Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-21051
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trus…
Android
Mitigation only
CRITICAL 9.8
CVE-2017-18652
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic librari…
Android
Mitigation only
HIGH 7.5
CVE-2020-11593
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data …
Cipace
9.1+
MEDIUM 5.3
CVE-2020-10960
In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user …
Mediawiki
1.34.1+
MEDIUM 6.5
CVE-2020-1958
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali…
Druid
Mitigation only
MEDIUM 6.1
CVE-2020-3884
An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbi…
Mac Os X
10.15.4+
MEDIUM 6.1
CVE-2020-11441
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on a…
phpMyAdmin
No fix yet
HIGH 8.8
CVE-2020-6982
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.
Win Pak
after 4.7.2
CRITICAL 9.8
CVE-2020-7475
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in…
Ecostruxure Control Expert
3.10 / 3.20+
CRITICAL 9.8
CVE-2013-7487
On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote attackers to e…
Dvr04b Firmware
No fix yet
MEDIUM 6.1
CVE-2019-18860EPSS 6%
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
Debian Linux
4.9+
MEDIUM 6.1
CVE-2019-12416
we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrat…
Deltaspike
after 1.9.2
HIGH 8.8
CVE-2020-8468 KEVEPSS 6%
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulne…
Apex One
Patch available
HIGH 7.2
CVE-2019-11073EPSS 6%
A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sa…
Prtg Network Monitor
19.4.54.1506+
MEDIUM 6.5
CVE-2020-6858
Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a res…
Styx
after 0.7.10
HIGH 8.6
CVE-2020-5259
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inje…
Dojox
1.11.10 / 1.12.8+
HIGH 7.5
CVE-2019-19614
An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the …
Raquest
Mitigation only
CRITICAL 9.8
CVE-2020-9757EPSS 73%
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers co…
Craft Cms
3.3.0+
MEDIUM 6.5
CVE-2020-5249
In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header, an attacker can use a carria…
Puma
after 4.3.2
HIGH 7.5
CVE-2020-5247
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newli…
Puma
after 4.3.2
MEDIUM 5.4
CVE-2020-9382
An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page …
Widgets
after 1.4.0
HIGH 8.8
CVE-2020-5245
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service a…
Dropwizard Validation
1.3.19 / 2.0.2+
CRITICAL 9.8
CVE-2014-4678EPSS 5%
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…
Ansible
1.6.4+
MEDIUM 6.3
CVE-2019-10792
bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.protot…
Bodymen
1.1.1+
MEDIUM 6.3
CVE-2019-10793
dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying properties of Object.prototy…
Dot Object
2.1.3+
MEDIUM 6.3
CVE-2019-10794
All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Objec…
Component Flatten
Patch available
MEDIUM 6.3
CVE-2019-10795
undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying properties of Object.prototyp…
Undefsafe
2.0.3+
CRITICAL 9.8
CVE-2014-4966
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which …
Ansible
1.6.7+
CRITICAL 9.8
CVE-2014-4967
Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib…
Ansible
1.6.7+
CRITICAL 9.1
CVE-2014-7236EPSS 56%
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenable…
Twiki
after 5.1.4