Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2017-3204
The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4…
Crypto
after 2017-03-17
MEDIUM 6.8
CVE-2016-7585
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It…
Mac Os X
after 10.12.3
MEDIUM 5.5
CVE-2015-8234
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, wh…
Glance
Patch available
HIGH 8.8
CVE-2015-8989
Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earli…
Vulnerability Manager
after 7.5.8
MEDIUM 6.7
CVE-2015-4056
The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users …
Vce Vision Intelligent Operations
after 2.6.4
MEDIUM 5.3
CVE-2016-9346
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. Configuration data are st…
Miineport E1 Firmware
after 1.7
MEDIUM 5.9
CVE-2016-6329EPSS 6%
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duratio…
Openvpn
after 2.3.14
HIGH 7.8
CVE-2016-10136
An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in…
Adups Fota
Mitigation only
HIGH 7.8
CVE-2016-10137
An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in…
Adups Fota
Mitigation only
HIGH 7.8
CVE-2016-10138
An issue was discovered on BLU Advance 5.0 and BLU R1 HD devices with Shanghai Adups software. The com.adups.fota.sysoper app is installed as a syste…
Adups Fota
Mitigation only
HIGH 7.8
CVE-2016-10139
An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The two package names involved in the exfiltration are com.adups.fota and …
Adups Fota
Mitigation only
MEDIUM 5.3
CVE-2016-10099
Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of archives), potentially allowin…
Borg
after 1.0.8
HIGH 7.5
CVE-2016-7270EPSS 20%
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the A…
.net Framework
Mitigation only
MEDIUM 5.9
CVE-2016-1411
A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), a…
Content Security Management Appliance
Mitigation only
MEDIUM 5.5
CVE-2016-7439
The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging ca…
Wolfssl
after 3.9.8
MEDIUM 5.5
CVE-2016-7438
The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging ca…
Wolfssl
after 3.9.8
MEDIUM 5.3
CVE-2016-9847
An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runti…
phpMyAdmin
Patch available
HIGH 8.1
CVE-2016-6606
An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This ca…
phpMyAdmin
Patch available
MEDIUM 6.2
CVE-2016-8889
In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information i…
Bitcoin Knots
Patch available
HIGH 7.5
CVE-2016-5084
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive informa…
Onetouch Ping Firmware
Mitigation only
MEDIUM 5.4
CVE-2016-6550
The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to…
The U
after 1.5.4
HIGH 7.5
CVE-2016-5957
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection me…
Security Privileged Identity Manager Virtual Appliance
after 2.0.2
MEDIUM 6.8
CVE-2016-4763
WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HT…
Safari
after 12.4.3
HIGH 7.5
CVE-2016-4754
ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mech…
Os X Server
after 5.1
HIGH 8.6
CVE-2016-0904
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers…
Avamar Server
after 7.3.0
CRITICAL 9.8
CVE-2016-0897
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for…
Operations Manager
after 1.6.16
HIGH 7.5
CVE-2016-6899
The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with sof…
Rh5885 V3 Server Firmware
Mitigation only
HIGH 7.5
CVE-2016-6838
Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers…
Rh1288 V3 Server Firmware
Mitigation only
MEDIUM 5.3
CVE-2016-5430
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which m…
Jose Php
2.2.1+
HIGH 7.5
CVE-2016-5419EPSS 16%
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass…
Debian Linux
after 7.50.0