Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2016-20002
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's securit…
Rest\/json
after 7.x-1.5
CRITICAL 9.8
CVE-2016-20004
The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security …
Rest\/json
after 7.x-1.5
CRITICAL 9.8
CVE-2016-20005
The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's secu…
Rest\/json
after 7.x-1.5
MEDIUM 6.5
CVE-2020-26029
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization…
Zammad
3.4.1+
HIGH 8.8
CVE-2020-24674
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users c…
Symphony \+ Historian
Mitigation only
MEDIUM 5.4
CVE-2020-4794
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6…
Automation Workstream Services
Patch available
HIGH 7.8
CVE-2020-0479
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malic…
Android
Patch available
MEDIUM 6.3
CVE-2020-26250
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2…
Oauthenticator
0.12.2+
HIGH 7.5
CVE-2020-15246
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1…
October
1.0.469+
MEDIUM 6.5
CVE-2020-28053
HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key conf…
Consul
1.6.10 / 1.7.10+
HIGH 7.8
CVE-2020-28211
A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cau…
Ecostruxure Control Expert
Patch available
HIGH 7.5
CVE-2020-25699
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that …
Moodle
after 3.9.2
MEDIUM 5.3
CVE-2020-25701
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneousl…
Moodle
after 3.9.2
MEDIUM 5.3
CVE-2020-8278
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
Social
No fix yet
MEDIUM 6.5
CVE-2020-26223
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12…
Spree
3.7.13 / 4.0.5+
MEDIUM 5.5
CVE-2020-11209
Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, SD820, QCS603, QCS605, SDA855…
Sd820 Firmware
No fix yet
MEDIUM 6.6
CVE-2020-17049EPSS 14%
A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via…
Windows Server 2012
4.13.13 / 4.14.9+
MEDIUM 6.5
CVE-2020-25655
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f…
Advanced Cluster Management For Kubernetes
Mitigation only
MEDIUM 6.5
CVE-2020-24401
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisio…
Magento
2.3.5+
MEDIUM 6.5
CVE-2020-3592
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author…
Catalyst Sd Wan Manager
after 20.1.12
HIGH 7.8
CVE-2020-3600
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating syste…
Sd Wan
20.1.2 / 20.3.2+
HIGH 7.5
CVE-2020-15278
Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit allows Discord users with a hig…
Red Discord Bot
3.4.1+
MEDIUM 5.3
CVE-2020-3852
A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrectly ignored when determining …
Safari
13.0.5+
MEDIUM 6.5
CVE-2020-3578
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c…
Secure Firewall Threat Defense
6.3.0.6 / 6.4.0.10+
MEDIUM 5.3
CVE-2020-27609
BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data stora…
Bigbluebutton
after 2.2.28
MEDIUM 6.5
CVE-2020-6362
SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with othe…
Banking Services
Mitigation only
MEDIUM 5.3
CVE-2020-16904
<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p>
<p>An unauthenticated attacker who successfull…
Azure Functions
Patch available
HIGH 7.2
CVE-2020-12503EPSS 23%
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…
Es7510 Xt Firmware
No fix yet
CRITICAL 9.8
CVE-2020-27156
Veritas APTARE versions prior to 10.5 did not perform adequate authorization checks. This vulnerability could allow for remote code execution by an u…
Aptare
10.5+
CRITICAL 9.8
CVE-2020-13957EPSS 79%
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote co…
Solr
after 8.6.2