Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2012-4143
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into…
Opera Browser
after 12.00
HIGH 9.3
CVE-2012-1661EPSS 24%
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remo…
Arcmap
after 10.0.2.3200
MEDIUM 6.5
CVE-2012-1037
PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP co…
Glpi
Mitigation only
HIGH 8.3
CVE-2012-2486
The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices…
Telepresence Multipoint Switch Software
after 1.9.0.1
HIGH 8.8
CVE-2012-0175EPSS 26%
The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gol…
Windows 2003 Server
Mitigation only
HIGH 9.3
CVE-2012-2174EPSS 38%
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.
Lotus Notes
Mitigation only
HIGH 7.8
CVE-2012-3289
VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attacke…
Workstation
Mitigation only
HIGH 9.3
CVE-2012-1855EPSS 20%
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitra…
.net Framework
Mitigation only
MEDIUM 5.5
CVE-2012-2596
The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in param…
Wincc
Mitigation only
MEDIUM 6.8
CVE-2011-4458
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allow…
Rt
Patch available
HIGH 9.3
CVE-2012-0295
The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-…
Endpoint Protection
Mitigation only
HIGH 7.5
CVE-2012-2924
PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary PHP co…
Elearning Server
No fix yet
MEDIUM 5.0
CVE-2011-3285
CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 all…
Adaptive Security Appliance Software
Mitigation only
HIGH 9.3
CVE-2011-2478
Google SketchUp before 8 does not properly handle edge geometry in SketchUp (aka .SKP) files, which allows remote attackers to execute arbitrary code…
Sketchup
after 7.1
MEDIUM 5.0
CVE-2011-4882
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit) via an uns…
Webmi2ads
after 2.0.1
HIGH 7.5
CVE-2012-2224
Xunlei Thunder before 7.2.6 allows remote attackers to execute arbitrary code via a crafted file, related to a "DLL injection vulnerability."
Thunder
Mitigation only
HIGH 8.8
CVE-2012-0158 KEVEPSS 100%
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3…
Office
Patch available
MEDIUM 6.8
CVE-2012-1924
Opera before 11.62 allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the dow…
Opera Browser
after 11.61
MEDIUM 6.4
CVE-2012-1919
CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directory trave…
Atmail Open
after 1.04
MEDIUM 6.5
CVE-2012-0319
The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary…
Movable Type Open Source
after 4.37
HIGH 7.5
CVE-2011-4189EPSS 12%
The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corru…
Groupwise
No fix yet
HIGH 9.0
CVE-2012-0363
The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows…
Small Business Srp520 Series Firmware
after 1.01.24
HIGH 7.5
CVE-2012-1205EPSS 25%
PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute…
Relocate Upload
after 0.14
MEDIUM 6.8
CVE-2012-0993
Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows r…
Zenphoto
Patch available
MEDIUM 6.8
CVE-2011-4614EPSS 6%
PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, …
TYPO3
Patch available
HIGH 7.5
CVE-2012-1199
Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP…
Basic Analysis And Security Engine
No fix yet
HIGH 7.5
CVE-2012-1200
Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType par…
Nova Cms
No fix yet
HIGH 7.8
CVE-2012-0014EPSS 28%
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unman…
.net Framework
Mitigation only
HIGH 9.3
CVE-2012-0015EPSS 24%
Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute …
.net Framework
Mitigation only
HIGH 9.3
CVE-2012-0019EPSS 20%
Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…
Visio Viewer
Mitigation only