Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.6
CVE-2020-14355
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Bot…
Openstack
Patch available
HIGH 7.5
CVE-2020-25644
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to caus…
Wildfly Openssl
1.1.3+
MEDIUM 6.7
CVE-2020-25637
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network inte…
Libvirt
6.8.0+
MEDIUM 5.5
CVE-2020-25635
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. File…
Ansible
Mitigation only
HIGH 7.1
CVE-2020-25636
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written d…
Ansible
Mitigation only
MEDIUM 6.1
CVE-2020-25626
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails…
Ceph Storage
3.12.0+
MEDIUM 6.1
CVE-2019-11556
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
Pagure
5.6+
HIGH 7.5
CVE-2020-10714
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an …
Wildfly Elytron
1.11.3+
HIGH 7.1
CVE-2020-14365
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using …
Ansible Engine
after 3.7.2
MEDIUM 5.3
CVE-2020-14370
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-…
Openshift Container Platform
2.0.5+
MEDIUM 5.3
CVE-2020-25633
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensi…
Resteasy
3.14.0+
MEDIUM 5.3
CVE-2020-14338
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforce…
Xerces
2.12.0+
HIGH 7.5
CVE-2020-10718
A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context…
Jboss Fuse
13.0.0+
MEDIUM 6.1
CVE-2020-10748
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows a…
Keycloak
7.4.1+
HIGH 7.5
CVE-2020-10758
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak …
Keycloak
11.0.1+
HIGH 7.5
CVE-2020-1748
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed whe…
Wildfly Elytron
1.6.8.final-redhat-00001+
HIGH 7.8
CVE-2020-14382
A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on e…
Enterprise Linux
Patch available
MEDIUM 5.3
CVE-2020-1710
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
Jboss Data Grid
Mitigation only
MEDIUM 6.0
CVE-2020-10759
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signatur…
Enterprise Linux
No fix yet
HIGH 7.3
CVE-2020-0570
Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privil…
Enterprise Linux
5.9.10 / 5.12.7+
MEDIUM 5.5
CVE-2020-14330
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json o…
Ansible Engine
2.9.12+
MEDIUM 5.5
CVE-2020-14332
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive dat…
Ansible Engine
2.8.14 / 2.9.12+
HIGH 7.5
CVE-2020-14384
A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable t…
Jboss Enterprise Application Platform
7.5.31.final-redhat-3+
MEDIUM 5.5
CVE-2020-14373
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to …
Enterprise Linux
Patch available
MEDIUM 5.0
CVE-2020-14364EPSS 5%
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB pa…
Openstack
5.2.0+
HIGH 8.0
CVE-2020-14352
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repo…
Librepo
1.12.1+
HIGH 7.3
CVE-2019-14904
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name…
Ansible
2.7.15 / 2.8.7+
MEDIUM 5.3
CVE-2020-10775
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary we…
Ovirt Engine
after 4.4
CRITICAL 9.1
CVE-2020-14324
A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerabil…
Cloudforms Management Engine
5.11.7.0+
HIGH 7.1
CVE-2020-14296
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker co…
Cloudforms Management Engine
Mitigation only