Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2020-9470
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may vi…
Wing Ftp Server
after 6.2.5
HIGH 7.8
CVE-2020-8635
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local…
Wing Ftp Server
No fix yet
HIGH 7.8
CVE-2020-4278
IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges…
Platform Lsf
Patch available
CRITICAL 9.4
CVE-2020-8768
An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanis…
Ilc 2050 Bi Firmware
1.2.3+
HIGH 7.8
CVE-2020-1704
An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens…
Openshift Service Mesh
1.0.8+
CRITICAL 9.8
CVE-2020-9024
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and…
Vantage Velocity Firmware
No fix yet
MEDIUM 5.4
CVE-2020-7050
Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatic…
Codoforum
after 4.8.4
HIGH 8.1
CVE-2019-11215
In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.data…
Itop
after 2.6.0
HIGH 7.8
CVE-2020-0563
Improper permissions in the installer for Intel(R) MPSS before version 3.8.6 may allow an authenticated user to potentially enable escalation of priv…
Manycore Platform Software Stack
3.8.6+
MEDIUM 6.1
CVE-2020-7051
Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lac…
Codoforum
after 4.8.4
HIGH 7.8
CVE-2020-0668EPSS 26%
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privile…
Windows 10
Patch available
HIGH 8.0
CVE-2019-13321
This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User inte…
Mi Browser
10.4.0+
MEDIUM 5.3
CVE-2011-4912
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
Joomla\!
after 1.5.13
HIGH 7.8
CVE-2019-20358
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the…
Anti Threat Toolkit
after 1.62.0.1218
HIGH 7.8
CVE-2019-7656
A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. T…
Streaming Engine
after 4.8.0
HIGH 7.8
CVE-2019-19363
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation.…
Generic Pcl5 Driver
4.26+
MEDIUM 5.5
CVE-2019-19894
In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non…
Easyinstall
No fix yet
HIGH 7.8
CVE-2019-19895
In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker c…
Easyinstall
No fix yet
CRITICAL 9.8
CVE-2012-2087
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
Ispconfig
No fix yet
MEDIUM 5.5
CVE-2019-14629
Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable information disclosure via local…
Data Analytics Acceleration Library
2020+
HIGH 8.8
CVE-2019-3683
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/k…
Openstack Cloud
2019-02-18+
HIGH 7.8
CVE-2019-20327
Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrappe…
Centreon
after 19.10
HIGH 7.8
CVE-2019-16784
In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software usin…
Pyinstaller
3.6+
MEDIUM 5.5
CVE-2019-19727
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
Slurm
18.08.9 / 19.05.5+
MEDIUM 6.1
CVE-2019-19736
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potent…
Yetishare
after 4.5.3
HIGH 7.8
CVE-2019-3467
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive A…
Debian Lan Config
0.26 / 2.11.10+
CRITICAL 9.0
CVE-2019-19915
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or i…
301 Redirects
2.45+
MEDIUM 5.5
CVE-2019-19341
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both …
Ansible Tower
3.6.2+
CRITICAL 9.8
CVE-2019-8256
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitat…
Coldfusion
Mitigation only
HIGH 7.8
CVE-2019-19882
shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid p…
Shadow
Patch available