Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2020-26293
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before versi…
Htmlsanitizer
5.0.372+
CRITICAL 9.9
CVE-2020-10208
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B …
Ak45x Firmware
No fix yet
HIGH 8.8
CVE-2020-16268
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair o…
Client
Mitigation only
CRITICAL 10.0
CVE-2020-26282
BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Prox…
Browserup Proxy
2.1.2+
MEDIUM 6.1
CVE-2020-35669
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, …
Http
after 0.12.2
HIGH 7.8
CVE-2020-35608
A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted …
Azure Sphere
No fix yet
HIGH 8.8
CVE-2020-27687
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-…
Thingsboard
3.2+
HIGH 7.8
CVE-2020-8177
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file wh…
Curl
after 7.70.0
HIGH 8.8
CVE-2020-25967
The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.
Fastadmin
No fix yet
MEDIUM 6.4
CVE-2020-26260
BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit…
Bookstack
0.30.5+
HIGH 7.5
CVE-2020-29655
An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaste…
Rt Ac88u Firmware
3.1.0.108+
MEDIUM 5.4
CVE-2020-14193
Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF…
Automation For Jira
7.1.15+
HIGH 8.1
CVE-2020-26238
Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.…
Cron Utils
9.1.3+
CRITICAL 9.8
CVE-2020-13942EPSS 68%
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…
Unomi
1.5.2+
MEDIUM 6.1
CVE-2020-26081
Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-sit…
Iot Field Network Director
4.6.1+
MEDIUM 6.1
CVE-2020-26884
RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vuln…
Archer
after 6.8.0.3
MEDIUM 6.1
CVE-2020-27627
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
Teamcity
2020.1.2+
HIGH 8.8
CVE-2020-26222
Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Java, .NET, Elm and Go. In Depen…
Dependabot
0.125.1+
HIGH 7.0
CVE-2020-15238
Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argume…
Debian Linux
2.1.4+
HIGH 7.2
CVE-2020-15244
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to…
Magento
20.0.4+
HIGH 7.6
CVE-2020-7749
This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}})…
Osm Static Maps
Patch available
HIGH 7.3
CVE-2020-15255
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treat…
Time Tracker
1.19.23.5325+
HIGH 8.8
CVE-2020-15252
In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet …
Xwiki
11.10.6 / 12.5+
MEDIUM 5.3
CVE-2020-25768
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end …
Contao
4.4.52 / 4.9.6+
CRITICAL 9.8
CVE-2020-15227EPSS 34%
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters…
Debian Linux
2.0.19 / 2.1.13+
MEDIUM 6.5
CVE-2020-26137
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characte…
Urllib3
1.25.9+
CRITICAL 9.8
CVE-2020-21523
A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the…
Halo
No fix yet
HIGH 7.2
CVE-2020-26116EPSS 6%
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker contro…
Python
3.5.10 / 3.6.12+
MEDIUM 5.5
CVE-2020-25596
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves va…
Fedora
after 4.14.0
HIGH 8.4
CVE-2020-16875EPSS 47%
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p>
<p>An attacker who s…
Exchange Server
Patch available