Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2020-0448
In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. …
Android
Patch available
MEDIUM 5.5
CVE-2020-0437
In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial …
Android
Patch available
HIGH 7.8
CVE-2020-0439
In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to…
Android
Patch available
CRITICAL 9.8
CVE-2020-28036EPSS 5%
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
WordPress
5.5.2+
CRITICAL 9.8
CVE-2020-27998
An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, T…
Fastreport
2020.4.0+
HIGH 7.5
CVE-2020-16260
Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote …
Winston Firmware
No fix yet
HIGH 8.1
CVE-2020-26649
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
Atomxcms 2
No fix yet
MEDIUM 6.1
CVE-2020-10746
A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to controls via both REST and Hot…
Infinispan Server Runtime
Mitigation only
CRITICAL 9.1
CVE-2019-19885
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and …
Com465ip Firmware
4.2.0+
MEDIUM 5.3
CVE-2020-14185
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOper…
Jira
7.13.18 / 8.5.9+
MEDIUM 5.5
CVE-2020-0419
In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permissi…
Android
Patch available
HIGH 7.8
CVE-2020-0420
In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escala…
Android
Patch available
MEDIUM 5.5
CVE-2020-0378
In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local information disclosure of location data…
Android
Mitigation only
MEDIUM 5.5
CVE-2020-0246
In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local information disclosure of EID data…
Android
Mitigation only
MEDIUM 6.5
CVE-2020-15251
In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is a…
Channelmgnt
1.0.3+
HIGH 7.5
CVE-2020-26598
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management component could allow an unauthorized…
Android
Mitigation only
HIGH 8.8
CVE-2020-13296
An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tok…
GitLab
13.0.14 / 13.1.8+
HIGH 8.2
CVE-2020-24718
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restr…
FreeBSD
after 11.2
MEDIUM 6.8
CVE-2020-3524
A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cisco ASR 920 Series Aggregation…
Ios Xe Rom Monitor
15.6 / 16.2+
HIGH 8.8
CVE-2020-3400
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize parts of the web UI for which…
Ios Xe
Mitigation only
HIGH 7.8
CVE-2020-0299
In Bluetooth, there is a possible spoofing of bluetooth device metadata due to a missing permission check. This could lead to local escalation of pri…
Android
Mitigation only
MEDIUM 5.5
CVE-2020-0316
In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privile…
Android
Mitigation only
MEDIUM 5.5
CVE-2020-0327
In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution pri…
Android
Mitigation only
MEDIUM 5.5
CVE-2020-0276
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additi…
Android
Mitigation only
MEDIUM 5.5
CVE-2020-0284
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additi…
Android
Mitigation only
MEDIUM 5.5
CVE-2020-0285
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additi…
Android
Mitigation only
HIGH 7.8
CVE-2020-0298
In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing permission check. This could lead to local escalation of priv…
Android
Mitigation only
MEDIUM 5.5
CVE-2020-0265
In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local information disclosure with no ad…
Android
Mitigation only
HIGH 7.8
CVE-2020-0089
In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding audio settings with no additiona…
Android
Mitigation only
HIGH 7.8
CVE-2020-0375
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setti…
Android
Mitigation only