Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-3531
A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end data…
Iot Field Network Director
4.6.1+
HIGH 7.5
CVE-2020-3392
A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on…
Iot Field Network Director
4.6.1+
CRITICAL 10.0
CVE-2020-26821
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…
Solution Manager
Mitigation only
CRITICAL 10.0
CVE-2020-26822
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…
Solution Manager
Mitigation only
CRITICAL 10.0
CVE-2020-26823
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…
Solution Manager
Mitigation only
CRITICAL 10.0
CVE-2020-26824
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…
Solution Manager
Mitigation only
CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…
Airflow
1.10.11+
MEDIUM 5.5
CVE-2020-27019EPSS 18%
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an …
Interscan Messaging Security Virtual Appliance
after 9.1
HIGH 7.5
CVE-2020-10291
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making …
Visual Components Network License Server
Mitigation only
CRITICAL 9.8
CVE-2020-7128
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
Airwave Glass
1.3.2+
HIGH 7.5
CVE-2020-27986EPSS 16%
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reported…
Sonarqube
Mitigation only
HIGH 7.5
CVE-2020-25966
Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentic…
Spectra
3.4.0+
HIGH 8.1
CVE-2020-26649
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
Atomxcms 2
No fix yet
HIGH 8.8
CVE-2018-11764
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even …
Hadoop
Mitigation only
CRITICAL 9.8
CVE-2020-12500
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…
Es7510 Xt Firmware
No fix yet
CRITICAL 9.8
CVE-2020-15243
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 …
Smartstore
Mitigation only
MEDIUM 5.5
CVE-2020-26567EPSS 17%
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any a…
Dsr 250n Firmware
3.17b+
MEDIUM 6.5
CVE-2020-3598
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to acc…
Vision Dynamic Signage Director
6.2.0+
HIGH 7.5
CVE-2020-26876EPSS 11%
The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by u…
Wp Courses
after 2.0.27
MEDIUM 5.3
CVE-2020-26599
An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can be accepted without authentic…
Android
Mitigation only
CRITICAL 9.8
CVE-2020-24217EPSS 40%
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authenti…
Iptv\/h.264 Video Encoder Firmware
No fix yet
CRITICAL 9.8
CVE-2020-6875
A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attacke…
Zxone 19700 Snpe Firmware
Mitigation only
HIGH 7.5
CVE-2020-26061
ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword functio…
Passwordstate
8.5+
HIGH 7.5
CVE-2020-12127EPSS 7%
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to…
Wn530h4 Firmware
Mitigation only
HIGH 7.5
CVE-2020-9487
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to c…
Nifi
after 1.11.4
HIGH 8.2
CVE-2020-12505
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without aut…
750 852 Firmware
Mitigation only
CRITICAL 9.1
CVE-2020-12506
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by send…
750 362 Firmware
Mitigation only
CRITICAL 9.4
CVE-2020-25747
The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP…
Rv 3406 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-15851
Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories …
Backup \& Replication Transporter
No fix yet
MEDIUM 6.5
CVE-2019-16004
A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentic…
Vision Dynamic Signage Director
6.2.0+