Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-10921
This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. A…
C More Hmi Ea9 Firmware
Mitigation only
HIGH 7.5
CVE-2020-15894
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can…
Dir 816l Firmware
Patch available
HIGH 8.1
CVE-2020-12028EPSS 53%
In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the re…
Factorytalk View
No fix yet
HIGH 7.5
CVE-2020-10605
Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.
Cim 500 Firmware
06.16.00+
HIGH 7.5
CVE-2020-13405EPSS 14%
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /mo…
Microweber
1.1.20+
CRITICAL 9.8
CVE-2020-14501
Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulner…
Iview
after 5.6
HIGH 7.5
CVE-2020-5373
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an improper authentication v…
Emc Omimssc For Sccm
7.2.1+
HIGH 7.5
CVE-2020-10044
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with a…
Sicam Mmu Firmware
2.05 / 2.18+
CRITICAL 9.8
CVE-2020-10038
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with a…
Sicam Mmu Firmware
2.05 / 2.18+
CRITICAL 10.0
CVE-2020-6287 KEVEPSS 95%
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.8
CVE-2020-10282
The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety o…
Micro Air Vehicle Link
Mitigation only
HIGH 7.5
CVE-2020-5910
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do no…
Nginx Controller
after 3.5.0
HIGH 7.5
CVE-2020-3402
A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, rem…
Unified Customer Voice Portal
after 12.5
CRITICAL 9.1
CVE-2020-13382EPSS 53%
openSIS through 7.4 has Incorrect Access Control.
Opensis
after 7.4
HIGH 7.5
CVE-2020-15335
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
Cloudcnm Secumanager
Mitigation only
HIGH 7.5
CVE-2020-15336
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
Cloudcnm Secumanager
Mitigation only
HIGH 7.5
CVE-2020-11961
Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authen…
Xiaomi R3600 Firmware
1.0.20+
CRITICAL 9.8
CVE-2020-10272
MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authen…
Mir100 Firmware
after 2.8.1.1
CRITICAL 9.8
CVE-2020-9480EPSS 29%
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…
Spark
after 2.4.5
CRITICAL 9.8
CVE-2020-11969
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP…
Tomee
after 8.0.1
HIGH 7.8
CVE-2020-13150
D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filterin…
Dsl 2750u Firmware
Mitigation only
MEDIUM 6.8
CVE-2020-1813
HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. Due to improper authenticat…
P30 Firmware
10.1.0.135+
MEDIUM 6.5
CVE-2020-4471
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a…
Spectrum Protect Plus
after 10.1.5
HIGH 7.5
CVE-2020-14048
Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agen…
Manageengine Servicedesk Plus
Mitigation only
CRITICAL 9.1
CVE-2020-7589
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker reading and mod…
Logo\! 8 Bm Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-6263
Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40…
Netweaver Application Server Java
Mitigation only
HIGH 7.5
CVE-2020-12004EPSS 14%
The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gat…
Ignition Gateway
7.9.14 / 8.0.10+
HIGH 8.8
CVE-2020-5589
SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with…
Wf 1000x Firmware
Mitigation only
MEDIUM 5.3
CVE-2020-3333
A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on …
Application Policy Infrastructure Controller
1.1.2.20+
MEDIUM 5.5
CVE-2020-3335
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive informa…
Application Policy Infrastructure Controller
1.1.2.20+