Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-21823
An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially crafted s…
Komoot
after 11.1.11
HIGH 8.6
CVE-2021-34749
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), an…
Ironport Web Security Appliance
Patch available
MEDIUM 5.3
CVE-2021-35936
If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server…
Airflow
2.1.2+
MEDIUM 5.3
CVE-2021-37326
NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.
Xshell
Mitigation only
HIGH 7.5
CVE-2021-36793
The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure beca…
Routes
2.1.1+
CRITICAL 9.8
CVE-2021-21564
Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentiall…
Openmanage Enterprise
3.6.1+
MEDIUM 6.5
CVE-2021-21584
Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenti…
Openmanage Enterprise
Patch available
HIGH 8.8
CVE-2021-21596
Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code …
Openmanage Enterprise
after 3.6.1
MEDIUM 5.5
CVE-2015-7731
SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security N…
Mobile Platform
Mitigation only
HIGH 7.5
CVE-2021-20594
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SF…
R08sfcpu Firmware
Mitigation only
MEDIUM 5.5
CVE-2021-3566
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that refer…
Debian Linux
4.3+
MEDIUM 5.3
CVE-2021-22925
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pair…
Curl
7.78.0+
MEDIUM 6.5
CVE-2021-34707
A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitiv…
Evolved Programmable Network Manager
after 5.0
MEDIUM 6.5
CVE-2021-21440
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edi…
Otrs
after 8.0.14
MEDIUM 5.3
CVE-2020-7387EPSS 36%
Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installati…
Adxadmin
93.2.53+
HIGH 7.5
CVE-2021-22001
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an iden…
Cf Deployment
16.18.0 / 75.3.0+
MEDIUM 6.5
CVE-2021-22145EPSS 76%
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queri…
Elasticsearch
after 7.13.3
MEDIUM 5.3
CVE-2021-22721
A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …
Evlink City Evc1s22p4 Firmware
Mitigation only
MEDIUM 6.5
CVE-2021-22728
A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …
Evlink City Evc1s22p4 Firmware
Mitigation only
MEDIUM 6.5
CVE-2021-22770
A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensitive information to an actor no…
Easergy T300 Firmware
after 2.7.1
HIGH 7.5
CVE-2021-21817
An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network …
Dir 3040 Firmware
No fix yet
MEDIUM 6.5
CVE-2021-0291
An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-level resource is not being suff…
Junos
Mitigation only
HIGH 7.5
CVE-2021-32770
Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authenti…
Gatsby Source Wordpress
4.0.8 / 5.9.2+
MEDIUM 5.3
CVE-2021-20498
IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. IBM X…
Security Verify Access
Patch available
MEDIUM 5.7
CVE-2021-32750
MuWire is a file publishing and networking tool that protects the identity of its users by using I2P technology. Users of MuWire desktop client prior…
Muwire
0.8.8+
MEDIUM 5.3
CVE-2021-34429EPSS 99%
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of t…
Jetty
9.4.43 / 10.0.6+
HIGH 7.8
CVE-2021-0602
In onCreateOptionsMenu of WifiNetworkDetailsFragment.java, there is a possible way for guest users to view and modify Wi-Fi settings for all configur…
Android
Mitigation only
HIGH 7.5
CVE-2021-35527
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user cre…
Esoms
6.3.1+
MEDIUM 6.5
CVE-2021-32747
Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed…
Icinga
2.7.5 / 2.8.3+
MEDIUM 6.5
CVE-2021-32689
Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier…
Talk
11.2.2+