Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2020-15785
A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affe…
Siveillance Video Client
Mitigation only
HIGH 7.5
CVE-2020-1749
A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encr…
Linux Kernel
Patch available
MEDIUM 6.5
CVE-2020-3702
u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequ…
Debian Linux
Mitigation only
HIGH 7.5
CVE-2019-4689
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly …
Guardium Data Encryption
1.7.0 / 4.0.0.3+
HIGH 7.8
CVE-2020-15482
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank passwo…
M1000 Multipara Patient Monitor Firmware
Mitigation only
HIGH 7.1
CVE-2020-10124
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer,…
Aptra Xfs
Mitigation only
HIGH 7.5
CVE-2020-2232
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form,…
Email Extension
Mitigation only
MEDIUM 5.9
CVE-2020-9526
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session d…
P2p
after 3.0.3a
HIGH 8.8
CVE-2020-15058
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administr…
42633 Firmware
Mitigation only
HIGH 8.8
CVE-2020-15062
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administr…
Da 70254 Firmware
Mitigation only
HIGH 8.8
CVE-2020-15054
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administr…
Tl Ps310u Firmware
2.079.000.t0210+
MEDIUM 6.5
CVE-2020-15954
KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.
Debian Linux
Mitigation only
MEDIUM 6.8
CVE-2020-12638
An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK dev…
Esp Idf
after 4.2
MEDIUM 5.9
CVE-2020-4397
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle…
Verify Gateway
Patch available
MEDIUM 5.7
CVE-2020-3442
The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initiates an SSH connection to a D…
Duoconnect
1.1.1+
MEDIUM 6.5
CVE-2020-7592
A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Basic Panels 2nd G…
Simatic Hmi Basic Panels 1st Generation
Mitigation only
MEDIUM 6.5
CVE-2020-14171
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a …
Bitbucket
7.2.4+
HIGH 7.5
CVE-2020-12398
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unen…
Ubuntu Linux
68.9.0+
MEDIUM 6.5
CVE-2020-15509
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can…
Android Ble Library
after 2.2.1
HIGH 7.5
CVE-2020-10281
This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information prov…
Micro Air Vehicle Link
Mitigation only
HIGH 7.8
CVE-2020-5899
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which al…
Nginx Controller
after 3.4.0
HIGH 7.5
CVE-2020-12036
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) w…
Prismaflex Firmware
3.0+
HIGH 7.5
CVE-2020-12037
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) w…
Prismaflex Firmware
3.0+
CRITICAL 9.8
CVE-2020-12040
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer …
Sigma Spectrum Infusion System Firmware
after 6.05
HIGH 7.5
CVE-2020-12048
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) wh…
Phoenix X36 Firmware
Mitigation only
HIGH 7.5
CVE-2020-12008
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information w…
Em2400 Firmware
Mitigation only
HIGH 7.5
CVE-2020-10628
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.
Controledge Plc Firmware
Mitigation only
HIGH 7.5
CVE-2020-10624
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
Controledge Plc Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-5594
Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sen…
Melsec Iq R Firmware
Mitigation only
HIGH 8.1
CVE-2020-14930
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the veri…
Bt Ctroms Terminal
No fix yet