Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2014-0512
Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own…
Acrobat Reader
Mitigation only
MEDIUM 5.8
CVE-2014-0125
repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, w…
Moodle
after 2.3.11
MEDIUM 5.0
CVE-2014-2276
The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not properly restrict additions to th…
Connectrix Manager
after 12.1.2
HIGH 7.5
CVE-2014-0002EPSS 33%
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other uns…
Camel
after 2.11.3
HIGH 7.5
CVE-2014-0003EPSS 7%
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbit…
Camel
after 2.11.3
HIGH 7.5
CVE-2011-5275
The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for …
Domain Technologie Control
after 0.32.11
HIGH 8.5
CVE-2014-2119
The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1…
Ironport Asyncos
after 7.9.1-039
MEDIUM 5.8
CVE-2014-1501
Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving…
Firefox
after 27.0.1
HIGH 7.2
CVE-2014-2533
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a comm…
Qnx Neutrino Rtos
No fix yet
MEDIUM 6.5
CVE-2013-2048
ownCloud before 5.0.6 does not properly check permissions, which allows remote authenticated users to execute arbitrary API commands via unspecified …
Owncloud
after 5.0.5
MEDIUM 5.0
CVE-2014-2049
The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified v…
Owncloud Server
after 5.0.14
MEDIUM 5.0
CVE-2014-1276
IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that acce…
Iphone Os
after 7.0.6
MEDIUM 5.8
CVE-2014-1282
The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requireme…
Tvos
after 7.0.6
MEDIUM 5.8
CVE-2014-1285
Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveragi…
Iphone Os
after 7.0.6
MEDIUM 5.0
CVE-2014-2265
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omittin…
Contact Form 7
after 3.7.1
HIGH 8.8
CVE-2013-5133
Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via c…
Iphone Os
after 7.0.6
MEDIUM 5.8
CVE-2013-6442
The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgr…
Samba
Mitigation only
MEDIUM 5.0
CVE-2013-6835EPSS 7%
TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remot…
Iphone Os
after 7.0.6
HIGH 7.2
CVE-2014-0300
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2…
Windows 7
Patch available
MEDIUM 5.8
CVE-2013-4191
zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in…
Plone
Patch available
MEDIUM 5.0
CVE-2013-4196
The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restric…
Plone
Patch available
HIGH 10.0
CVE-2014-2321EPSS 59%
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by …
F460
Mitigation only
MEDIUM 6.5
CVE-2014-0899
ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated …
Aix
Mitigation only
MEDIUM 5.0
CVE-2013-4971
Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive …
Puppet Enterprise
after 3.1.1
MEDIUM 5.8
CVE-2014-1959
lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attack…
Gnutls
after 3.1.20
MEDIUM 5.8
CVE-2009-5138
GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which …
Gnutls
after 2.7.5
HIGH 8.5
CVE-2014-0629
EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 does not properly handle the interaction between the dm_world group and the dm…
Documentum Taskspace
Mitigation only
MEDIUM 5.8
CVE-2013-6666
The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not veri…
Chrome
after 33.0.1750.144
MEDIUM 6.8
CVE-2012-6636EPSS 41%
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary me…
Android Api
after 16.0
HIGH 7.5
CVE-2014-1881EPSS 11%
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev…
Cordova
after 3.3.0