Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2015-7461
XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cau…
Connections
after 3.0.1.1
MEDIUM 5.3
CVE-2016-8782
Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacke…
Cloudengine 12800 Firmware
Mitigation only
HIGH 7.5
CVE-2004-2779
id3_utf16_deserialize() in utf16.c in libid3tag through 0.15.1b misparses ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an end…
Libid3tag
after 0.15.1b
MEDIUM 5.5
CVE-2015-9252
An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, relat…
Qpdf
7.0.0+
MEDIUM 5.5
CVE-2014-8171
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes w…
Linux Kernel
Mitigation only
HIGH 8.6
CVE-2018-0137
A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to cause a denial of service (Do…
Prime Network
Mitigation only
HIGH 7.4
CVE-2018-0102
A vulnerability in the Pong tool of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, r…
Nx Os
Mitigation only
MEDIUM 6.7
CVE-2018-0088
A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow a…
Industrial Ethernet 4010 Series Firmware
Mitigation only
MEDIUM 5.3
CVE-2017-12355
A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthen…
Ios Xr
Mitigation only
MEDIUM 6.5
CVE-2017-12362
A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resultin…
Meeting Server
2.2.2+
MEDIUM 5.8
CVE-2017-12311
A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco Meeting Server…
Meeting Server
Mitigation only
HIGH 7.5
CVE-2017-12318
A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device …
Rf Gateway 1 Firmware
Mitigation only
HIGH 7.5
CVE-2012-0881EPSS 17%
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML servi…
Xerces2 Java
after 2.11.0
HIGH 7.5
CVE-2016-4921
By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the i…
Junos
Mitigation only
HIGH 8.6
CVE-2017-12245
A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause …
Secure Firewall Management Center
Mitigation only
HIGH 8.6
CVE-2017-12246EPSS 7%
A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthe…
Adaptive Security Appliance Software
Mitigation only
MEDIUM 6.5
CVE-2017-12256
A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attack…
Wide Area Application Services
Mitigation only
MEDIUM 6.5
CVE-2017-12222
A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch…
Ios Xe
Mitigation only
HIGH 7.5
CVE-2017-12231 KEVEPSS 7%
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticate…
iOS
after 15.6
MEDIUM 6.5
CVE-2017-12232 KEV
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through…
iOS
after 15.6
HIGH 7.5
CVE-2017-12237 KEVEPSS 7%
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an…
iOS
after 16.5
MEDIUM 6.5
CVE-2017-12238 KEV
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an …
iOS
after 15.4
MEDIUM 5.9
CVE-2014-9686
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial…
Googlemaps
after 3.2
HIGH 7.5
CVE-2017-12219
A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticat…
Spa 301 Firmware
Mitigation only
MEDIUM 5.3
CVE-2017-12250
A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an…
Wide Area Application Services
Mitigation only
MEDIUM 6.5
CVE-2015-2927
node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
Node.js
after 1.0.5
MEDIUM 5.3
CVE-2017-12211
A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remot…
iOS
Mitigation only
HIGH 7.5
CVE-2017-6627 KEVEPSS 6%
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote atta…
iOS
Mitigation only
HIGH 7.5
CVE-2017-6631
A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an unauthent…
Yesmax Hd Firmware
Mitigation only
HIGH 7.5
CVE-2017-6780
A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to cause…
Connected Grid Network Management System
after 3.2.0-182