-2014-2684
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 d…
Zendopenid
after 2.0.1
HIGH 7.1
CVE-2014-7998
Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a m…
iOS
Mitigation only
HIGH 7.5
CVE-2014-5424EPSS 11%
Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or p…
Connected Components Workbench
after 6.01.00
HIGH 7.2
CVE-2014-8359
Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code and conduct D…
Mobile Partner Firmware
No fix yet
HIGH 7.5
CVE-2014-3674
Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of …
Openshift
after 2.1.8
HIGH 7.5
CVE-2014-8442EPSS 5%
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.…
Flash Player
11.2.202.418 / 13.0.0.252+
MEDIUM 5.0
CVE-2014-6331EPSS 20%
Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not pr…
Active Directory Federation Services
Mitigation only
MEDIUM 5.1
CVE-2014-4078EPSS 20%
The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for doma…
Internet Information Services
Mitigation only
MEDIUM 5.0
CVE-2014-8655EPSS 7%
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass aut…
Firmware
No fix yet
HIGH 7.2
CVE-2014-5507
iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local users to gain privileges via a Tr…
Ibackup
after 10.0.0.32
MEDIUM 5.0
CVE-2014-7986
install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.
Espocrm
after 2.5.2
MEDIUM 6.8
CVE-2014-3684
The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and e…
Torque Resource Manager
Mitigation only
MEDIUM 5.0
CVE-2013-6796EPSS 6%
The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous …
Deepofix
after 3.3
MEDIUM 5.0
CVE-2014-4624
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which a…
6.0
No fix yet
MEDIUM 5.0
CVE-2012-5243
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.
Banana Dance
No fix yet
MEDIUM 5.0
CVE-2012-5696
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers…
Smartphone Pentest Framework
after 0.1.2
MEDIUM 5.0
CVE-2014-3381
The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which …
Asyncos
after 8.5
HIGH 7.5
CVE-2014-4427
App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.
Mac Os X
after 10.9.5