Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-5396
VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed…
Gemfire
1.10.2 / 1.11.1+
HIGH 7.5
CVE-2020-14520
The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all version…
Ignition Gateway
8.0.13+
MEDIUM 6.5
CVE-2020-15102
In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The …
Dashboard Products
2.1.0+
MEDIUM 6.5
CVE-2020-14491
OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to a…
Openclinic Ga
Mitigation only
MEDIUM 5.5
CVE-2020-0107
In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local …
Android
Patch available
HIGH 7.8
CVE-2020-0227
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to loca…
Android
Patch available
CRITICAL 9.8
CVE-2020-14001
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such …
Kramdown
2.3.0+
MEDIUM 6.7
CVE-2020-15780
An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be us…
Linux Kernel
5.7.7+
MEDIUM 5.3
CVE-2020-15001
An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set option…
Yubikey 5 Nfc Firmware
after 5.3.1
HIGH 7.5
CVE-2020-5368
Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vul…
Vxrail D560f Firmware
Mitigation only
HIGH 8.8
CVE-2020-15518
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged user…
Veeam Availability Suite
10.0+
MEDIUM 5.3
CVE-2020-15080
In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. …
Prestashop
1.7.6.6+
MEDIUM 5.4
CVE-2020-2204
A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the glob…
Fortify On Demand
after 5.0.1
HIGH 7.8
CVE-2020-15360
com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
Docker Desktop
No fix yet
MEDIUM 5.9
CVE-2020-4413
IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T…
Security Secret Server
10.8+
MEDIUM 5.4
CVE-2020-5345
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMa…
Emc Unisphere For Powermax
9.1.0.17+
HIGH 7.8
CVE-2020-14971
Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them…
Pi Hole
after 5.0
CRITICAL 9.8
CVE-2020-14944EPSS 6%
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeo…
Bsa Radar
after 1.6.7234.24750
HIGH 7.5
CVE-2020-14969
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, reveal…
Misp
Patch available
HIGH 7.5
CVE-2019-20885
An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
Mattermost Server
5.8.0+
CRITICAL 9.8
CVE-2018-21251
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the param…
Mattermost Server
5.1.1+
MEDIUM 5.3
CVE-2018-21257
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) vi…
Mattermost Server
5.1.0+
MEDIUM 5.3
CVE-2020-3245
A vulnerability in the web application of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to creat…
Smart Software Manager On Prem
8-202004+
MEDIUM 5.4
CVE-2020-14213
In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).
Zammad
3.3.1+
HIGH 7.8
CVE-2020-0202
In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing system traces due to a missing pe…
Android
Patch available
MEDIUM 5.5
CVE-2020-0177
In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privilege to change network connectio…
Android
Patch available
MEDIUM 5.5
CVE-2020-0178
In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This could lead to local informatio…
Android
Patch available
HIGH 7.8
CVE-2020-0137
In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This …
Android
Patch available
HIGH 8.8
CVE-2020-13445
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not r…
Liferay Portal
Patch available
HIGH 8.8
CVE-2020-13270
Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on rest…
GitLab
11.9.8 / 12.9.8+