Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-13700EPSS 13%
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manip…
Acf To Rest Api
after 3.1.0
MEDIUM 5.3
CVE-2020-13998
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA er…
Xenapp
Mitigation only
HIGH 7.7
CVE-2020-8154
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a…
Nextcloud Server
17.0.5 / 18.0.3+
MEDIUM 6.5
CVE-2020-8791
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticate…
Oklok
No fix yet
MEDIUM 6.5
CVE-2020-11009
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not autho…
Rundeck
3.2.6+
CRITICAL 9.8
CVE-2020-11658
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.
Ca Api Developer Portal
after 4.3.1
HIGH 8.8
CVE-2020-9384
An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authentica…
Roc Partner Settlement
No fix yet
HIGH 7.5
CVE-2020-11589
An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET reques…
Cipace
9.1+
MEDIUM 5.4
CVE-2020-7918
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of…
Totemomail
Mitigation only
MEDIUM 6.5
CVE-2019-19946
The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
Dradis
No fix yet
MEDIUM 6.5
CVE-2020-5539
GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arb…
Grandit
Mitigation only
HIGH 7.5
CVE-2019-19866
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive informa…
Unify Openscape Uc Web Client
Mitigation only
HIGH 7.1
CVE-2019-18998
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables…
Asset Suite
9.4.2.6 / 9.5.3.2+
MEDIUM 6.5
CVE-2020-8503
Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by an authen…
Secure File Transfer
after 6.0.1003
MEDIUM 5.3
CVE-2019-15581
An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or mai…
GitLab
12.1.12 / 12.2.6+
MEDIUM 5.3
CVE-2019-15582
An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer t…
GitLab
12.1.12 / 12.2.6+
MEDIUM 5.4
CVE-2020-5194
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricte…
Ftp Server
No fix yet
HIGH 7.5
CVE-2019-20209
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR…
Citybook
1.0.6 / 1.2.2+
MEDIUM 5.3
CVE-2020-6859
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress …
Ultimate Member
after 2.1.2
CRITICAL 9.8
CVE-2019-15913
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communic…
Dgnwg03lm Firmware
No fix yet
MEDIUM 6.5
CVE-2019-5469
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users fil…
GitLab
11.11.6 / 12.0.4+
HIGH 8.8
CVE-2014-8356EPSS 6%
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modi…
Znid 2426a Firmware
No fix yet
MEDIUM 5.9
CVE-2019-16546
Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-th…
Google Compute Engine
4.2.0+
MEDIUM 6.5
CVE-2019-15815
ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized us…
2.00\(abbx.3\)
Patch available
HIGH 8.8
CVE-2019-17605
A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiti…
Eyecms
after 2019-10-15
MEDIUM 6.5
CVE-2019-8235
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. …
Magento
2.1.17 / 2.2.8+
CRITICAL 9.1
CVE-2019-17574EPSS 9%
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the…
Popup Maker
1.8.13+
CRITICAL 9.1
CVE-2019-17382EPSS 54%
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the…
Zabbix
after 4.4
HIGH 7.2
CVE-2019-17050
An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arb…
Voyager
after 1.2.7
HIGH 8.8
CVE-2019-16403
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be mani…
Bagisto
0.1.5+