Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-45652
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 …
Rbk352 Firmware
4.4.0.10+
HIGH 7.5
CVE-2021-45653
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 …
Rbk352 Firmware
4.4.0.10+
HIGH 7.5
CVE-2021-45654
NETGEAR XR1000 devices before 1.0.0.58 are affected by disclosure of sensitive information.
Xr1000 Firmware
1.0.0.58+
HIGH 7.5
CVE-2021-45646
NETGEAR R7000 devices before 1.0.11.116 are affected by disclosure of sensitive information.
R7000 Firmware
1.0.11.116+
HIGH 7.5
CVE-2021-45647
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EAX80 before 1.0.1.62, EX7000 before 1.0.1.104, R6120 befor…
Eax80 Firmware
1.0.0.76 / 1.0.1.62+
MEDIUM 5.5
CVE-2021-45603
Certain NETGEAR devices are affected by disclosure of sensitive information. A UPnP request reveals a device's serial number, which can be used for a…
D7800 Firmware
1.0.0.90 / 1.0.1.66+
HIGH 7.5
CVE-2021-45493
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RA…
Rax35 Firmware
1.0.4.102+
MEDIUM 6.5
CVE-2021-4024
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gv…
Fedora
3.4.3+
MEDIUM 6.5
CVE-2021-39013
IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses t…
Cloud Pak For Security
Mitigation only
MEDIUM 5.5
CVE-2021-36341
Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated user with low privileges cou…
Wyse Device Agent
after 14.5.4.1
MEDIUM 6.5
CVE-2021-44145
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious externa…
Nifi
1.15.1+
MEDIUM 5.3
CVE-2021-45038
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can …
Mediawiki
1.35.5 / 1.36.3+
MEDIUM 5.5
CVE-2021-45095
pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.
Linux Kernel
after 5.15.8
MEDIUM 5.0
CVE-2021-1023
In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, d…
Android
Mitigation only
MEDIUM 6.5
CVE-2021-43823
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in priva…
Sourcegraph
3.33.2+
MEDIUM 5.5
CVE-2021-38901
IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Forc…
Spectrum Protect Operations Center
7.1.14+
MEDIUM 5.3
CVE-2021-39941
An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to se…
GitLab
14.3.6 / 14.4.4+
HIGH 8.0
CVE-2021-24945
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX acti…
Like Button Rating
2.6.38+
HIGH 7.5
CVE-2021-37935
An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get inf…
Huntflow Enterprise
after 3.10.4
MEDIUM 6.5
CVE-2021-43536
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thun…
Firefox
91.4.0 / 95.0+
HIGH 7.5
CVE-2021-41090
Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.…
Agent
0.20.1 / 0.21.2+
MEDIUM 6.5
CVE-2021-43067
A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and…
Fortiauthenticator
after 6.0.7
HIGH 8.1
CVE-2021-43963
An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write data in Couchbase Server were in…
Sync Gateway
2.8.3+
HIGH 7.5
CVE-2021-37067
There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerabilit…
Harmonyos
2.0+
MEDIUM 5.3
CVE-2021-29115
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attac…
Arcgis Enterprise
after 10.9
HIGH 7.5
CVE-2021-36198
Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.
Kantech Entrapass
8.40+
MEDIUM 5.9
CVE-2020-27414
Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure if unauthori…
Mahavitaran
after 7.50
MEDIUM 5.5
CVE-2021-38999
IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.
Mq Appliance
Patch available
MEDIUM 5.5
CVE-2021-39000
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. I…
Mq Appliance
Patch available
HIGH 7.5
CVE-2021-37010
There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerabilit…
Harmonyos
No fix yet