Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2020-25011
A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.…
Kps2204 6 Port Managed Din Rail Programmable Serial Device Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-14480
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or…
Netcrunch
after 11.0.0.5282
HIGH 7.5
CVE-2020-25191
Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that c…
Compactrio Firmware
20.5+
MEDIUM 6.7
CVE-2020-7337
Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administr…
Virusscan Enterprise
8.8+
MEDIUM 5.3
CVE-2020-4625
IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly fla…
Cloud Pak For Security
Patch available
HIGH 8.8
CVE-2020-29074
scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
Fedora
Patch available
MEDIUM 5.5
CVE-2020-10762
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes …
Gluster Block
0.5.1+
CRITICAL 9.8
CVE-2020-11831
OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.
Ovoicemanager
Mitigation only
HIGH 7.1
CVE-2020-28914
An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a fil…
Kata Containers
1.11.5+
HIGH 7.8
CVE-2020-24525
Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of pri…
Nuc 8 Mainstream G Kit Nuc8i5inh Firmware
Mitigation only
HIGH 7.8
CVE-2019-11121
Improper file permissions in the installer for the Intel(R) Media SDK for Windows before version 2019 R1 may allow an authenticated user to potential…
Media Sdk
Patch available
MEDIUM 6.2
CVE-2020-16990
Azure Sphere Information Disclosure Vulnerability
Azure Sphere
20.07+
HIGH 7.8
CVE-2020-24367
Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later e…
Bluestacks
after 4.230
HIGH 7.8
CVE-2020-28055
A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporatio…
32s330 Firmware
No fix yet
HIGH 7.8
CVE-2020-3595
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating…
Sd Wan
20.1.2 / 20.3.2+
MEDIUM 5.5
CVE-2020-17490
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
Debian Linux
2015.8.10 / 2015.8.13+
HIGH 7.8
CVE-2020-15708
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite ar…
Ubuntu Linux
Mitigation only
HIGH 7.8
CVE-2020-27992
Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\Driv…
Dr.fone
No fix yet
MEDIUM 6.1
CVE-2020-27658
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easi…
Router Manager
1.2.4-8081+
HIGH 7.8
CVE-2020-26130
Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the d…
Open Tftp Server
No fix yet
HIGH 7.8
CVE-2020-26131
Issues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient access restrictions in the d…
Open Dhcp Server
No fix yet
HIGH 7.8
CVE-2020-26132
An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation directory, an attacker can eleva…
Home Dns Server
Mitigation only
HIGH 7.8
CVE-2020-26133
An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installation directory, an attacker can …
Dual Dhcp Dns Server
Mitigation only
HIGH 7.3
CVE-2020-10140
Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C…
True Image
Mitigation only
MEDIUM 5.5
CVE-2020-0410
In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclo…
Android
Patch available
HIGH 7.8
CVE-2020-17414
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtai…
Foxit Reader
after 10.0.1.35811
HIGH 7.8
CVE-2020-17415
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PhantomPDF 10.0.0.35798. An attacker must first o…
Foxit Reader
after 10.0.1.35811
MEDIUM 5.5
CVE-2020-15250
In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste…
Debian Linux
3.1.1 / 4.13.1+
HIGH 8.8
CVE-2020-15838
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
Automate
2020.8+
HIGH 8.1
CVE-2020-9048
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated…
Victor Web Client
after 5.4.1