Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2020-8218 KEVEPSS 32%
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution …
Connect Secure
after 9.0
CRITICAL 9.8
CVE-2020-12812 KEVEPSS 49%
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succe…
Fortios
6.0.10 / 6.2.4+
HIGH 7.5
CVE-2020-3452 KEVEPSS 100%
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c…
Adaptive Security Appliance Software
6.2.3.16 / 6.3.0.6+
HIGH 8.8
CVE-2020-11978 KEVEPSS 99%
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D…
Airflow
1.10.11+
CRITICAL 9.8
CVE-2020-14644 KEVEPSS 95%
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.…
Weblogic Server
Mitigation only
CRITICAL 10.0
CVE-2020-1350 KEVEPSS 91%
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Serve…
Windows Server 2008
Patch available
HIGH 7.8
CVE-2020-1147 KEVEPSS 94%
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source m…
.net Core
after 16.6
CRITICAL 9.0
CVE-2020-1040 KEVEPSS 7%
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user …
Windows Server 2008
Patch available
CRITICAL 10.0
CVE-2020-6287 KEVEPSS 95%
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.8
CVE-2020-10987 KEVEPSS 80%
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the device…
Ac15 Firmware
Mitigation only
MEDIUM 6.5
CVE-2020-8195 KEVEPSS 33%
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix S…
Application Delivery Controller Firmware
1.0.0.137 / 10.2.7+
MEDIUM 6.5
CVE-2020-8193 KEVEPSS 88%
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW…
Application Delivery Controller Firmware
10.2.7 / 10.5-70.18+
HIGH 8.8
CVE-2020-9377 KEVEPSS 21%
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are n…
Dir 610 Firmware
Patch available
CRITICAL 9.8
CVE-2020-15505 KEVEPSS 100%
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0,…
Core
2.0.0.2 / 9.7.3+
CRITICAL 9.8
CVE-2020-5902 KEVEPSS 100%
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TM…
Big Ip Access Policy Manager
11.6.5.2 / 12.1.5.2+
CRITICAL 9.8
CVE-2020-15415 KEVEPSS 85%
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell …
Vigor3900 Firmware
1.5.1+
CRITICAL 9.8
CVE-2020-15069 KEVEPSS 11%
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access.…
Xg Firewall Firmware
17.5+
CRITICAL 10.0
CVE-2020-2021 KEV
When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (uncheck…
Pan Os
8.1.15 / 9.0.9+
MEDIUM 5.4
CVE-2020-11899 KEVEPSS 19%
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
Tcp\/ip
6.0.1.66+
HIGH 7.8
CVE-2020-0986 KEVEPSS 16%
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of P…
Windows 10 1507
Patch available
HIGH 8.8
CVE-2020-9818 KEV
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5.…
Ipados
6.2.5 / 12.4.7+
MEDIUM 6.1
CVE-2020-13965 KEVEPSS 77%
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am…
Debian Linux
1.3.12 / 1.4.5+
HIGH 7.8
CVE-2020-9859 KEV
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 S…
Ipados
6.2.6 / 10.15.5+
HIGH 7.5
CVE-2020-5410 KEVEPSS 96%
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitra…
Spring Cloud Config
2.1.9 / 2.2.3+
HIGH 7.2
CVE-2020-8816 KEVEPSS 78%
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
Pi Hole
after 4.3.2
HIGH 8.8
CVE-2020-1956 KEVEPSS 97%
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is …
Kylin
after 2.6.5
HIGH 7.0
CVE-2020-1054 KEVEPSS 53%
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker…
Windows 10 1507
Patch available
HIGH 7.2
CVE-2020-5741 KEVEPSS 73%
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
Media Server
1.19.3+
CRITICAL 9.1
CVE-2020-4428 KEVEPSS 62%
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F…
Data Risk Manager
after 2.0.4
CRITICAL 9.8
CVE-2020-4427 KEVEPSS 70%
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with…
Data Risk Manager
after 2.0.6.1