Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2020-25506 KEVEPSS 100%
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code exec…
Dns 320 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-29557 KEVEPSS 54%
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achi…
Dir 825 R1 Firmware
after 3.0.1
HIGH 7.8
CVE-2021-3156 KEVEPSS 99%
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudo…
Fedora
1.8.32 / 1.9.5+
HIGH 7.5
CVE-2020-36193 KEVEPSS 71%
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue …
Archive Tar
7.78 / 8.9.13+
HIGH 8.8
CVE-2020-6572 KEVEPSS 11%
Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
Chrome
81.0.4044.92+
HIGH 7.8
CVE-2021-1647 KEVEPSS 39%
Microsoft Defender Remote Code Execution Vulnerability
Windows Defender
Patch available
CRITICAL 9.8
CVE-2021-3129 KEVEPSS 100%
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure u…
Ignition
2.5.2+
CRITICAL 9.6
CVE-2020-16017 KEV
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potent…
Chrome
86.0.4240.198+
HIGH 8.8
CVE-2020-16013 KEV
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a cra…
Chrome
86.0.4240.198+
HIGH 7.5
CVE-2020-17519 KEVEPSS 98%
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of t…
Flink
1.11.3+
CRITICAL 9.8
CVE-2020-10148 KEVEPSS 92%
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou…
Orion Platform
Mitigation only
MEDIUM 6.1
CVE-2020-35730 KEVEPSS 33%
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-ma…
Fedora
1.2.13 / 1.3.16+
CRITICAL 9.8
CVE-2020-29583 KEVEPSS 90%
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can …
Usg20 Vpn Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-29574 KEV
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements…
Cyberoamos
after 2020-12-04
CRITICAL 9.8
CVE-2020-17530 KEVEPSS 96%
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.…
Struts
2.5.30+
HIGH 8.4
CVE-2020-17144 KEVEPSS 37%
Microsoft Exchange Remote Code Execution Vulnerability
Exchange Server
Patch available
MEDIUM 5.5
CVE-2020-27950 KEVEPSS 16%
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 202…
Ipados
5.3.9 / 6.2.9+
HIGH 7.8
CVE-2020-27932 KEVEPSS 10%
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.…
Icloud
5.3.9 / 6.2.9+
HIGH 7.8
CVE-2020-27930 KEVEPSS 22%
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS…
Ipados
5.3.9 / 6.2.9+
CRITICAL 9.1
CVE-2020-4006 KEVEPSS 17%
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Identity Manager
after 8.2
HIGH 8.8
CVE-2020-13671 KEV
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and …
Drupal
7.74 / 8.8.11+
HIGH 7.8
CVE-2020-28949 KEVEPSS 85%
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to o…
Archive Tar
1.4.12 / 7.75+
HIGH 7.8
CVE-2020-17087 KEVEPSS 5%
Windows Kernel Local Elevation of Privilege Vulnerability
Windows 10 1507
Patch available
CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…
Airflow
1.10.11+
CRITICAL 9.8
CVE-2020-16846 KEVEPSS 100%
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel…
Debian Linux
2015.8.10 / 2015.8.13+
CRITICAL 9.6
CVE-2020-16010 KEVEPSS 6%
Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to p…
Chrome
86.0.4240.185+
HIGH 8.8
CVE-2020-16009 KEVEPSS 49%
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a cra…
Chrome
86.0.241 / 86.0.622.63+
CRITICAL 9.6
CVE-2020-15999 KEVEPSS 44%
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a craft…
Chrome
2.10.4 / 86.0.4240.111+
CRITICAL 9.8
CVE-2020-14750 KEVEPSS 99%
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6…
Weblogic Server
Patch available
MEDIUM 6.1
CVE-2018-19953 KEVEPSS 24%
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the …
Qts
4.2.6 / 4.3.3.1161+