Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 9.3
CVE-2013-2135EPSS 14%
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" an…
Struts
2.3.14.3+
HIGH 10.0
CVE-2013-1777EPSS 10%
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and o…
Geronimo
Patch available
HIGH 9.3
CVE-2013-1965EPSS 94%
Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a cr…
Struts
2.3.14.1+
HIGH 9.3
CVE-2013-1966EPSS 74%
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …
Struts
2.3.14.1+
HIGH 8.1
CVE-2013-2115EPSS 75%
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …
Struts
after 2.3.14.1
HIGH 9.3
CVE-2013-3132EPSS 22%
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, wh…
.net Framework
Mitigation only
HIGH 9.3
CVE-2013-3133EPSS 21%
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote …
.net Framework
Mitigation only
HIGH 9.3
CVE-2013-3134EPSS 21%
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays o…
.net Framework
Mitigation only
HIGH 9.3
CVE-2013-3171EPSS 21%
The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of deleg…
.net Framework
Mitigation only
HIGH 9.3
CVE-2013-3127EPSS 22%
The Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Windows Media Format Runtime…
Windows Media Format Runtime
Mitigation only
HIGH 7.8
CVE-2013-3129EPSS 32%
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWr…
.net Framework
Mitigation only
HIGH 9.3
CVE-2013-3131EPSS 22%
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidim…
.net Framework
Mitigation only
HIGH 7.5
CVE-2013-3651
LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/…
Ec Cube
Mitigation only
HIGH 9.0
CVE-2013-3384
The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email…
Ironport Asyncos
after 7.1.3
HIGH 9.0
CVE-2013-3383
The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550 allows…
Ironport Asyncos
after 7.1.3
HIGH 9.3
CVE-2013-1688
The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to …
Firefox
after 21.0
HIGH 7.5
CVE-2013-3520EPSS 56%
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via …
Vcenter Chargeback Manager
after 2.5.0
MEDIUM 6.5
CVE-2013-0143EPSS 7%
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authen…
Viostor Network Video Recorder
Mitigation only
HIGH 9.3
CVE-2013-1323EPSS 21%
Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code…
Publisher
Mitigation only
HIGH 9.3
CVE-2013-1335EPSS 21%
Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape C…
Word
Mitigation only
MEDIUM 6.5
CVE-2013-3508
html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated us…
Groundwork Monitor
Mitigation only
HIGH 9.0
CVE-2013-3079
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by le…
Vcenter Server Appliance
Mitigation only
MEDIUM 6.8
CVE-2013-0132
The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to exec…
Parallels Plesk Panel
Mitigation only
HIGH 9.3
CVE-2013-1296EPSS 21%
The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not properly handle objects in memor…
Remote Desktop Connection
Mitigation only
HIGH 7.5
CVE-2013-1898
lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Thumbshooter
Mitigation only
MEDIUM 6.5
CVE-2013-1899EPSS 54%
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a den…
PostgreSQL
Mitigation only
HIGH 7.5
CVE-2013-2615
lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Fastreader
No fix yet
HIGH 7.5
CVE-2013-2616
lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Mini Magick
No fix yet
HIGH 7.5
CVE-2013-2617
lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Curl
No fix yet
HIGH 7.5
CVE-2013-1875
command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename.
Command Wrap
No fix yet