Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2014-9521
Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows…
Infinitewp
after 2.4.3
HIGH 7.5
CVE-2014-2208
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) bef…
Hiphop Virtual Machine
after 2.4.1
HIGH 9.3
CVE-2014-6119
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…
Security Appscan
Mitigation only
MEDIUM 6.5
CVE-2014-9185
Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php v…
Morfy Cms
after 1.04
HIGH 9.3
CVE-2014-6261EPSS 20%
Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1…
Zenoss Core
after 5.0.0
HIGH 7.5
CVE-2014-7260
The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to execute arbitrary co…
I Httpd
Mitigation only
HIGH 10.0
CVE-2014-7192EPSS 13%
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer a…
Node.js
after 0.10.32
HIGH 9.3
CVE-2014-6361EPSS 13%
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 Gold and SP1, Excel 2013 RT Gold and SP1, and Office Compatibility Pack allow remote attackers t…
Excel
Mitigation only
HIGH 9.3
CVE-2014-6360EPSS 13%
Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack allow remote attackers to execute arbitrary code via a crafted Office documen…
Excel
Mitigation only
HIGH 9.3
CVE-2014-6356EPSS 12%
Array index error in Microsoft Word 2007 SP3, Word 2010 SP2, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via …
Office Compatibility Pack
Mitigation only
HIGH 10.0
CVE-2014-9158EPSS 10%
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …
Acrobat
Mitigation only
HIGH 10.0
CVE-2014-8461EPSS 9%
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …
Acrobat Reader
Mitigation only
HIGH 10.0
CVE-2014-8459EPSS 9%
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …
Acrobat
Mitigation only
HIGH 10.0
CVE-2014-8458EPSS 9%
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …
Acrobat Reader
Mitigation only
HIGH 10.0
CVE-2014-8456EPSS 9%
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …
Acrobat Reader
Mitigation only
HIGH 10.0
CVE-2014-8447EPSS 9%
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …
Acrobat
Mitigation only
HIGH 10.0
CVE-2014-8445EPSS 9%
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …
Acrobat
Mitigation only
HIGH 7.5
CVE-2014-8485EPSS 7%
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and pos…
Fedora
after 2.24
HIGH 7.5
CVE-2014-9280
The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP code…
Mantisbt
after 1.2.17
MEDIUM 6.8
CVE-2014-9266
The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attackers to execute arbitrary code…
Smart Viewer
Mitigation only
HIGH 10.0
CVE-2014-8877EPSS 14%
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress…
Cm Download Manager
after 2.0.3
MEDIUM 6.0
CVE-2014-8791EPSS 15%
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object i…
Tuleap
No fix yet
MEDIUM 6.9
CVE-2014-3065
Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 b…
Java
Mitigation only
HIGH 10.0
CVE-2014-8551EPSS 5%
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through S…
Simatic Pcs 7
Mitigation only
MEDIUM 6.5
CVE-2014-9001
reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1…
Incredible Pbx 11
No fix yet
MEDIUM 6.5
CVE-2014-8998EPSS 36%
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.p…
X7 Chat
No fix yet
HIGH 7.5
CVE-2014-8997EPSS 9%
Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 allows remote attackers to exec…
Digi Online Examination System
No fix yet
MEDIUM 6.0
CVE-2014-8949EPSS 8%
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metach…
Imember360
No fix yet
MEDIUM 6.5
CVE-2014-0233
Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters…
Openshift
No fix yet
MEDIUM 6.0
CVE-2012-2301
The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute a…
Ubercart
Patch available