Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-14258
HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker…
Notes
Patch available
MEDIUM 6.6
CVE-2020-7842
Improper Input validation vulnerability exists in Netis Korea D'live AP which could cause arbitrary command injection and execution when the time set…
Wf2429tb Firmware
Mitigation only
MEDIUM 5.3
CVE-2020-3441
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information…
Webex Meetings
3.0+
CRITICAL 9.8
CVE-2020-3470
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to exec…
Enterprise Nfv Infrastructure Software
3.2.11.3 / 4.4.1+
MEDIUM 6.5
CVE-2020-3471
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to maintain bidirectional aud…
Webex Meetings Server
3.0+
HIGH 8.8
CVE-2020-7841
Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun…
Xplatform
9.2.2.250+
CRITICAL 9.8
CVE-2020-27131EPSS 88%
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker …
Security Manager
after 4.22
CRITICAL 9.8
CVE-2020-27125
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The …
Security Manager
after 4.21
HIGH 8.8
CVE-2020-28648EPSS 6%
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.
Nagios Xi
5.7.5+
HIGH 7.5
CVE-2020-25151
The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack on the NIO 50 (all versions).
Nio 50 Firmware
No fix yet
MEDIUM 6.7
CVE-2020-9127
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some ma…
Nip6300 Firmware
Mitigation only
MEDIUM 6.5
CVE-2020-8669
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable info…
Data Center Manager
3.6.2+
HIGH 8.8
CVE-2020-12347
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable esca…
Data Center Manager
3.6.2+
MEDIUM 6.5
CVE-2020-12349
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable info…
Data Center Manager
3.6.2+
MEDIUM 6.7
CVE-2020-12323
Improper input validation in the Intel(R) ADAS IE before version ADAS_IE_1.0.766 may allow a privileged user to potentially enable escalation of priv…
Adas Ie
1.0.766+
MEDIUM 6.7
CVE-2020-0572
Improper input validation in the firmware for Intel(R) Server Board S2600ST and S2600WF families may allow a privileged user to potentially enable es…
Server Board S2600st Firmware
02.01.0011 / 02.01.0012+
MEDIUM 6.7
CVE-2020-8756
Improper input validation in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user…
Converged Security And Manageability Engine
11.8.80 / 11.12.80+
CRITICAL 9.8
CVE-2020-7472
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9…
Sugarcrm
8.0.7 / 9.0.4+
MEDIUM 6.5
CVE-2020-12314
Improper input validation in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enabl…
Proset\/wireless Wifi
21.110+
MEDIUM 6.5
CVE-2020-12322
Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enab…
Dual Band Wireless Ac 3168 Firmware
21.110+
HIGH 7.8
CVE-2020-0590
Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege…
Xeon Bronze 3206r Firmware
Patch available
HIGH 7.8
CVE-2020-11201
Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapd…
Qcm6125 Firmware
No fix yet
HIGH 7.2
CVE-2020-2000
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrup…
Pan Os
8.1.16 / 9.0.10+
MEDIUM 5.5
CVE-2020-16127
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read …
Accountsservice
0.6.55+
HIGH 7.8
CVE-2020-26817
SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing …
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.5
CVE-2020-0442
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote de…
Android
Patch available
HIGH 7.5
CVE-2020-8268
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the glob…
Json8 Merge Patch
1.0.3+
MEDIUM 6.5
CVE-2020-28349
An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplink Denial of Service via malfo…
Network Server
Patch available
HIGH 7.5
CVE-2020-3444
A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic…
Ios Xe
after 17.2.1
HIGH 7.3
CVE-2020-3556
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, loc…
Anyconnect Secure Mobility Client
Mitigation only