Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.6
CVE-2016-8529
A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 a…
Lefthand
after 12.5
HIGH 8.8
CVE-2014-5279
The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for rem…
Boot2docker
after 1.2
MEDIUM 5.4
CVE-2016-0342
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify a…
Tririga Application Platform
3.3.2.6 / 3.4.2.3+
HIGH 7.5
CVE-2014-9504
The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via…
Open Atrium
7.x-2.26+
MEDIUM 6.5
CVE-2014-3519
The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, when using simfs, might allow …
Vzkernel
Patch available
CRITICAL 9.8
CVE-2016-6598EPSS 19%
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service cont…
Track It\!
after 11.4
MEDIUM 5.4
CVE-2017-9513
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence…
Activity Streams
6.3.0+
HIGH 7.5
CVE-2015-3888
Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL.
Sailfish Os
1.1.2.16+
HIGH 7.8
CVE-2017-15131
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting…
Enterprise Linux
0.15.5+
HIGH 7.5
CVE-2015-3302EPSS 22%
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attacker…
Thecartpress Ecommerce Shopping Cart
after 1.3.9
HIGH 7.5
CVE-2015-8008
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intende…
Fedora
1.25.3+
MEDIUM 6.5
CVE-2017-16766
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows loc…
Diskstation Manager
6.0.3-8754-6 / 6.1.4-15217+
HIGH 8.8
CVE-2017-5254EPSS 54%
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passw…
Epmp 1000 Firmware
after 3.5
MEDIUM 6.5
CVE-2017-15891
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calend…
Calendar
2.0.1-0242+
HIGH 7.8
CVE-2017-14031
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and wr…
Vtscada
after 11.3.03
HIGH 8.8
CVE-2017-12262
A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow a…
Application Policy Infrastructure Controller Enterprise Module
1.5+
CRITICAL 9.8
CVE-2015-9245
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from wh…
Openedge
Mitigation only
HIGH 8.8
CVE-2013-4246
libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories a…
Subversion
Patch available
CRITICAL 9.8
CVE-2014-3624
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request…
Traffic Server
Patch available
HIGH 7.5
CVE-2010-2232
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
Derby
Patch available
MEDIUM 6.5
CVE-2012-4379
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct c…
Mediawiki
after 1.18.4
HIGH 7.5
CVE-2012-4380
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an accoun…
Mediawiki
after 1.18.4
HIGH 7.2
CVE-2016-5714
Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protect…
Puppet Enterprise
after 1.7.0
HIGH 7.1
CVE-2014-2277
The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary file…
Perltidy
after 2012-07-01-1
HIGH 8.8
CVE-2014-9489
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "mast…
Gollum
after 4.0.0
CRITICAL 9.8
CVE-2014-9148EPSS 11%
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administ…
Fiyo Cms
after 2.0.1.8
MEDIUM 6.5
CVE-2016-10514
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that co…
Piwigo
after 2.8.2
MEDIUM 6.5
CVE-2017-8447
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a…
X Pack
Mitigation only
HIGH 8.8
CVE-2017-8448
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch…
X Pack
Mitigation only
HIGH 7.8
CVE-2015-1336
The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain pri…
Man Db
after 2.7.6.1