Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2020-0087
In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lead to local information disclo…
Android
Mitigation only
HIGH 7.8
CVE-2020-0036
In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions bypass. This could lead to loc…
Android
Mitigation only
HIGH 8.8
CVE-2020-2134
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor…
Script Security
after 1.70
HIGH 8.8
CVE-2020-2135
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement Gr…
Script Security
after 1.70
MEDIUM 5.3
CVE-2020-5251
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex o…
Parse Server
4.1.0+
HIGH 7.5
CVE-2020-9381
controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be expl…
Total.js Cms
Patch available
HIGH 8.1
CVE-2014-7914
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote att…
Android
5.1+
HIGH 8.8
CVE-2020-5242
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary comma…
Openhab
2.5.2+
MEDIUM 5.5
CVE-2020-7251
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows loca…
Endpoint Security
10.6.1+
HIGH 8.8
CVE-2020-5239
In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Ma…
Mailu
1.7+
HIGH 8.8
CVE-2020-6380
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer proc…
Chrome
79.0.3945.130+
HIGH 7.5
CVE-2020-5318
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vuln…
Emc Isilon Onefs
Mitigation only
MEDIUM 6.8
CVE-2013-2673
Brother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate attackers to gain unauthorized …
Mfc 9970cdw Firmware
No fix yet
MEDIUM 5.3
CVE-2020-7955
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended…
Consul
1.6.2+
CRITICAL 9.8
CVE-2013-2198
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted…
Login Security
after 7.x-1.3
CRITICAL 9.1
CVE-2013-1350
Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities
Network Management System
2.1.0+
HIGH 7.5
CVE-2013-2574EPSS 30%
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could l…
Fi8620 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-8086
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() f…
Debian Linux
after 2020-01-27
HIGH 8.1
CVE-2013-4862
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via …
Veralite Firmware
No fix yet
MEDIUM 6.5
CVE-2019-5474
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden witho…
GitLab
11.11.6 / 12.0.4+
HIGH 7.8
CVE-2019-17190
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the Avast…
Secure Browser
No fix yet
HIGH 8.8
CVE-2020-2097
Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read acc…
Sounds
after 0.5
HIGH 7.5
CVE-2012-3822
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' creden…
Campaign Enterprise
11.0.551+
HIGH 7.4
CVE-2019-17014
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-o…
Firefox
71.0+
HIGH 7.1
CVE-2016-6591
A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local m…
Norton App Lock
after 1.0.3.186
HIGH 8.8
CVE-2019-14843
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a mal…
Single Sign On
Patch available
HIGH 7.3
CVE-2019-6855
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M3…
Ecostruxure Control Expert
3.10 / 14.1+
MEDIUM 6.5
CVE-2014-0169
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could all…
Jboss Enterprise Application Platform
Mitigation only
HIGH 8.8
CVE-2010-3782
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.
Obs Server
1.7.7+
HIGH 7.5
CVE-2019-20213
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnc…
Dir 859 Firmware
after 3.12b04