Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-26511
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
Wordpress \+ Azure Ad \/ Microsoft Office 365
11.7+
HIGH 7.5
CVE-2020-26160
jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by …
Jwt Go
after 3.2.0
HIGH 7.5
CVE-2018-11765EPSS 5%
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerbe…
Hadoop
after 2.9.2
HIGH 7.8
CVE-2020-24563
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), whi…
Apex One
Mitigation only
CRITICAL 9.8
CVE-2020-26105
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
Cpanel
88.0.3+
CRITICAL 9.8
CVE-2020-26101
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
Cpanel
88.0.3+
HIGH 8.1
CVE-2020-15222
In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the un…
Fosite
0.31.0+
CRITICAL 9.8
CVE-2019-16028
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to b…
Secure Firewall Management Center
6.2.3.16 / 6.3.0.6+
MEDIUM 5.3
CVE-2019-15993EPSS 10%
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information…
Sg250x 24 Firmware
2.5.0.92+
HIGH 7.5
CVE-2020-8253
Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before R…
Xenmobile Server
after 10.8.0
MEDIUM 6.5
CVE-2020-8200
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory doma…
Storefront Server
3.0.8001 / 3.12.5001+
MEDIUM 5.7
CVE-2020-7297
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard …
Web Gateway
7.8.2.22 / 8.2.9+
CRITICAL 9.0
CVE-2020-7293
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change…
Web Gateway
7.8.2.23 / 8.2.11+
MEDIUM 5.7
CVE-2020-7296
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configurat…
Web Gateway
7.8.2.23 / 8.2.11+
CRITICAL 9.8
CVE-2020-16098
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior…
Command Centre
8.00.1228 / 8.10.1211+
MEDIUM 6.5
CVE-2020-13303
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized use…
GitLab
13.1.10 / 13.2.8+
MEDIUM 5.9
CVE-2020-15802EPSS 7%
Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specific…
Bluetooth Core Specification
5.1+
HIGH 8.8
CVE-2020-16222
In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and
PerformanceBridge Focal Point Version A.01, when an actor claims to have
a g…
Patient Information Center Ix
No fix yet
CRITICAL 9.1
CVE-2020-25251
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and …
Onbase
after 20.3.10.1000
CRITICAL 9.8
CVE-2020-15787
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authenticat…
Simatic Hmi United Comfort Panels Firmware
Mitigation only
MEDIUM 6.9
CVE-2020-7323
Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical lo…
Endpoint Security
10.7.0+
HIGH 7.8
CVE-2019-10562
u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into se…
Ipq6018 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-24987
Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authenticati…
Ac18 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-24029
Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple reque…
Qualiex
Mitigation only
CRITICAL 9.8
CVE-2020-5777EPSS 23%
MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database …
Magmi
0.7.24+
CRITICAL 9.8
CVE-2020-24786EPSS 13%
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo…
Manageengine Adselfservice Plus
after 12.1.2
HIGH 7.8
CVE-2020-8097
An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivile…
Endpoint Security
6.6.18.261+
CRITICAL 10.0
CVE-2020-15164
in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repea…
Scratch Login
1.1+
HIGH 8.1
CVE-2020-15601
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated …
Deep Security Manager
Patch available
HIGH 8.1
CVE-2020-15605
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthe…
Deep Security Manager
Patch available