Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2018-1319
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted…
Allura
after 1.8.0
CRITICAL 9.8
CVE-2018-6220EPSS 10%
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to…
Email Encryption Gateway
Patch available
HIGH 8.1
CVE-2018-1000130EPSS 73%
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on th…
Webarchive Agent
Mitigation only
CRITICAL 9.8
CVE-2015-5377EPSS 14%
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI app…
Elasticsearch
1.6.1+
MEDIUM 5.9
CVE-2017-10963
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker c…
Knox Enterprise Mobility Management
Mitigation only
HIGH 8.8
CVE-2017-5799EPSS 15%
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (…
Opencall Media Platform
3.4.2 / 4.4.7+
HIGH 7.5
CVE-2018-7032
webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attack…
Myrepos
after 1.20171231
MEDIUM 6.1
CVE-2018-6603
Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript cod…
Webpam Proe
Mitigation only
CRITICAL 9.8
CVE-2018-6289EPSS 7%
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
Secure Mail Gateway
No fix yet
HIGH 7.5
CVE-2018-6519
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for…
Debian Linux
1.10.4 / 2.3.5+
HIGH 7.5
CVE-2017-14523EPSS 8%
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that e…
Wondercms
No fix yet
MEDIUM 5.5
CVE-2017-18049
In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and …
Silverstripe
after 3.6.2
CRITICAL 9.8
CVE-2017-14094EPSS 19%
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command executio…
Smart Protection Server
after 3.2
HIGH 7.8
CVE-2014-7952
The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveragi…
Android
No fix yet
CRITICAL 9.8
CVE-2017-15714
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code …
Ofbiz
No fix yet
CRITICAL 9.8
CVE-2017-1000493
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
Rocket.chat
after 0.59
CRITICAL 9.8
CVE-2017-1000453
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execu…
Cms Made Simple
2.2+
HIGH 7.8
CVE-2017-1000454
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and l…
Cms Made Simple
2.2+
MEDIUM 5.5
CVE-2016-3695
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause …
Linux Kernel
Patch available
HIGH 8.8
CVE-2017-15313
Huawei SmartCare V200R003C10 has a CSV injection vulnerability. An remote authenticated attacker could inject malicious CSV expression to the affecte…
Smartcare
Mitigation only
MEDIUM 6.5
CVE-2017-16766
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows loc…
Diskstation Manager
6.0.3-8754-6 / 6.1.4-15217+
CRITICAL 9.8
CVE-2017-17790EPSS 6%
The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by…
Ruby
after 2.4.2
HIGH 8.8
CVE-2017-17531
gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow…
Global
Mitigation only
HIGH 8.8
CVE-2017-17532
examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable,…
Kiwi
Mitigation only
HIGH 8.8
CVE-2017-17533
default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow re…
Tkabber
Mitigation only
HIGH 8.8
CVE-2017-17534
uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow…
Mensis
Mitigation only
HIGH 8.8
CVE-2017-17535
lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which mig…
Gjots2
Mitigation only
HIGH 8.8
CVE-2017-17511
KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attac…
Debian Linux
Mitigation only
HIGH 8.8
CVE-2017-17513
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow rem…
Tex Live
after 20170524
HIGH 8.8
CVE-2017-17514
boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote …
Debian Linux
Mitigation only