Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2016-7110
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a dif…
Uma
Mitigation only
CRITICAL 9.8
CVE-2016-7109
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a dif…
Uma
Mitigation only
CRITICAL 9.8
CVE-2015-5721
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data…
Misp
after 2.3.89
HIGH 7.5
CVE-2016-2119
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a clie…
Samba
4.2.14 / 4.3.11+
CRITICAL 9.8
CVE-2016-5734EPSS 81%
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_repla…
phpMyAdmin
Patch available
MEDIUM 6.5
CVE-2016-1413
The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted cod…
Secure Firewall Management Center
Mitigation only
CRITICAL 9.8
CVE-2016-3154
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote att…
Spip
Patch available
CRITICAL 9.8
CVE-2016-3153
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related …
Debian Linux
Patch available
MEDIUM 5.3
CVE-2015-5970
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection atta…
Zenworks Configuration Management
Mitigation only
CRITICAL 9.8
CVE-2016-1986
HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to t…
Continuous Delivery Automation
Patch available
HIGH 7.5
CVE-2016-0033EPSS 18%
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote at…
.net Framework
Mitigation only
CRITICAL 10.0
CVE-2016-1985EPSS 7%
HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to …
Operations Manager
Patch available
CRITICAL 9.0
CVE-2015-8761
The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value se…
Values
Patch available
MEDIUM 6.0
CVE-2015-5242
OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authe…
Gluster Storage
Mitigation only
HIGH 7.5
CVE-2015-7905
Unitronics VisiLogic OPLC IDE before 9.8.02 allows remote attackers to execute unspecified code via unknown vectors.
Visilogic Oplc Ide
after 9.8.0.00
HIGH 8.5
CVE-2015-6555
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary Java code by connecting to the cons…
Endpoint Protection Manager
after 12.1
MEDIUM 6.5
CVE-2015-7729
Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenti…
Hana
No fix yet
HIGH 8.5
CVE-2015-5647
The RSS Reader component in Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via…
Garoon
Mitigation only
HIGH 8.5
CVE-2015-5646
Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka Cy…
Garoon
Patch available
MEDIUM 6.8
CVE-2015-5644
The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code vi…
Matchasns
after 1.3.6
MEDIUM 6.8
CVE-2015-5643
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP cod…
Matchasns
after 1.3.6
HIGH 7.5
CVE-2015-5687
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code …
Anchor Cms
Patch available
HIGH 7.5
CVE-2015-7381
Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to exe…
Refbase
after 0.9.6
MEDIUM 6.5
CVE-2015-5603EPSS 59%
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors…
Hipchat
after 6.29.2
HIGH 7.9
CVE-2015-5693
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute…
Web Gateway
after 5.2.2
HIGH 9.0
CVE-2014-8778
Checkmarx CxSAST (formerly CxSuite) before 7.1.8 allows remote authenticated users to bypass the CxQL sandbox protection mechanism and execute arbitr…
Cxsast
after 7.1.6
HIGH 8.5
CVE-2014-2331
Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. …
Check Mk
after 1.2.3
MEDIUM 6.8
CVE-2015-2308
Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6…
Symfony
Patch available
HIGH 7.5
CVE-2015-4726
PHP remote file inclusion vulnerability in ajax/myajaxphp.php in AudioShare 2.0.2 allows remote attackers to execute arbitrary PHP code via a URL in …
Audioshare
No fix yet
MEDIUM 6.5
CVE-2015-4338
Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the…
Xcloner
No fix yet