Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2020-35497
A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email an…
Virtualization
after 4.4.3
HIGH 7.1
CVE-2020-27781
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open S…
Ceph
14.2.16 / 15.2.8+
MEDIUM 5.3
CVE-2020-10770EPSS 70%
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_u…
Keycloak
12.0.2+
HIGH 7.8
CVE-2020-25712
A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The …
Enterprise Linux
1.20.10+
HIGH 7.8
CVE-2020-17159
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
Language Support For Java
Patch available
HIGH 7.5
CVE-2020-25692
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated atta…
Enterprise Linux
2.4.55+
MEDIUM 5.9
CVE-2020-27822
A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the…
Wildfly
Mitigation only
MEDIUM 5.5
CVE-2020-25677
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any use…
Ceph Storage
Patch available
HIGH 7.5
CVE-2020-29573
sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of…
Enterprise Linux
2.23+
HIGH 7.5
CVE-2020-27778
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious…
Enterprise Linux
0.76.0+
MEDIUM 6.1
CVE-2020-27783
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behavi…
Software Collections
4.6.2+
HIGH 8.8
CVE-2020-14339
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privi…
Libvirt
6.7.0+
MEDIUM 6.5
CVE-2020-25711
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When …
Data Grid
11.0.6+
MEDIUM 6.3
CVE-2020-14369
This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a…
Cloudforms
after 5.11
MEDIUM 6.5
CVE-2020-14383
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves prot…
Enterprise Linux
4.11.15 / 4.12.9+
HIGH 7.5
CVE-2020-25708
A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, wh…
Enterprise Linux
Patch available
MEDIUM 5.3
CVE-2020-25640
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inser…
Wildfly
21.0.0+
MEDIUM 5.5
CVE-2020-10762
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes …
Gluster Block
0.5.1+
MEDIUM 5.5
CVE-2020-10763
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access t…
Gluster Storage
10.1.0+
HIGH 8.8
CVE-2020-25660
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly a…
Ceph
14.2.14 / 15.2.6+
HIGH 8.1
CVE-2020-14389
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, …
Keycloak
12.0.0+
MEDIUM 5.9
CVE-2020-25658
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt part…
Openstack Platform
4.7+
HIGH 7.5
CVE-2020-14366
A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint…
Keycloak
12.0.0+
MEDIUM 6.5
CVE-2020-25655
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f…
Advanced Cluster Management For Kubernetes
Mitigation only
HIGH 8.8
CVE-2020-25661
A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. …
Enterprise Linux
Mitigation only
MEDIUM 6.5
CVE-2020-25662
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of s…
Enterprise Linux
Mitigation only
MEDIUM 6.5
CVE-2020-25689
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connec…
Wildfly
after 21.0.0
HIGH 7.8
CVE-2020-10721
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configur…
Fabric8 Maven
after 4.4.1
HIGH 7.5
CVE-2020-25648
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages,…
Enterprise Linux
3.58 / 9.2.6.0+
MEDIUM 6.5
CVE-2020-14299
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox Secur…
Jboss Enterprise Application Platform
5.0.3+