Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2020-6484
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a…
Chrome
83.0.4103.61+
CRITICAL 9.6
CVE-2020-6471
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…
Chrome
83.0.4103.61+
MEDIUM 6.5
CVE-2020-6476
Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious e…
Chrome
83.0.4103.61+
CRITICAL 9.6
CVE-2020-6469
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…
Chrome
83.0.4103.61+
MEDIUM 5.4
CVE-2020-13240
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file e…
Dolibarr Erp\/crm
No fix yet
CRITICAL 9.8
CVE-2020-11716
Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affec…
Eluga Ray 530 Firmware
after 2020-04-10
CRITICAL 9.8
CVE-2020-9409
The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO Jasper…
Jasperreports Server
after 7.1.1
HIGH 7.8
CVE-2020-13149
Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, a…
Dragon Center
2.6.2003.2401+
CRITICAL 9.8
CVE-2020-12834EPSS 11%
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, …
Homematic Ccu2 Firmware
after 3.51.6
HIGH 7.8
CVE-2020-0024
In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions bypass. This could lead to local…
Android
Patch available
MEDIUM 6.5
CVE-2020-4259
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules fro…
Sterling File Gateway
after 6.0.3.1
HIGH 8.1
CVE-2019-9682
Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of …
Sd6al Firmware
2019-12+
HIGH 7.8
CVE-2020-5896
On versions 7.1.5-7.1.9, the BIG-IP Edge Client's Windows Installer Service's temporary folder has weak file and folder permissions.
Big Ip Access Policy Manager
after 15.1.0.3
HIGH 7.8
CVE-2020-12608EPSS 22%
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insec…
Managed Service Provider Patch Management Engine
1.1.15+
MEDIUM 6.5
CVE-2020-2183
Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no perm…
Copy Artifact
after 1.43.1
HIGH 7.8
CVE-2020-8018
A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server …
Linux Enterprise Desktop
Mitigation only
MEDIUM 5.3
CVE-2020-12277
GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.
GitLab
12.7.8 / 12.8.8+
HIGH 7.8
CVE-2020-8471
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…
800xa System
Mitigation only
HIGH 8.8
CVE-2019-15793
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate us…
Linux Kernel
Patch available
HIGH 8.2
CVE-2020-12118
The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a…
Tss Lib
1.2.0+
MEDIUM 5.5
CVE-2020-8798
httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm e…
Rx4 1500 Firmware
after 1.0.5
HIGH 8.8
CVE-2020-12075
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
Data Tables Generator
1.9.92+
MEDIUM 6.5
CVE-2020-11689
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
Teamcity
2019.2.1+
HIGH 7.8
CVE-2020-0547
Incorrect default permissions in the installer for Intel(R) Data Migration Software versions 3.3 and earlier may allow an authenticated user to poten…
Data Migration
after 3.3
HIGH 7.8
CVE-2020-4270
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846.
Qradar Security Information And Event Manager
7.3.3+
MEDIUM 5.4
CVE-2020-4274
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission chec…
Qradar Security Information And Event Manager
7.3.3+
HIGH 7.8
CVE-2019-14326
An issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) with root privileges in the e…
Andy Os
after 46.11.113
MEDIUM 5.3
CVE-2020-7802
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulner…
Husky Rtu 6049 E70 Firmware
after 5.0
MEDIUM 6.5
CVE-2020-6456
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via …
Chrome
81.0.4044.92+
HIGH 8.8
CVE-2020-6439
Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted H…
Chrome
81.0.4044.92+