Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2019-5640
Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an a…
Nexpose
6.6.114+
MEDIUM 5.3
CVE-2021-41532
In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access…
Ozone
1.2.0+
MEDIUM 6.5
CVE-2021-23193
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrie…
Command Centre
8.20.1291 / 8.30.1454+
HIGH 7.5
CVE-2021-41277 KEVEPSS 97%
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->se…
Metabase
Patch available
MEDIUM 5.3
CVE-2021-41271
Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by in…
Discourse
after 2.7.9
HIGH 8.8
CVE-2021-41263
rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails…
Rails Multisite
4.0.0+
CRITICAL 9.1
CVE-2021-30284
Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Comput…
Apq8009 Firmware
Mitigation only
MEDIUM 5.9
CVE-2021-41251
@sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform abstractions. This affects a…
Cloud Sdk
1.52.0+
MEDIUM 5.3
CVE-2021-39898
In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project whi…
GitLab
14.1.7 / 14.2.5+
HIGH 7.5
CVE-2021-22044
In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapp…
Spring Cloud Openfeign
after 3.0.4
MEDIUM 5.3
CVE-2021-22047
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a …
Spring Data Rest
after 3.5.5
HIGH 7.5
CVE-2021-41158
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…
Freeswitch
1.10.7+
MEDIUM 5.3
CVE-2021-39223
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to versions 3.8.6 and 4.2.3 returned ve…
Richdocuments
3.8.6 / 4.2.3+
MEDIUM 5.3
CVE-2021-39224
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud OfficeOnline application prior to version 1.1.1 returned verbatim excep…
Officeonline
1.1.1+
MEDIUM 5.3
CVE-2017-20007
Ingeteam INGEPAC DA AU AUC_1.13.0.28 (and before) web application allows access to a certain path that contains sensitive information that could be u…
Ingepac Da Au Firmware
Mitigation only
MEDIUM 6.5
CVE-2021-42536
The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.
Wireless 1410 Gateway Firmware
4.7.94+
MEDIUM 5.3
CVE-2021-31380
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a special…
Session And Resource Control
4.12.0r5 / 4.13.0r3+
CRITICAL 9.1
CVE-2021-31381
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a special…
Session And Resource Control
4.12.0r5 / 4.13.0r3+
MEDIUM 5.3
CVE-2021-31371
Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing t…
Junos
after 17.2
MEDIUM 5.3
CVE-2021-31352
An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the negotiation of weak ciphers,…
Session And Resource Control
4.130r6+
MEDIUM 5.3
CVE-2021-41140
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given …
Discourse Reactions
0.2+
MEDIUM 6.5
CVE-2021-22036
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able…
Vrealize Automation
8.6+
MEDIUM 5.3
CVE-2021-20832
InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerability which may lead to inform…
Inbody
2.2.90 / 2.3.30+
MEDIUM 6.5
CVE-2021-33727
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any…
Sinec Nms
1.0+
MEDIUM 6.5
CVE-2021-32028
A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user coul…
PostgreSQL
9.6.22 / 10.17+
MEDIUM 6.5
CVE-2021-32029
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary…
PostgreSQL
11.12 / 12.7+
HIGH 7.5
CVE-2021-42089
An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.
Zammad
4.1.1+
MEDIUM 6.5
CVE-2021-41125
Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider a…
Debian Linux
1.8.1 / 2.5.1+
MEDIUM 5.5
CVE-2021-0644
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permiss…
Android
Patch available
HIGH 7.5
CVE-2021-41120
sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was…
Paypal
1.2.4 / 1.3.1+