Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-28464
This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.
Djv
2.1.4+
CRITICAL 9.8
CVE-2020-20298
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to ex…
Zzzphp
No fix yet
HIGH 7.5
CVE-2020-28367
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags speci…
Go
1.14.12 / 1.15.5+
HIGH 7.5
CVE-2020-28366
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symb…
Go
1.14.12 / 1.15.5+
CRITICAL 9.8
CVE-2020-11851
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remot…
Arcsight Logger
7.1.1+
HIGH 8.8
CVE-2020-25538EPSS 10%
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web p…
Cmsuno
No fix yet
HIGH 8.8
CVE-2020-25557EPSS 10%
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs…
Cmsuno
No fix yet
CRITICAL 9.8
CVE-2020-7472
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9…
Sugarcrm
8.0.7 / 9.0.4+
HIGH 7.8
CVE-2020-17091
Microsoft Teams Remote Code Execution Vulnerability
Teams
Patch available
CRITICAL 9.8
CVE-2020-7373EPSS 45%
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.…
Vbulletin
after 5.6.2
HIGH 7.1
CVE-2020-7745
This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. …
Mintegraladsdk
6.6.0.0+
HIGH 8.8
CVE-2020-15252
In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet …
Xwiki
11.10.6 / 12.5+
CRITICAL 9.8
CVE-2020-8349
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ option…
Cloud Networking Operating System
10.10.6.0+
HIGH 7.5
CVE-2017-18924
oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is sim…
Oauth2 Server
after 3.1.1
HIGH 8.8
CVE-2020-24628
A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
Kvm Ip Console Switch G2 Firmware
2.8.3+
CRITICAL 9.8
CVE-2020-18185
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
Pluxml
No fix yet
HIGH 8.8
CVE-2020-26124EPSS 67%
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, beca…
Openmediavault
4.1.36 / 5.5.12+
CRITICAL 9.8
CVE-2020-15227EPSS 34%
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters…
Debian Linux
2.0.19 / 2.1.13+
HIGH 7.2
CVE-2020-8243 KEVEPSS 91%
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform …
Connect Secure
after 9.0
HIGH 8.1
CVE-2019-20920
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allow…
Handlebars
3.0.8 / 4.5.3+
CRITICAL 9.8
CVE-2020-15371
Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation …
Fabric Operating System
Mitigation only
HIGH 7.2
CVE-2019-7177
Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.
Pexip Infinity
20.1+
MEDIUM 6.7
CVE-2020-3513
Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation…
Ios Xe
Mitigation only
MEDIUM 6.7
CVE-2020-3416
Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation…
Ios Xe
Mitigation only
HIGH 8.8
CVE-2020-11803EPSS 8%
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could le…
Spamtitan
No fix yet
HIGH 8.8
CVE-2020-11804EPSS 7%
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection c…
Spamtitan
No fix yet
MEDIUM 6.6
CVE-2020-15171
In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servle…
Xwiki
11.10.5 / 12.2.1+
HIGH 7.2
CVE-2020-6318EPSS 6%
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of thi…
Abap Platform
No fix yet
HIGH 7.8
CVE-2020-7381
In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by a…
Nexpose
6.6.40+
HIGH 8.6
CVE-2020-15167
In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to …
Miller
No fix yet