Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2014-0685
Cisco Nexus 1000V InterCloud 5.2(1)IC1(1.2) and earlier for VMware allows remote attackers to bypass ACL deny statements via crafted (1) IGMPv2 or (2…
Cisco Nexus 1000v Intercloud
after 5.2
MEDIUM 6.9
CVE-2014-2905
fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal vari…
Fish
Mitigation only
MEDIUM 5.8
CVE-2014-3001
The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to…
FreeBSD
Mitigation only
MEDIUM 6.8
CVE-2014-3006
Sitepark Information Enterprise Server (IES) 2.9 before 2.9.6, when upgraded from an earlier version, does not properly restrict access, which allows…
Information Enterprise Server
Mitigation only
MEDIUM 6.2
CVE-2014-3125
Xen 4.4.x, when running on an ARM system, does not properly context switch the CNTKCTL_EL1 register, which allows local guest users to modify the har…
Xen
Patch available
MEDIUM 5.5
CVE-2013-7061
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via …
Plone
Mitigation only
HIGH 7.2
CVE-2014-2173
Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 do not properly restrict access to the serial port, which allows local users t…
Telepresence Te Software
Mitigation only
MEDIUM 6.0
CVE-2014-1989
Cybozu Garoon 3.0 through 3.7 SP3 allows remote authenticated users to bypass intended access restrictions and delete schedule information via unspec…
Garoon
Mitigation only
MEDIUM 5.0
CVE-2013-1807EPSS 8%
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow …
Php Fusion
after 7.02.05
MEDIUM 5.0
CVE-2014-3133
SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered o…
Netweaver Java Application Server
Mitigation only
HIGH 7.2
CVE-2014-0470
super.c in Super 3.30.0 does not check the return value of the setuid function when the -F flag is set, which allows local users to gain privileges v…
Super
Mitigation only
MEDIUM 6.5
CVE-2014-1957
FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.
Fortiweb
after 5.0.2
HIGH 9.0
CVE-2013-6990
FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.
Fortiauthenticator
after 2.2
MEDIUM 5.0
CVE-2013-7063
The Invitation module 7.x-2.x for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via unspe…
Invitation
Mitigation only
MEDIUM 5.8
CVE-2013-7065
The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions and post to arbitrary groups v…
Organic Groups
Patch available
HIGH 7.5
CVE-2014-0112EPSS 98%
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "mani…
Struts
2.3.16.2+
HIGH 7.5
CVE-2014-0113EPSS 78%
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method…
Struts
2.3.16.2+
HIGH 9.0
CVE-2014-0187
The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass secu…
Ubuntu Linux
Mitigation only
HIGH 7.5
CVE-2014-1217
Livetecs Timelive before 6.2.8 does not properly restrict access to systemsetting.aspx, which allows remote attackers to change configurations and ob…
Timeline
Mitigation only
MEDIUM 5.5
CVE-2014-2915
Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of s…
Xen
Mitigation only
MEDIUM 5.0
CVE-2012-3946
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an u…
iOS
after 15.3
MEDIUM 5.0
CVE-2014-0473
The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all…
Django
after 1.4.10
HIGH 10.0
CVE-2014-1314
WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox …
Mac Os X
after 10.9.2
MEDIUM 5.8
CVE-2014-0173
The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x…
Jetpack
Mitigation only
MEDIUM 5.5
CVE-2013-7195
PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request that specif…
Phpfox
Mitigation only
MEDIUM 5.5
CVE-2013-7196
static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a privat…
Phpfox
Mitigation only
MEDIUM 6.4
CVE-2014-0071
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int…
Openstack
Mitigation only
MEDIUM 5.0
CVE-2014-0053
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files…
Grails Resources
Mitigation only
MEDIUM 5.0
CVE-2014-2857
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to file…
Grails Resources
Mitigation only
HIGH 7.5
CVE-2014-2859
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.
Commonspot Content Server
after 7.0.1