Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-11856EPSS 5%
Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow r…
Operation Bridge Reporter
after 10.40
MEDIUM 6.5
CVE-2020-3977
VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first …
Horizon Daas
after 8.0.1
CRITICAL 9.8
CVE-2020-23512
VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) with…
P1 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-16098
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior…
Command Centre
8.00.1228 / 8.10.1211+
MEDIUM 5.4
CVE-2020-13289
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA …
GitLab
13.1.10 / 13.2.8+
MEDIUM 5.9
CVE-2020-13920
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to con…
Activemq
5.15.12+
MEDIUM 5.3
CVE-2020-5780
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, …
Email Subscribers \& Newsletters
4.5.6+
HIGH 7.5
CVE-2020-11579EPSS 26%
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unau…
Phpkb
No fix yet
MEDIUM 6.1
CVE-2020-12621
The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component.
Teamwire
No fix yet
MEDIUM 5.3
CVE-2020-20627
The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.
Givewp
after 2.5.9
HIGH 8.8
CVE-2020-24363 KEVEPSS 21%
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a fac…
Tl Wa855re Firmware
200731+
HIGH 7.5
CVE-2018-1501
IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-F…
Security Guardium
Patch available
MEDIUM 6.8
CVE-2020-15483
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, wit…
M1000 Multipara Patient Monitor Firmware
No fix yet
MEDIUM 5.3
CVE-2020-9062
Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages betwe…
Probase
Mitigation only
HIGH 7.1
CVE-2020-10124
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer,…
Aptra Xfs
Mitigation only
CRITICAL 9.8
CVE-2020-24051
The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authenticatio…
Exvf5c 2 Firmware
No fix yet
MEDIUM 5.8
CVE-2020-3448
A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authen…
Cyber Vision Center
3.0.4+
HIGH 7.5
CVE-2020-17475
Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet dat…
Koala Firmware
Mitigation only
MEDIUM 6.5
CVE-2019-5591 KEVEPSS 18%
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by imper…
Fortios
after 6.2.0
CRITICAL 9.8
CVE-2020-12106
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative fun…
Vpncrypt M10 Firmware
Mitigation only
CRITICAL 9.1
CVE-2020-6294
Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for fun…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.5
CVE-2020-6309
SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authent…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.1
CVE-2020-16167
Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and an…
Launcher Os
after 13146
MEDIUM 6.5
CVE-2020-15136
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gatew…
Etcd
3.3.23 / 3.4.10+
HIGH 7.5
CVE-2020-15127
In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entir…
Contour
1.7.0+
MEDIUM 5.3
CVE-2020-3461
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …
Data Center Network Manager
11.4+
CRITICAL 9.8
CVE-2020-3376
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypa…
Data Center Network Manager
Mitigation only
CRITICAL 9.8
CVE-2020-2076
SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST …
Package Analytics
after 04.0.0
CRITICAL 9.8
CVE-2020-15391
The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket p…
Devspace
Patch available
CRITICAL 9.8
CVE-2020-10920
This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen p…
C More Hmi Ea9 Firmware
Mitigation only