Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-8149
Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.
Logkitty
0.7.1+
HIGH 8.8
CVE-2020-11057
In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while edi…
Xwiki
after 11.10.2
HIGH 7.2
CVE-2020-6248
SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while execut…
Adaptive Server Enterprise Backup Server
Mitigation only
HIGH 8.8
CVE-2020-6262
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows …
Application Server
Mitigation only
HIGH 8.8
CVE-2020-6243
Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks …
Adaptive Server Enterprise
Mitigation only
CRITICAL 9.8
CVE-2020-10176
ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.
Yale Wipc 301w Firmware
2.x.2.43+
MEDIUM 6.3
CVE-2020-11056
In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which…
Sprout Forms
3.9.0+
CRITICAL 9.8
CVE-2020-7609
node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled b…
Node Rules
5.0.0+
HIGH 8.8
CVE-2020-5739EPSS 5%
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up s…
Gxp1610 Firmware
after 1.0.4.152
MEDIUM 6.1
CVE-2019-19089
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be i…
Esoms
after 6.0.3
CRITICAL 9.8
CVE-2019-9163
The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML ob…
Command Client
2.7.2+
CRITICAL 9.8
CVE-2020-10948EPSS 7%
Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a differen…
Alienform2
No fix yet
HIGH 8.8
CVE-2020-5558
CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.
Cutenews
No fix yet
CRITICAL 9.8
CVE-2020-5553
mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.
Mailform
No fix yet
HIGH 7.1
CVE-2020-10684
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a …
Ansible
2.7.17 / 2.8.9+
CRITICAL 9.8
CVE-2020-7480
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files…
Andover Continuum 9680 Firmware
Mitigation only
HIGH 8.8
CVE-2020-6650
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code …
Ups Companion
after 1.05
MEDIUM 6.7
CVE-2020-8140
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set i…
Desktop
2.6.3+
CRITICAL 9.8
CVE-2020-8137
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.
Blamer
1.0.1+
HIGH 7.5
CVE-2019-16108
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
Phpbb
Patch available
HIGH 7.2
CVE-2019-18582
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side t…
Emc Data Protection Advisor
Mitigation only
CRITICAL 9.8
CVE-2019-19208EPSS 19%
Codiad Web IDE through 2.8.4 allows PHP Code injection.
Codiad
after 2.8.4
HIGH 8.8
CVE-2020-8141
The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they …
Dot
No fix yet
HIGH 7.2
CVE-2020-10389
admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any PO…
Phpkb
No fix yet
CRITICAL 9.8
CVE-2020-5203
In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GE…
Fat Free Framework
Patch available
HIGH 7.7
CVE-2020-5258
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to in…
Debian Linux
1.11.10 / 1.12.8+
HIGH 8.6
CVE-2020-5259
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inje…
Dojox
1.11.10 / 1.12.8+
CRITICAL 9.8
CVE-2020-10257EPSS 9%
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for P…
Addons
1.0.1 / 1.0.1.2001+
MEDIUM 6.5
CVE-2020-9530
An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of…
Miui Firmware
Mitigation only
HIGH 7.8
CVE-2019-3695
A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Lin…
Pcp
3.11.9-5.8.1 / 3.11.9-6.14.1+