Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2014-9422
The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.1…
Kerberos 5
Patch available
HIGH 8.3
CVE-2014-8757
LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.
On Screen Phone
after 4.3.009
HIGH 8.3
CVE-2015-0008EPSS 29%
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows…
Windows 7
Patch available
HIGH 10.0
CVE-2015-0929
time.htm in the web interface on SerVision HVG Video Gateway devices with firmware before 2.2.26a78 allows remote attackers to bypass authentication …
Hvg Video Gateway Firmware
after 2.2.26a77
MEDIUM 6.8
CVE-2015-0926
Labtech before 100.237 on Linux uses world-writable permissions for root-executed scripts, which allows local users to gain privileges by modifying a…
Labtech
after 55.170
HIGH 7.8
CVE-2014-9197
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access con…
Etg3000 Factorycast Hmi Gateway Firmware
Patch available
HIGH 7.5
CVE-2014-9572
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain dat…
Mantisbt
after 1.2.18
HIGH 7.2
CVE-2014-1949
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass …
Ubuntu
after 3.10.9
MEDIUM 5.0
CVE-2014-1449
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that…
Maxthon Cloud Browser
after 4.1.5.2000
MEDIUM 5.8
CVE-2014-7193
The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which al…
Hapi Crumb
after 2.2.0
HIGH 7.5
CVE-2014-5208EPSS 23%
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, a…
Exaopc
after 3.71.10
MEDIUM 5.0
CVE-2014-6078
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a …
Security Access Manager For Mobile
Mitigation only
MEDIUM 5.0
CVE-2014-9388
bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter.
Mantisbt
after 1.2.17
MEDIUM 6.8
CVE-2014-1589
Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypas…
Firefox
after 33.0
MEDIUM 5.4
CVE-2014-8680EPSS 9%
The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via…
Bind
Mitigation only
MEDIUM 5.0
CVE-2014-6319EPSS 10%
Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requ…
Exchange Server
Mitigation only
MEDIUM 5.0
CVE-2014-9117
MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA prot…
Mantisbt
after 1.2.17
HIGH 7.5
CVE-2014-9151
The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote …
Services
Mitigation only
HIGH 9.0
CVE-2014-6627
Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a differe…
Clearpass
after 6.3.4
HIGH 10.0
CVE-2014-6626
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows …
Clearpass
after 6.3.4
HIGH 9.0
CVE-2014-6625
The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecifi…
Clearpass
after 6.3.4
MEDIUM 5.0
CVE-2014-7905
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, whic…
Chrome
after 39.0.2171.45
HIGH 8.1
CVE-2014-3120 KEVEPSS 89%
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions …
Elasticsearch
1.2.0+
MEDIUM 5.5
CVE-2014-2365
Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.
Advantech Webaccess
after 7.1
MEDIUM 5.0
CVE-2013-7293
The ASUS WL-330NUL router has a configuration process that relies on accessing the 192.168.1.1 IP address, but the documentation advises users to ins…
Wl 330nul
Mitigation only
HIGH 10.0
CVE-2013-4316EPSS 8%
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Struts
after 3.0.4
MEDIUM 5.0
CVE-2013-2175
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows…
Debian Linux
Patch available
MEDIUM 6.4
CVE-2013-4213
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attacker…
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2012-6435EPSS 33%
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…
Controllogix Controllers
after 1400
HIGH 8.5
CVE-2012-6439EPSS 23%
When an affected
product receives a valid CIP message from an unauthorized or unintended
source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or…
Controllogix Controllers
after 1400