Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2020-17448
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use o…
Telegram Desktop
after 2.1.13
HIGH 7.5
CVE-2020-12780
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
Itop
2.7.1+
HIGH 8.8
CVE-2020-3386
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privile…
Data Center Network Manager
11.4+
CRITICAL 9.9
CVE-2020-3374
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author…
Sd Wan
18.4.5 / 19.2.2+
HIGH 8.8
CVE-2020-14486
An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which …
Openclinic Ga
Mitigation only
MEDIUM 6.5
CVE-2020-15126
In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User …
Parse Server
4.3.0+
HIGH 8.1
CVE-2020-15110
In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default se…
Kubespawner
0.12+
CRITICAL 9.8
CVE-2020-3140
A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain…
Prime License Manager
after 11.5
MEDIUM 5.9
CVE-2020-3150
A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote…
Rv110w Firmware
1.2.2.8 / 1.3.1.7+
HIGH 8.8
CVE-2020-2228
Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulner…
Gitlab Authentication
after 1.5
CRITICAL 9.1
CVE-2020-7692
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by…
Oauth Client Library For Java
1.31.0+
MEDIUM 5.3
CVE-2020-15513
The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.
Typo3 Forum
1.2.1+
HIGH 7.5
CVE-2020-5372
Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthent…
Emc Powerstore 1000 Firmware
1.0.1.0.5.002+
MEDIUM 5.3
CVE-2020-14196
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enfo…
Recursor
after 4.3.1
CRITICAL 9.1
CVE-2020-15084
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When al…
Express Jwt
after 5.3.3
CRITICAL 9.8
CVE-2020-12053
In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized withou…
Stealth
5.0.026+
HIGH 8.8
CVE-2020-13263
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unautho…
GitLab
12.9.8 / 12.10.7+
MEDIUM 6.5
CVE-2020-13277
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
GitLab
after 13.0.5
MEDIUM 5.3
CVE-2020-3360
A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sens…
Unified Ip Phone 6901 Firmware
after 12.8
MEDIUM 5.3
CVE-2020-3364
A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could all…
Ios Xr
Mitigation only
MEDIUM 6.5
CVE-2020-14214
Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can registe…
Zammad
3.3.1+
MEDIUM 6.5
CVE-2020-7499
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) …
Mtn6501 0001 Firmware
1.4.2+
HIGH 7.8
CVE-2020-0115
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a…
Android
Patch available
HIGH 7.5
CVE-2020-13834
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict …
Android
Mitigation only
MEDIUM 5.5
CVE-2020-3335
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive informa…
Application Policy Infrastructure Controller
1.1.2.20+
CRITICAL 9.8
CVE-2020-3227
A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenti…
Ios Xe
Mitigation only
HIGH 8.8
CVE-2020-3229EPSS 5%
A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remo…
Ios Xe
Patch available
CRITICAL 9.8
CVE-2020-11844
Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions …
Service Management Automation
Mitigation only
MEDIUM 6.5
CVE-2020-4249
IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to …
Security Identity Governance And Intelligence
Patch available
HIGH 7.5
CVE-2020-12391
Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that …
Firefox
76.0+