Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2015-3971
The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to read or writ…
Umg 508
Patch available
HIGH 8.8
CVE-2015-6984
libarchive in Apple OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that conducts an unspecified symlink attack.
Mac Os X
after 10.11.0
MEDIUM 5.3
CVE-2015-4902 KEVEPSS 13%
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployme…
Satellite
Patch available
MEDIUM 6.8
CVE-2015-7184
The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user cre…
Firefox
after 41.0.1
HIGH 7.5
CVE-2015-7369
The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows re…
Revive Adserver
after 3.2.1
HIGH 7.5
CVE-2015-7367
Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) de…
Revive Adserver
after 3.2.1
HIGH 7.5
CVE-2015-1304
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, whi…
Chrome
after 45.0.2454.93
MEDIUM 6.8
CVE-2015-5913
Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents…
Mac Os X
after 10.10.5
HIGH 7.2
CVE-2015-3860
packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters i…
Android
after 5.1
MEDIUM 6.8
CVE-2015-6928
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, whi…
Cubecart
Patch available
HIGH 7.2
CVE-2015-5882
The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access t…
Watchos
after 10.10.5
HIGH 7.5
CVE-2015-1173
Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules,…
Teta Web
after 22.62.3.4
MEDIUM 5.5
CVE-2015-4299
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default …
Unified Web And E Mail Interaction Manager
Mitigation only
MEDIUM 6.5
CVE-2015-4298
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to rea…
Unified Web And E Mail Interaction Manager
Mitigation only
MEDIUM 6.4
CVE-2015-4302
The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in…
Firesight System Software
Mitigation only
MEDIUM 5.0
CVE-2015-5512
The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argum…
Me Aliases
Patch available
HIGH 7.5
CVE-2015-5502
The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not no…
Storage Api
Patch available
MEDIUM 6.0
CVE-2015-0277
The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specif…
Picketlink
after 2.6.0
MEDIUM 5.0
CVE-2015-5746
AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages sy…
Iphone Os
after 8.4
HIGH 7.2
CVE-2015-3806
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executa…
Iphone Os
after 10.10.4
MEDIUM 5.0
CVE-2015-3155
Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to captu…
Foreman
after 1.8.0
HIGH 7.2
CVE-2015-3213
The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch…
Clutter
after 1.16.0
MEDIUM 5.0
CVE-2015-2847
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended…
Tuxedo Touch
after 5.1.13.0_va
MEDIUM 6.4
CVE-2015-4271
Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request pa…
Telepresence Tc Software
Mitigation only
HIGH 8.5
CVE-2015-1763EPSS 12%
Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 does not prevent use of uninitialized memory in certain attemp…
Sql Server
Mitigation only
MEDIUM 6.5
CVE-2015-1761EPSS 19%
Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, …
Sql Server
Mitigation only
HIGH 7.2
CVE-2015-3007
The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not …
Junos
Mitigation only
MEDIUM 6.0
CVE-2015-1936
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disab…
Websphere Application Server
Patch available
MEDIUM 6.8
CVE-2015-1927
The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false …
Websphere Application Server
Patch available
HIGH 9.0
CVE-2015-1961
The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.…
Business Process Manager
Patch available