Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.4
CVE-2020-8843
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Ist…
Istio
after 1.3.6
HIGH 7.5
CVE-2019-20045
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. Specially crafted malicio…
Husky Rtu 6049 E70 Firmware
after 5.0
MEDIUM 6.5
CVE-2018-21033
A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Adviso…
Device Manager
4.2.0-00 / 8.6.2-00+
CRITICAL 9.8
CVE-2020-8614
An issue was discovered on Askey AP4000W TDC_V1.01.003 devices. An attacker can perform Remote Code Execution (RCE) by sending a specially crafted ne…
Ap4000w Firmware
No fix yet
MEDIUM 5.5
CVE-2020-1976
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the …
Globalprotect
after 5.0.5
HIGH 8.8
CVE-2013-5106
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
Python Mode
No fix yet
HIGH 7.2
CVE-2020-6191
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Age…
Landscape Management
Mitigation only
HIGH 7.2
CVE-2020-6192
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent …
Landscape Management
Mitigation only
MEDIUM 6.5
CVE-2019-19192
The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecutive Attr…
Wb55
after 1.3.1
MEDIUM 5.3
CVE-2020-7957
The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet an…
Fedora
2.3.9.3+
HIGH 7.5
CVE-2020-8815
Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via…
Bearftp
0.3.1+
HIGH 8.8
CVE-2020-2109
Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed m…
Pipeline\
after 2.78
HIGH 8.8
CVE-2020-2110
Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST trans…
Script Security
after 1.69
CRITICAL 9.8
CVE-2014-9390EPSS 75%
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on…
Git
0.21.3 / 1.8.5.6+
MEDIUM 6.0
CVE-2020-0751
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a …
Windows 10
Patch available
MEDIUM 6.8
CVE-2020-0661
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest o…
Windows 10
Patch available
CRITICAL 9.8
CVE-2013-1607
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability
Pdfkit
0.5.3+
HIGH 8.8
CVE-2013-4535
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm imag…
Virtualization
1.7.2+
MEDIUM 5.4
CVE-2020-6411
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via…
Chrome
80.0.3987.87+
MEDIUM 5.4
CVE-2020-6412
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via…
Chrome
80.0.3987.87+
HIGH 8.8
CVE-2020-6416
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a…
Chrome
80.0.3987.87+
MEDIUM 6.5
CVE-2020-6399
Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted …
Chrome
80.0.3987.87+
MEDIUM 6.5
CVE-2020-6401
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via…
Chrome
80.0.3987.87+
HIGH 8.8
CVE-2020-6402
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a mal…
Chrome
80.0.3987.87+
HIGH 8.8
CVE-2019-13322
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction …
Mi Browser
10.4.0+
CRITICAL 9.8
CVE-2014-5087EPSS 7%
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user ex…
Sphider
1.3.6 / 3.2+
CRITICAL 9.8
CVE-2014-5091EPSS 15%
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious use…
Status2k
No fix yet
HIGH 8.8
CVE-2014-5468EPSS 53%
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG …
Railo
after 4.2.1.000
HIGH 8.8
CVE-2014-7224
A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityT…
Android
4.4+
CRITICAL 9.8
CVE-2019-15606EPSS 20%
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
Node.js
10.19.0 / 12.15.0+