Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2017-15608
Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Proget
5.0.4+
CRITICAL 9.8
CVE-2017-15607
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.
Otter
1.7.4+
CRITICAL 9.8
CVE-2017-17086
Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (cr…
Otter
after 1.7.4
HIGH 7.5
CVE-2017-16520
Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.
Buildmaster
5.8.2+
CRITICAL 9.8
CVE-2017-16521
In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.
Buildmaster
5.8.2+
MEDIUM 6.1
CVE-2017-16760
Inedo BuildMaster before 5.8.2 has XSS.
Buildmaster
5.8.2+
MEDIUM 6.1
CVE-2017-16761
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
Buildmaster
5.8.2+
HIGH 7.5
CVE-2017-14944
Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.
Proget
after 4.7.13