Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2020-10858
Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.
Zulip Desktop
5.0.0+
MEDIUM 6.5
CVE-2020-29604
An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues…
Mantisbt
2.24.4+
MEDIUM 5.9
CVE-2020-4816
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTT…
Cloud Pak For Security
Patch available
MEDIUM 5.5
CVE-2020-7343
Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulatin…
Agent
5.7.1+
HIGH 7.5
CVE-2021-21246EPSS 49%
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that o…
Onedev
4.0.3+
HIGH 8.8
CVE-2020-27220
The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control mess…
Hono
after 1.4.4
MEDIUM 6.7
CVE-2020-9209
There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located improperly. It does not apply the …
Smc2.0 Firmware
Mitigation only
MEDIUM 5.3
CVE-2021-23123
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublishe…
Joomla\!
after 3.9.23
MEDIUM 6.5
CVE-2021-21468
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allow…
Business Warehouse
No fix yet
MEDIUM 5.3
CVE-2020-5022
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai…
Spectrum Protect Plus
10.1.7+
MEDIUM 6.5
CVE-2020-16027
Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malic…
Chrome
87.0.4280.66+
HIGH 8.8
CVE-2020-16029
Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a craft…
Chrome
87.0.4280.66+
HIGH 8.8
CVE-2020-35745
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of us…
Hospital Management System
No fix yet
HIGH 7.5
CVE-2020-29160
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.
Zammad
3.5.1+
HIGH 8.8
CVE-2020-25917
Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "hel…
Notouch Center
4.4.68+
MEDIUM 6.5
CVE-2019-11783
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote auth…
Odoo
after 14.0
MEDIUM 6.5
CVE-2019-11784
Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authent…
Odoo
after 14.0
HIGH 8.8
CVE-2020-35625
An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace c…
Mediawiki
after 1.35.1
MEDIUM 5.9
CVE-2020-4841
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T…
Security Secret Server
Patch available
HIGH 8.8
CVE-2020-13512
A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted …
Cam
No fix yet
HIGH 8.8
CVE-2020-13513
A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted …
Cam
No fix yet
HIGH 8.8
CVE-2020-13514
A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted …
Cam
No fix yet
HIGH 8.8
CVE-2020-13515
A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted I/O request…
Cam
No fix yet
HIGH 8.8
CVE-2020-13519
A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted I/O request…
Cam
No fix yet
HIGH 8.8
CVE-2020-29479
An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for t…
Debian Linux
after 4.14.0
MEDIUM 6.7
CVE-2020-27777
A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest sy…
Linux Kernel
4.14.204 / 4.19.155+
HIGH 7.8
CVE-2020-27052
In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a permissions bypass. This cou…
Android
Patch available
HIGH 7.8
CVE-2020-27054
In onFactoryReset of BluetoothManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no addi…
Android
Patch available
MEDIUM 5.5
CVE-2020-27032
In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing permission check. This could lead…
Android
Mitigation only
MEDIUM 5.5
CVE-2020-0497
In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information disclosure with no additional e…
Android
Mitigation only