Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2014-3177
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attac…
Chrome
after 37.0.2062.93
HIGH 7.5
CVE-2014-5261EPSS 11%
The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharac…
Cacti
after 0.8.8b
MEDIUM 6.5
CVE-2014-4767
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, wh…
Websphere Application Server
Mitigation only
HIGH 10.0
CVE-2014-5158
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to exe…
Open Source Security Information Management
after 4.5
HIGH 10.0
CVE-2014-5210EPSS 15%
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (…
Open Source Security Information Management
after 4.6.1
MEDIUM 6.5
CVE-2014-5194
Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/…
Sphider
No fix yet
HIGH 9.0
CVE-2013-7394
The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOT…
Splunk
after 5.0.4
MEDIUM 6.8
CVE-2014-3429
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary c…
Opensuse
Patch available
MEDIUM 6.8
CVE-2014-0479
reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vectors related to compare_versio…
Reportbug
after 6.5.0
HIGH 7.9
CVE-2014-3560EPSS 56%
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspec…
Ubuntu Linux
Mitigation only
MEDIUM 6.5
CVE-2014-5090
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location …
Status2k
No fix yet
MEDIUM 6.0
CVE-2014-3545
Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to execu…
Moodle
Patch available
HIGH 7.5
CVE-2014-3541
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remot…
Moodle
Patch available
HIGH 7.5
CVE-2014-5112EPSS 9%
maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.
Trixbox
No fix yet
HIGH 9.3
CVE-2014-1556
Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted W…
Firefox
after 30.0
HIGH 9.3
CVE-2014-1557
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does no…
Firefox
after 30.0
MEDIUM 6.8
CVE-2014-3518
jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Po…
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2014-1999
The auto-format feature in the Request_Curl class in FuelPHP 1.1 through 1.7.1 allows remote attackers to execute arbitrary code via a crafted respon…
Fuelphp
Mitigation only
MEDIUM 6.8
CVE-2014-4663EPSS 10%
TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metachara…
Timthumb
No fix yet
HIGH 9.3
CVE-2014-1824EPSS 19%
Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a…
Windows 7
Patch available
MEDIUM 6.8
CVE-2014-0248
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Ente…
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2014-0602
Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in NetIQ Security Manager through 6.5.4 allows remote a…
Security Manager
after 6.5.4
HIGH 7.5
CVE-2014-4672
The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.
Yiiframework
Mitigation only
MEDIUM 6.0
CVE-2013-6309
IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct…
Marketing Platform
Mitigation only
MEDIUM 5.0
CVE-2014-3011
IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors.
Openpages Grc Platform
No fix yet
HIGH 10.0
CVE-2014-3496EPSS 5%
cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metach…
Openshift
Patch available
HIGH 10.0
CVE-2014-4151EPSS 7%
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a craft…
Open Source Security Information Management
after 4.7.0
HIGH 10.0
CVE-2014-4152EPSS 6%
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, rel…
Open Source Security Information Management
after 4.7.0
HIGH 10.0
CVE-2014-3804EPSS 72%
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_in…
Open Source Security Information Management
after 4.6.1
HIGH 10.0
CVE-2014-3805EPSS 13%
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2)…
Open Source Security Information Management
after 4.6.1