Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2015-5841
The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, whic…
Mac Os X
after 10.10.5
CRITICAL 9.8
CVE-2015-3253EPSS 41%
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause…
Groovy
Patch available
HIGH 7.1
CVE-2015-1762EPSS 10%
Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not preven…
Sql Server
Mitigation only
HIGH 7.5
CVE-2015-3205EPSS 11%
libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, related to "free" function ca…
Libmimedir
No fix yet
HIGH 7.5
CVE-2015-3200EPSS 10%
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon cha…
Lighttpd
after 15.07
MEDIUM 5.0
CVE-2015-2704
realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf via a newline character in an LDAP response.
Realmd
after 15.2
MEDIUM 6.0
CVE-2015-3013
ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbit…
Owncloud Server
5.0.19 / 6.0.7+
HIGH 7.5
CVE-2015-1592EPSS 75%
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw funct…
Debian Linux
5.2.12 / 6.0.7+
MEDIUM 6.8
CVE-2015-0931
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to e…
Ektron Content Management System
Mitigation only
HIGH 7.5
CVE-2015-1169
Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as …
Central Authentication Service
after 3.5.2
MEDIUM 5.0
CVE-2014-7287
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger un…
Encryption Management Server
after 3.3.2
HIGH 7.6
CVE-2013-6435EPSS 8%
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the con…
Debian Linux
after 4.11.1
HIGH 10.0
CVE-2014-8423EPSS 62%
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown …
Vap2500 Firmware
after 08.41
CRITICAL 9.8
CVE-2013-2251 KEVEPSS 100%
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi…
Archiva
1.3.8+
MEDIUM 6.4
CVE-2012-4196
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before …
Firefox
2.13.2 / 10.0.10+
MEDIUM 6.8
CVE-2011-2855
Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a den…
Chrome
5.1 / 5.1.4+
MEDIUM 6.8
CVE-2011-2805
Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vecto…
Chrome
5.0 / 5.1.1+
HIGH 7.5
CVE-2009-1781
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into p…
Php Recommend
after 1.3
HIGH 7.5
CVE-2005-3750EPSS 6%
Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (backticks) in a URL that anot…
Opera Browser
8.51+
HIGH 7.5
CVE-2004-1157
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a t…
Opera Browser
after 7.54
MEDIUM 5.0
CVE-2004-2570
Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from…
Opera Browser
7.54+