Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2021-25375
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when …
Email
6.1.14.0+
MEDIUM 5.3
CVE-2021-25376
An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotia…
Email
6.1.41.0+
MEDIUM 5.5
CVE-2021-25357
A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), an…
Android
Mitigation only
MEDIUM 6.3
CVE-2021-3413
A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Az…
Satellite
2.2.0+
HIGH 8.8
CVE-2021-24163
The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, ther…
Ninja Forms
3.4.34+
HIGH 7.5
CVE-2021-24167
When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send an XMLHttpRequest request to …
Web Stat
1.4.1+
HIGH 7.5
CVE-2021-24170
The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functio…
User Profile Picture
2.5.0+
MEDIUM 6.5
CVE-2021-21400
wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being …
Wire Webapp
after 2019-07-11-13-18
MEDIUM 6.5
CVE-2021-21421
node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer…
Node Etsy Client
after 0.3.0
MEDIUM 5.3
CVE-2021-22876EPSS 5%
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in …
Fedora
after 7.75.0
MEDIUM 5.3
CVE-2021-28164EPSS 82%
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to a…
Jetty
after 11.70.1
MEDIUM 6.5
CVE-2021-21396
wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16 and before version 2021-03-0…
Wire Server
2021-03-02+
MEDIUM 5.5
CVE-2021-25369 KEV
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
Android
Mitigation only
MEDIUM 5.3
CVE-2020-35518
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an un…
389 Directory Server
1.4.3.19 / 1.4.4.13+
MEDIUM 6.5
CVE-2021-23890
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to do…
Epolicy Orchestrator
5.9.1+
MEDIUM 6.5
CVE-2021-21376
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the cu…
Omero.web
5.9.0+
MEDIUM 5.5
CVE-2020-11199
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, S…
Apq8009 Firmware
Mitigation only
MEDIUM 5.5
CVE-2020-11221
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the…
Apq8009 Firmware
Mitigation only
MEDIUM 5.3
CVE-2021-20281
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5,…
Moodle
3.5.17 / 3.8.8+
HIGH 7.5
CVE-2021-26923
An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is …
Argo Cd
1.7.12 / 1.8.4+
MEDIUM 5.5
CVE-2021-21364
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen…
Swagger Codegen
2.4.19+
MEDIUM 5.3
CVE-2021-21360
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSet…
Products.genericsetup
2.1.1+
MEDIUM 6.5
CVE-2021-21336
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t…
Products.pluggableauthservice
2.6.0+
HIGH 7.5
CVE-2021-25122EPSS 18%
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate re…
Tomcat
21.3.0+
CRITICAL 9.0
CVE-2021-26566
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-i…
Diskstation Manager
6.2.3-25426-3+
CRITICAL 9.1
CVE-2020-28199
best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor.
Amazon Pay
9.4.2+
MEDIUM 5.3
CVE-2021-21621
Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details onl…
Support Core
after 2.72
MEDIUM 5.3
CVE-2021-20256
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts perm…
Satellite
Mitigation only
MEDIUM 5.3
CVE-2021-21323
Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME adblocking feature added in B…
Brave
after 1.20.103
HIGH 7.5
CVE-2021-26593
In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of infor…
Directus
after 8.8.1