Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-2168
Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resultin…
Azure Container Service
after 1.0.1
CRITICAL 9.1
CVE-2020-5555
Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the same directory where it is pl…
Shihonkanri Plus Goout
Mitigation only
HIGH 7.8
CVE-2019-4001
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.
Insync
No fix yet
CRITICAL 9.8
CVE-2020-10837
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and a…
Android
Mitigation only
CRITICAL 9.8
CVE-2020-1747EPSS 5%
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes …
Fedora
5.3.1+
MEDIUM 5.4
CVE-2020-6425
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious…
Chrome
80.0.3987.149+
HIGH 7.5
CVE-2018-20335
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= …
Asuswrt
No fix yet
HIGH 7.8
CVE-2020-10648
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT im…
U Boot
2018.03+
MEDIUM 5.7
CVE-2019-20485
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a…
Libvirt
6.0.0+
HIGH 7.5
CVE-2020-8787
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
Suitecrm
7.10.23 / 7.11.11+
HIGH 7.5
CVE-2017-12842
Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that pa…
Bitcoin Core
0.14.0+
MEDIUM 5.3
CVE-2020-10240
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames …
Joomla\!
3.9.16+
HIGH 7.5
CVE-2019-19942
Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 b…
Centro Grande Firmware
6.14.06 / 7.10.18+
MEDIUM 6.1
CVE-2019-6696
An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an…
Fortios
after 6.0.8
HIGH 7.3
CVE-2019-2216
In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privileg…
Android
Mitigation only
CRITICAL 9.8
CVE-2020-10567EPSS 19%
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is n…
Responsive Filemanager
after 9.14.0
MEDIUM 5.5
CVE-2020-0567
Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to enable denial of service via …
Graphics Driver
26.20.100.7212+
MEDIUM 6.7
CVE-2020-0526
Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. Th…
Nuc Kit Nuc8i7bek Firmware
Mitigation only
MEDIUM 5.3
CVE-2018-19516
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equ…
Kde Applications
18.12+
HIGH 7.8
CVE-2020-0808
An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, aka 'Provisioning Runtime Eleva…
Windows 10
Patch available
CRITICAL 9.8
CVE-2020-5203
In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GE…
Fat Free Framework
Patch available
HIGH 7.2
CVE-2020-6202
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate th…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.7
CVE-2020-0050
In nfa_hciu_send_msg of nfa_hci_utils.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalati…
Android
Patch available
HIGH 7.8
CVE-2020-0041 KEV
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of p…
Android
Mitigation only
CRITICAL 9.8
CVE-2019-7589
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code …
Entrapass
8.10+
HIGH 7.5
CVE-2019-19298
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2). …
Sinvr\/sivms Video Server
Patch available
HIGH 7.5
CVE-2019-19279
A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions). Spec…
Siprotec 4
Mitigation only
CRITICAL 9.0
CVE-2020-10255
Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations against RowHammer attacks known …
Ddr4 Sdram
Mitigation only
MEDIUM 5.3
CVE-2019-12433
An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settin…
GitLab
after 11.11.0
MEDIUM 6.1
CVE-2020-10236
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was n…
Froxlor
0.10.14+