Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2020-11827
In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious …
Galaxy
1.2.67+
MEDIUM 5.4
CVE-2020-6267
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.
Disclosure Management
Mitigation only
HIGH 8.8
CVE-2020-5371
Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability. An attacker, with ne…
Emc Isilon Onefs
after 8.2.2
HIGH 7.8
CVE-2020-15528
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of we…
Galaxy
Mitigation only
HIGH 7.8
CVE-2020-15529
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repa…
Galaxy
Mitigation only
HIGH 7.8
CVE-2020-15397
HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations und…
Hylafax\+
after 7.0.2
CRITICAL 9.4
CVE-2020-12041
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM th…
Sigma Spectrum Infusion System Firmware
Mitigation only
MEDIUM 5.3
CVE-2017-18916
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission res…
Mattermost Server
3.6.7 / 3.7.5+
MEDIUM 5.3
CVE-2016-11062
An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
Mattermost Server
3.5.1+
MEDIUM 5.3
CVE-2017-18896
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API versio…
Mattermost Server
4.0.5 / 4.1.1+
HIGH 8.8
CVE-2017-18886
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
Mattermost Server
4.1.2 / 4.2.1+
HIGH 8.1
CVE-2017-18894
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner au…
Mattermost Server
4.0.5 / 4.1.1+
MEDIUM 5.3
CVE-2018-21265
An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, au…
Mattermost Desktop
4.0.0+
MEDIUM 6.5
CVE-2020-10782
An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable …
Ansible Tower
Mitigation only
MEDIUM 5.3
CVE-2020-11911
The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.
Tcp\/ip
6.0.1.66+
HIGH 7.8
CVE-2020-13431
I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% su…
I2p
0.9.46+
HIGH 7.8
CVE-2020-5358
Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to inc…
Encryption
2.7+
HIGH 7.8
CVE-2020-5755
Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attac…
Endpoint Agents
9.0.28.48+
HIGH 7.8
CVE-2020-3961
VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe lo…
Horizon Client
5.4.3+
HIGH 7.8
CVE-2020-11613
Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation…
Mids\' Reborn Hero Designer
No fix yet
HIGH 7.8
CVE-2020-1170
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an …
Windows Defender
Patch available
HIGH 7.8
CVE-2020-13866
WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable f…
Wingate
No fix yet
HIGH 7.3
CVE-2020-13912
SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to …
Advanced Monitoring Agent
10.8.9+
HIGH 7.3
CVE-2020-13386
In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the SmartDraw 2020 installation folde…
Smartdraw 2020
No fix yet
MEDIUM 6.6
CVE-2020-12431
A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and nam…
Software Updater
1.5.6.16 / 3.3.8.0+
MEDIUM 5.3
CVE-2020-12831
An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empt…
Free Range Routing
after 7.3.1
HIGH 8.1
CVE-2020-8153
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
Group Folders
4.0.4+
HIGH 7.8
CVE-2020-5895
On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which allows processes or users on t…
Nginx Controller
3.4.0+
HIGH 7.5
CVE-2020-3312
A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attac…
Secure Firewall Management Center
Mitigation only
HIGH 8.1
CVE-2020-11443
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an update…
It Installer
4.6.10+