Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2013-3981
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users v…
Sametime
Mitigation only
HIGH 7.1
CVE-2013-1191
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to ga…
Nx Os
Mitigation only
HIGH 7.1
CVE-2014-2200
Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to ga…
Nx Os
Mitigation only
HIGH 9.0
CVE-2014-2504
EMC Documentum D2 3.1 before P20, 3.1 SP1 before P02, 4.0 before P10, 4.1 before P13, and 4.2 before P01 allows remote authenticated users to bypass …
Documentum D2
Mitigation only
MEDIUM 5.0
CVE-2014-3848EPSS 9%
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials vi…
Imember360
after 3.9.000
MEDIUM 5.0
CVE-2013-4223
The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP aut…
Nullmailer
Mitigation only
HIGH 7.5
CVE-2013-2757
Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network…
Cloudplatform
Patch available
MEDIUM 5.0
CVE-2014-3844
The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings…
Color Picker
after 1.1
MEDIUM 5.5
CVE-2013-4320
The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenti…
TYPO3
Mitigation only
HIGH 9.0
CVE-2013-7383
x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain privileges via unspecified vect…
X2go Server
after 4.0.0.7
MEDIUM 5.5
CVE-2013-4431
Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users …
Mahara
after 1.5.11
MEDIUM 5.0
CVE-2013-4406
The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not properly check block permissions…
Quicktabs
Patch available
HIGH 8.5
CVE-2014-2084
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin in…
Skybox View Appliance Iso
No fix yet
HIGH 7.9
CVE-2014-1649EPSS 42%
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLR…
Workspace Streaming
after 7.5.0
HIGH 7.2
CVE-2014-1807
The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…
Windows 7
Patch available
MEDIUM 6.8
CVE-2014-1809EPSS 10%
The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypas…
Office
Mitigation only
HIGH 7.5
CVE-2014-0520
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…
Flash Player
11.2.202.359 / 13.0.0.111+
HIGH 10.0
CVE-2014-0525EPSS 6%
The API in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X does not prevent access to unmapped memory, which…
Acrobat Reader
Mitigation only
HIGH 7.5
CVE-2014-0516
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…
Flash Player
11.2.202.359 / 13.0.0.111+
HIGH 7.5
CVE-2014-0517
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…
Flash Player
11.2.202.359 / 13.0.0.111+
HIGH 7.5
CVE-2014-0518
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…
Flash Player
11.2.202.359 / 13.0.0.111+
HIGH 7.5
CVE-2014-0519
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…
Flash Player
11.2.202.359 / 13.0.0.111+
MEDIUM 6.8
CVE-2011-2514
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…
Icedtea Web
after 1.8.8
MEDIUM 5.0
CVE-2013-4501
The default views in the Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote attackers to obtain sensitive quiz results via unspecified vecto…
Quiz
Patch available
MEDIUM 5.0
CVE-2014-0192
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive inf…
Foreman
Patch available
MEDIUM 6.5
CVE-2013-0187
Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
Foreman
after 1.0
MEDIUM 6.9
CVE-2014-3215
seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the s…
Policycoreutils
Mitigation only
HIGH 7.6
CVE-2013-5016
Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform, allows remote attackers to b…
Symantec Critical System Protection
after 5.2.8
MEDIUM 5.8
CVE-2014-0116EPSS 7%
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me…
Struts
Mitigation only
MEDIUM 6.7
CVE-2014-3124
The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or poss…
Xen
Patch available