Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2014-0558EPSS 5%
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.…
Flash Player
after 15.0.0.252
HIGH 7.5
CVE-2014-5297
The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP obj…
X2engine
Patch available
HIGH 7.5
CVE-2014-7226EPSS 9%
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file wit…
Http File Server
after 2.3c
MEDIUM 6.8
CVE-2014-7296
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated user…
Spagobi
Mitigation only
HIGH 10.0
CVE-2014-7205EPSS 79%
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for …
Bassmaster
1.5.2+
HIGH 10.0
CVE-2014-3188EPSS 6%
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remot…
Chrome Os
after 38.0.2125.77
HIGH 10.0
CVE-2014-7235EPSS 43%
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.…
Freepbx
after 2.9.0.8
HIGH 10.0
CVE-2014-6433
gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action.
Gopro Hero Firmware
Mitigation only
MEDIUM 5.5
CVE-2014-3399
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information dur…
Adaptive Security Appliance Software
after 9.2
CRITICAL 9.8
CVE-2014-6287 KEVEPSS 99%
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to exe…
Http File Server
2.3c+
HIGH 7.5
CVE-2014-2044EPSS 12%
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass in…
Owncloud
after 4.5.13
HIGH 7.5
CVE-2014-4043
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which …
Glibc
after 2.19
HIGH 7.5
CVE-2014-6389EPSS 9%
backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter.
Phpcompta\/noalyss
after 6.7.1
HIGH 7.5
CVE-2013-1436EPSS 9%
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which …
Xmonad Contrab
after 0.11.1
HIGH 7.5
CVE-2014-6298
Unrestricted file upload vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to execute arbitrary code by uploadin…
Mm Forum
after 1.9.2
HIGH 7.5
CVE-2014-3947
Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute ar…
Powermail
after 1.6.10
HIGH 8.5
CVE-2012-5493
gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execu…
Plone
after 4.2.2
MEDIUM 5.0
CVE-2012-5495
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back."
Plone
after 4.2.2
MEDIUM 6.8
CVE-2012-5485
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to t…
Plone
after 4.2.2
MEDIUM 5.0
CVE-2012-5488
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObje…
Plone
after 4.2.2
HIGH 7.5
CVE-2014-6446EPSS 46%
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload a…
Infusionsoft Gravity Forms
Patch available
MEDIUM 6.5
CVE-2014-5324
Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbi…
N Media File Uploader
after 3.3
HIGH 9.3
CVE-2006-1318EPSS 15%
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, wh…
Office
Mitigation only
MEDIUM 6.8
CVE-2013-4444EPSS 14%
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JM…
Tomcat
after 7.0.39
HIGH 7.5
CVE-2014-2223EPSS 10%
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbi…
Plogger
after 1.0
HIGH 7.5
CVE-2014-5519EPSS 65%
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[conten…
Phpwiki
No fix yet
HIGH 7.6
CVE-2014-2378
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which…
Trafficdot
after 2.10.2
HIGH 7.5
CVE-2014-0485
S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized obje…
S3ql
after 1.18.1
HIGH 9.3
CVE-2014-5340EPSS 6%
The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execu…
Check Mk
after 1.2.4
HIGH 10.0
CVE-2014-3176EPSS 10%
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attac…
Chrome
after 37.0.2062.93