Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2020-11018
In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound r…
Debian Linux
after 2.0.0
MEDIUM 6.5
CVE-2020-11017
In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. Th…
Debian Linux
2.1.0+
MEDIUM 6.1
CVE-2020-11082
In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has b…
Debian Linux
1.2.1+
MEDIUM 5.3
CVE-2019-20807
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby,…
Debian Linux
8.1.0881+
HIGH 7.5
CVE-2020-3811
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
Debian Linux
Patch available
MEDIUM 5.5
CVE-2020-3812
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and d…
Debian Linux
Patch available
HIGH 8.2
CVE-2020-13113
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-afte…
Debian Linux
0.6.22+
CRITICAL 9.1
CVE-2020-13112
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crash…
Debian Linux
0.6.22+
MEDIUM 5.3
CVE-2020-8021
a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/acces…
Debian Linux
2.10.5+
HIGH 8.6
CVE-2020-8616EPSS 11%
A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, thro…
Debian Linux
after 9.17.1
HIGH 7.5
CVE-2020-12662
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NS…
Debian Linux
1.10.1+
HIGH 7.5
CVE-2020-12663
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
Debian Linux
1.10.1+
MEDIUM 5.9
CVE-2020-8617EPSS 93%
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfu…
Debian Linux
after 9.17.1
HIGH 7.8
CVE-2018-10756
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly exec…
Debian Linux
3.00+
MEDIUM 5.5
CVE-2020-3810
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafte…
Apt
2.1.2+
MEDIUM 5.0
CVE-2020-0093
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local informati…
Debian Linux
0.6.22+
MEDIUM 6.1
CVE-2020-8020
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code …
Debian Linux
2020-05-13+
MEDIUM 5.5
CVE-2020-12767
exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
Debian Linux
Patch available
MEDIUM 5.9
CVE-2020-11042
In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of…
Debian Linux
2.0.0+
MEDIUM 6.5
CVE-2020-12108
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
Debian Linux
2.1.31+
HIGH 7.5
CVE-2020-12672
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
Debian Linux
after 1.3.35
MEDIUM 6.5
CVE-2020-12626
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not consid…
Debian Linux
1.4.4+
MEDIUM 6.1
CVE-2020-12625
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScrip…
Debian Linux
1.4.4+
HIGH 8.1
CVE-2020-11027EPSS 14%
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to…
Debian Linux
3.7.33 / 3.8.33+
MEDIUM 6.1
CVE-2020-11029
In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scriptin…
Debian Linux
3.7.33 / 3.8.33+
CRITICAL 9.8
CVE-2020-11651 KEVEPSS 97%
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate…
Debian Linux
2019.2.4 / 3000.2+
MEDIUM 6.5
CVE-2020-11652 KEVEPSS 86%
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some meth…
Debian Linux
2019.2.4 / 3000.2+
HIGH 7.5
CVE-2020-12243
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
Debian Linux
2.4.50+
CRITICAL 9.8
CVE-2020-12278EPSS 5%
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate …
Debian Linux
0.28.4+
CRITICAL 9.8
CVE-2020-12279EPSS 5%
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short …
Debian Linux
0.28.4+