Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2018-2634
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u…
Satellite
Patch available
MEDIUM 6.1
CVE-2018-2641EPSS 5%
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u1…
Satellite
Patch available
MEDIUM 5.3
CVE-2018-2629
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Ja…
Satellite
Patch available
MEDIUM 5.9
CVE-2018-2618
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Jav…
Satellite
Patch available
MEDIUM 5.3
CVE-2018-2603EPSS 7%
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected a…
Satellite
Patch available
MEDIUM 6.5
CVE-2018-2582
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE:…
Satellite
Patch available
HIGH 8.8
CVE-2014-0087
The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), al…
Cloudforms Management Engine
5.3+
HIGH 7.8
CVE-2017-12189
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which c…
Jboss Enterprise Application Platform
Patch available
HIGH 7.0
CVE-2017-7536
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows…
Hibernate Validator
5.2.5 / 5.3.6+
MEDIUM 6.1
CVE-2017-7559
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomp…
Undertow
1.3.31 / 1.4.17+
HIGH 7.8
CVE-2017-15131
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting…
Enterprise Linux
0.15.5+
HIGH 7.5
CVE-2018-4871EPSS 6%
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data …
Enterprise Linux Desktop
after 28.0.0.126
HIGH 7.8
CVE-2013-4364
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local u…
Openshift
Mitigation only
CRITICAL 9.8
CVE-2014-0121
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
Jboss Fuse
after 1.2.2
HIGH 8.8
CVE-2014-0120
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary us…
Jboss Fuse
after 1.2.2
MEDIUM 6.5
CVE-2017-16818
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) b…
Ceph
after 12.2.1
MEDIUM 5.4
CVE-2013-6465
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HT…
Jbpm
Patch available
HIGH 8.8
CVE-2017-15103EPSS 5%
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r…
Enterprise Linux
Patch available
HIGH 7.8
CVE-2017-15104
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi serv…
Enterprise Linux
Mitigation only
HIGH 7.8
CVE-2017-16997
elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or…
Enterprise Linux Desktop
Patch available
MEDIUM 6.5
CVE-2017-11305
A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference fil…
Enterprise Linux Desktop
after 27.0.0.187
HIGH 7.4
CVE-2017-1000407
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to …
Virtualization Host
4.15+
MEDIUM 6.5
CVE-2014-3250
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers t…
Linux
3.6.2+
CRITICAL 9.8
CVE-2017-3112EPSS 6%
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…
Enterprise Linux Desktop
after 27.0.0.183
CRITICAL 9.8
CVE-2017-3114EPSS 6%
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…
Enterprise Linux Desktop
after 27.0.0.183
CRITICAL 9.8
CVE-2017-11213EPSS 7%
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…
Enterprise Linux Desktop
after 27.0.0.183
CRITICAL 9.8
CVE-2017-11215EPSS 6%
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in…
Enterprise Linux Desktop
after 27.0.0.183
CRITICAL 9.8
CVE-2017-11225EPSS 6%
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in…
Enterprise Linux Desktop
after 27.0.0.183
CRITICAL 9.8
CVE-2017-10906
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitr…
Openstack
Patch available
MEDIUM 5.5
CVE-2017-15121
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not e…
Enterprise Linux
Mitigation only