Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2017-1000052
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypa…
Plug
1.0.4 / 1.1.7+
HIGH 7.5
CVE-2017-7459
ntopng before 3.0 allows HTTP Response Splitting.
Ntopng
after 2.4
HIGH 8.8
CVE-2017-9133
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in…
Backhaul Radios
after 2.2.1
HIGH 8.8
CVE-2017-9135
An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, t…
Backhaul Radios
after 2.2.3
HIGH 8.8
CVE-2017-6031
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripti…
Atvise Scada
after 2.5.10
MEDIUM 6.5
CVE-2017-8458
Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://[email protected]/ is displayed without a clear UI indic…
Brave
Patch available
HIGH 8.8
CVE-2017-2140
Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to specially crafted directory.
Tablacus Explorer
after 17.3.30
HIGH 7.4
CVE-2017-3547
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported vers…
Peoplesoft Enterprise Peopletools
Patch available
CRITICAL 9.8
CVE-2016-1155
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or …
Android
Mitigation only
HIGH 7.5
CVE-2017-7703
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was …
Wireshark
Patch available
CRITICAL 9.8
CVE-2017-7239
Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of ser…
Ninka
after 1.3.0
CRITICAL 9.8
CVE-2015-7264
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.
Proxygen
after 0.32.0
HIGH 7.5
CVE-2015-8258EPSS 9%
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script …
Axis Communications Firmware
after 5.80.3
HIGH 8.8
CVE-2017-6971EPSS 16%
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, …
Ossim
after 5.3.6
HIGH 8.8
CVE-2017-5585
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based co…
Documentum Content Server
No fix yet
HIGH 7.5
CVE-2017-5630EPSS 13%
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which al…
Pear
No fix yet
HIGH 8.8
CVE-2015-2180
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in …
Webmail
after 1.1
CRITICAL 9.8
CVE-2016-4010EPSS 93%
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serializ…
Magento
after 2.0.5
MEDIUM 5.4
CVE-2016-5013
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
Moodle
after 2.7.14
CRITICAL 9.8
CVE-2016-10131
system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from f…
Codeigniter
after 3.1.2
MEDIUM 6.5
CVE-2016-6473
A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unauthenticated, adjacent attacker to cause a Layer 2…
iOS
Mitigation only
CRITICAL 9.9
CVE-2016-9832
PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbit…
Ace Advanced Business Application Programming
No fix yet
HIGH 8.8
CVE-2016-5685
Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.
Idrac7 Firmware
after 2.30.30.30
HIGH 8.8
CVE-2016-6754
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote a…
Android
after 6.0.1
HIGH 7.5
CVE-2016-7125EPSS 6%
ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows r…
PHP
after 5.6.24
MEDIUM 6.1
CVE-2016-5701
setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to condu…
phpMyAdmin
Patch available
HIGH 7.3
CVE-2015-8800
Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers …
Symantec Critical System Protection
Mitigation only
HIGH 8.2
CVE-2016-2204
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted…
Messaging Gateway
after 10.6.0
MEDIUM 6.5
CVE-2016-0881
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection…
Documentum Xcp
Mitigation only
MEDIUM 6.5
CVE-2015-7309EPSS 39%
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbit…
Bolt
after 2.2.0