Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2020-3396
A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical …
Ios Xe
Mitigation only
CRITICAL 9.8
CVE-2015-4719
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
Pexip Infinity
10+
HIGH 7.8
CVE-2020-25595
An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been ide…
Fedora
after 4.14.0
HIGH 8.8
CVE-2020-8247
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.18…
Application Delivery Controller Firmware
10.2.7b / 11.0.3f+
MEDIUM 6.7
CVE-2020-0403
In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation…
Android
Mitigation only
HIGH 7.2
CVE-2020-24046
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a smal…
Spamtitan
No fix yet
MEDIUM 5.5
CVE-2020-0404
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalati…
Android
Mitigation only
HIGH 7.8
CVE-2020-0074
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a…
Android
Patch available
HIGH 8.4
CVE-2020-16875EPSS 47%
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p>
<p>An attacker who s…
Exchange Server
Patch available
HIGH 7.5
CVE-2020-9733
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If e…
Experience Manager
after 6.5.5.0
HIGH 7.0
CVE-2020-7311
Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to assume SYSTEM rights during…
Mcafee Agent
5.6.6+
HIGH 7.8
CVE-2020-10056
A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the affected application is execu…
License Management Utility
2.4+
MEDIUM 6.1
CVE-2020-7324
Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass security mechanisms and deny acces…
Mvision Endpoint
20.9+
HIGH 7.8
CVE-2020-7523
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could ca…
Modbus Driver Suite
2.20_ie_30 / 3.20_ie_30+
HIGH 7.2
CVE-2020-4603
IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new wea…
Security Guardium Insights
Patch available
MEDIUM 6.8
CVE-2020-5916
In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file…
Big Ip Access Policy Manager
15.0.1.4 / 15.1.0.5+
HIGH 7.8
CVE-2019-11847
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the co…
Aleos
4.4.9 / 4.9.4+
MEDIUM 6.8
CVE-2020-10290
Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that p…
Urx
Mitigation only
MEDIUM 6.9
CVE-2020-7310
Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change fil…
Total Protection
4.0.161.1+
MEDIUM 5.4
CVE-2020-14194
Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
Zulip Server
2.1.5+
HIGH 7.5
CVE-2020-14215
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
Zulip Server
2.1.5+
HIGH 7.8
CVE-2020-15862
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as …
Ubuntu Linux
5.8.1+
CRITICAL 9.9
CVE-2020-15149
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user…
Nodebb
1.14.3+
HIGH 8.8
CVE-2020-7018
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, t…
Enterprise Search
7.9.0+
MEDIUM 6.5
CVE-2020-7019
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs …
Elasticsearch
6.8.12 / 7.9.0+
HIGH 7.0
CVE-2020-1488
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in acc…
Windows 10
Patch available
MEDIUM 5.3
CVE-2015-8032
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
Textpattern
Patch available
HIGH 7.8
CVE-2020-24330
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop t…
Fedora
after 0.3.14
HIGH 7.8
CVE-2020-24331
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access …
Fedora
after 0.3.14
MEDIUM 6.5
CVE-2020-7305
Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to crea…
Data Loss Prevention
11.3.28 / 11.4.200+