Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-3811
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
Debian Linux
Patch available
MEDIUM 5.3
CVE-2019-20801
An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin request…
Documents
6.9.7+
HIGH 7.8
CVE-2020-0097
In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead t…
Android
Patch available
MEDIUM 6.3
CVE-2020-12875
Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitiv…
Aptare
10.4+
HIGH 7.5
CVE-2020-12876
Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows …
Aptare
10.4+
HIGH 8.8
CVE-2020-1998
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions …
Pan Os
7.1.26 / 8.1.13+
HIGH 7.5
CVE-2020-8151
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to acce…
Active Resource
5.1.1+
HIGH 8.8
CVE-2020-12691
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a pro…
Ubuntu Linux
15.0.1+
MEDIUM 5.3
CVE-2020-7921
Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credent…
MongoDB
3.6.18 / 4.0.15+
HIGH 7.8
CVE-2020-5343
Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vuln…
Os Recovery Image For Microsoft Windows 10
2019-12-20+
HIGH 7.5
CVE-2020-12477
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For…
Teampass
No fix yet
HIGH 8.8
CVE-2020-10786
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron…
Vesta Control Panel
after 0.9.8-26
HIGH 8.8
CVE-2020-11753
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to …
Nexus Repository Manager 3
Patch available
MEDIUM 6.5
CVE-2020-5287
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.
Prestashop
1.7.6.5+
MEDIUM 6.5
CVE-2020-5288
"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5.
Prestashop
1.7.6.5+
MEDIUM 6.5
CVE-2020-5293
In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific pr…
Prestashop
1.7.6.5+
MEDIUM 6.5
CVE-2020-5279
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-d…
Prestashop
1.7.6.5+
HIGH 8.8
CVE-2020-0981
A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the v…
Windows 10
Patch available
HIGH 8.8
CVE-2020-11707
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result,…
Provide Ftp Server
after 13.1
HIGH 7.5
CVE-2018-21039
An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka Quic…
Android
Mitigation only
HIGH 8.4
CVE-2018-21082
An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use scr…
Android
Mitigation only
MEDIUM 5.3
CVE-2020-11628
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, AC…
Ejbca
6.15.2.6 / 7.3.1.2+
MEDIUM 6.8
CVE-2020-8142
A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like…
Revive Adserver
5.0.5+
HIGH 8.1
CVE-2020-5275
In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and s…
Symfony
4.4.7 / 5.0.7+
MEDIUM 6.5
CVE-2020-10510
Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a …
Ehrd
Mitigation only
MEDIUM 6.6
CVE-2020-1796
There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successf…
Mate 20 Firmware
after 10.0.0.203
HIGH 8.8
CVE-2019-11361
Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full ap…
Manageengine Remote Access Plus
Mitigation only
HIGH 8.8
CVE-2020-10239
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.
Joomla\!
3.9.16+
HIGH 8.5
CVE-2020-5240
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does …
Wagtail 2fa
1.4.1+
CRITICAL 9.8
CVE-2020-10534
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-…
Mediawiki
after 1.34.0