Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.0
CVE-2014-0686
Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file…
Unified Communications Manager
after 9.1
MEDIUM 5.0
CVE-2013-7301
Cantata before 1.2.2 does not restrict access to files in the play queue, which allows remote attackers to obtain sensitive information by reading th…
Cantata
after 1.2.1
MEDIUM 5.5
CVE-2014-0833
The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which a…
Financial Transaction Manager
Mitigation only
MEDIUM 5.0
CVE-2013-6727
The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote att…
Sametime
Mitigation only
MEDIUM 6.5
CVE-2013-2747
The password reset feature in Courion Access Risk Management Suite Version 8 Update 9 allows remote authenticated users to bypass intended Internet E…
Access Risk Management Suite
Mitigation only
HIGH 7.5
CVE-2013-2974
The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass aut…
Tivoli Application Dependency Discovery Manager
Mitigation only
HIGH 7.2
CVE-2013-7135
The Proc::Daemon module 0.14 for Perl uses world-writable permissions for a file that stores a process ID, which allows local users to have an unspec…
Proc\
Mitigation only
HIGH 8.3
CVE-2014-1666
The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix …
Xen
Patch available
MEDIUM 5.0
CVE-2014-1626
XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other pro…
Marc Xml
after 1.0.1
MEDIUM 5.0
CVE-2013-7247
cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover…
Ts 550 Evo Firmware
No fix yet
MEDIUM 5.5
CVE-2014-0678
The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack…
Secure Access Control System
Mitigation only
MEDIUM 5.2
CVE-2013-6457
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap…
Libvirt
after 1.2.0
MEDIUM 6.8
CVE-2013-7315EPSS 5%
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactor…
Spring Framework
after 3.2.3
MEDIUM 6.8
CVE-2013-4152EPSS 26%
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allow…
Spring Framework
after 3.2.3
MEDIUM 5.0
CVE-2013-6448
The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote …
Jboss Seam 2 Framework
after 2.3.1
MEDIUM 6.8
CVE-2014-0676
Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.
Nx Os
Mitigation only
MEDIUM 5.0
CVE-2014-0669
The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attacker…
Asr 5000 Series Software
Mitigation only
MEDIUM 6.8
CVE-2013-0339
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExt…
Ubuntu Linux
after 2.9.1
MEDIUM 5.5
CVE-2013-2104
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authen…
Python Keystoneclient
after 0.2.3
MEDIUM 5.8
CVE-2013-4200
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs star…
Plone
Patch available
MEDIUM 5.8
CVE-2010-5293
wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers…
WordPress
after 3.0.1
MEDIUM 6.4
CVE-2012-6634
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restr…
WordPress
after 3.3.2
MEDIUM 5.5
CVE-2014-0009
course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the…
Moodle
after 2.2.11
HIGH 10.0
CVE-2014-0648EPSS 6%
The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements,…
Secure Access Control System
after 5.4.0.46.6
HIGH 9.0
CVE-2014-0649
The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remot…
Secure Access Control System
after 5.4.0.46.6
MEDIUM 6.3
CVE-2014-0667
The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated…
Secure Access Control System
Mitigation only
HIGH 10.0
CVE-2014-0492EPSS 6%
Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR bef…
Flash Player
4.0.0.1390 / 11.2.202.335+
HIGH 10.0
CVE-2014-0491EPSS 7%
Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR bef…
Flash Player
4.0.0.1390 / 11.2.202.335+
MEDIUM 6.4
CVE-2013-2826
WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console ra…
Kingalarm\&event
after 3.1
HIGH 7.2
CVE-2014-0615
Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 befor…
Junos
Mitigation only