Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-17527EPSS 25%
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTT…
Tomcat
21.1.2+
HIGH 7.5
CVE-2020-5676
GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.
Growi
after 4.1.3
HIGH 7.5
CVE-2020-29043
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can cr…
Bigbluebutton
after 2.2.29
CRITICAL 9.8
CVE-2020-28333
Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not u…
Wepresent Wipg 1600w Firmware
No fix yet
MEDIUM 6.5
CVE-2020-12496
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.…
Rsg35 Firmware
2.0.0+
MEDIUM 5.3
CVE-2020-25703
The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affec…
Moodle
after 3.9.2
HIGH 7.5
CVE-2020-26076
A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on a…
Iot Field Network Director
4.6.1+
MEDIUM 5.3
CVE-2020-26230
Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identification and de-anonymization of…
Radar Covid Backend Dp3t Server
1.0.7 / 1.0.8+
HIGH 7.5
CVE-2020-2022
An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administ…
Pan Os
8.1.17 / 9.0.11+
MEDIUM 6.5
CVE-2020-27403
A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporatio…
32s330 Firmware
No fix yet
HIGH 7.5
CVE-2020-10291
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making …
Visual Components Network License Server
Mitigation only
MEDIUM 6.5
CVE-2020-7196
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos pass…
Bluedata Epic
after 4.0
HIGH 7.5
CVE-2020-15931
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administ…
Account Lockout Examiner
5.1+
MEDIUM 5.3
CVE-2020-1777
Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as in chat transcriptions inside…
Otrs
after 8.0.6
MEDIUM 5.5
CVE-2020-15250
In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste…
Debian Linux
3.1.1 / 4.13.1+
HIGH 7.5
CVE-2020-26869
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitima…
Pcvue
12.0.17+
HIGH 7.5
CVE-2020-1902
A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from…
Whatsapp
after 2.20.140
HIGH 7.5
CVE-2020-15235
In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would normally be hidden to everyone ex…
Core
after 41edf92
MEDIUM 5.3
CVE-2020-5132
SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerab…
Sma100 Firmware
Mitigation only
MEDIUM 6.5
CVE-2019-15963
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view s…
Unified Communications Manager
after 12.5
HIGH 7.5
CVE-2020-5975
NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application software that includes sensiti…
Geforce Now
2.0.23+
MEDIUM 5.3
CVE-2020-14181EPSS 100%
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabili…
Data Center
7.13.6 / 8.5.7+
MEDIUM 6.5
CVE-2018-19947
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sen…
Helpdesk
3.0.3+
HIGH 7.5
CVE-2020-9733
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If e…
Experience Manager
after 6.5.5.0
MEDIUM 5.3
CVE-2020-15790
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susc…
Spectrum Power 4
4.70+
MEDIUM 5.5
CVE-2020-3643
u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snapdragon Compute, Snapdragon Co…
Apq8009 Firmware
Mitigation only
MEDIUM 5.5
CVE-2020-3644
u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in Snapdragon Auto, S…
Apq8009 Firmware
Mitigation only
MEDIUM 6.5
CVE-2020-3547
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Mana…
Asyncos
after 13.6.1-193
MEDIUM 6.5
CVE-2020-3498
A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is …
Jabber
12.1.3 / 12.5.2+
MEDIUM 5.7
CVE-2020-3537
A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information. The vulne…
Jabber
12.1.3 / 12.5.2+