Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2019-16152
A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes …
Forticlient
after 6.2.1
MEDIUM 5.5
CVE-2011-0220
Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
Bonjour
2011+
CRITICAL 9.8
CVE-2010-4815
Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.
Coppermine Gallery
1.4.26+
HIGH 8.8
CVE-2020-3110EPSS 6%
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated…
Video Surveillance 8400 Ip Camera Firmware
1.0.7+
HIGH 8.8
CVE-2020-3111
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely e…
Ip Conference Phone 7832 Firmware
11.3 / 12.7+
MEDIUM 5.3
CVE-2020-8124
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass securit…
Url Parse
after 1.4.4
CRITICAL 9.8
CVE-2020-8125
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution…
Klona
after 1.1.0
HIGH 7.5
CVE-2020-8517EPSS 7%
An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may w…
Ubuntu Linux
4.10+
HIGH 8.0
CVE-2019-15613
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
Nextcloud Server
15.0.14 / 16.0.7+
HIGH 8.8
CVE-2014-8126
The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.
Htcondor
8.2.6+
CRITICAL 9.8
CVE-2016-2031EPSS 5%
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient ch…
Airwave
4.1.3.0 / 8.2.0.0+
MEDIUM 5.5
CVE-2020-8095
A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial…
Total Security 2020
24.9+
HIGH 7.5
CVE-2020-3147
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con…
Sg200 50 Firmware
1.3.7.18+
CRITICAL 9.8
CVE-2020-8445
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from pr…
Ossec
after 3.5.0
HIGH 7.5
CVE-2020-5215
In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation fault in eager mode as the f…
Tensorflow
1.15.2 / 2.0.1+
HIGH 7.8
CVE-2019-4620
IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables.…
Mq Appliance
8.0.0.14 / 9.1.0.4+
CRITICAL 9.8
CVE-2014-2914
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to ex…
Fish
2.1.1+
CRITICAL 9.8
CVE-2013-2571EPSS 16%
Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted reques…
Xpient Iris
after 3.8
CRITICAL 9.8
CVE-2019-5464
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the li…
GitLab
11.11.7+
CRITICAL 9.8
CVE-2020-8087EPSS 6%
SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as de…
D3g0804w Firmware
No fix yet
HIGH 7.5
CVE-2019-20430
In the Lustre file system before 2.12.3, the mdt module has an LBUG panic (via a large MDT Body eadatasize field) due to the lack of validation for s…
Lustre
2.12.3+
CRITICAL 9.1
CVE-2019-16029
A vulnerability in the application programming interface (API) of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacke…
Smart Software Manager On Prem
7-201910+
MEDIUM 6.5
CVE-2020-3134
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, re…
Email Security Appliance
13.0+
MEDIUM 5.3
CVE-2020-3139
A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC)…
Application Policy Infrastructure Controller
4.2+
MEDIUM 5.9
CVE-2019-16026
A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mobility Management Entity (MME) could allow an una…
Staros
21.16.1+
MEDIUM 6.5
CVE-2019-16027
A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in C…
Ios Xr
Mitigation only
HIGH 7.2
CVE-2019-16005
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary co…
Collaboration Meeting Rooms
2019.09.19.1956m+
HIGH 8.8
CVE-2019-1349EPSS 34%
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution …
Visual Studio 2017
15.9.18 / 16.4.1+
HIGH 8.8
CVE-2019-1350EPSS 26%
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution …
Visual Studio 2017
15.9.18 / 16.4.1+
HIGH 8.8
CVE-2019-1352EPSS 24%
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution …
Visual Studio 2017
15.9.18 / 16.4.1+