Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2021-34401
NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to …
Shield Experience
9.0+
MEDIUM 6.7
CVE-2021-34402
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memor…
Shield Experience
9.0+
MEDIUM 6.5
CVE-2021-37864
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view conte…
Mattermost
after 6.1
HIGH 7.1
CVE-2021-28507
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RE…
Eos
after 4.26.2f
HIGH 7.3
CVE-2022-23132
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix …
Fedora
after 5.4.8
MEDIUM 5.3
CVE-2022-23134 KEVEPSS 85%
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. M…
Fedora
after 5.4.8
HIGH 7.5
CVE-2021-45034
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (Al…
Cp 8000 Master Module With I\/o 25\/\+70 Firmware
16.20+
HIGH 7.5
CVE-2022-0133
peertube is vulnerable to Improper Access Control
Peertube
2022-01-06+
MEDIUM 6.5
CVE-2021-4194
bookstack is vulnerable to Improper Access Control
Bookstack
21.12.1+
HIGH 7.3
CVE-2021-25991
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to …
Ifme
after 7.32
HIGH 7.5
CVE-2021-20050
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, pot…
Sma 100 Firmware
10.0.0.0+
MEDIUM 6.7
CVE-2021-42808
Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges.
Sentinel Protection Installer
7.7.1+
CRITICAL 9.8
CVE-2021-4119EPSS 27%
bookstack is vulnerable to Improper Access Control
Bookstack
after 21.11.2
CRITICAL 9.8
CVE-2021-36888EPSS 7%
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6…
Image Hover Effects
9.6.1+
MEDIUM 6.5
CVE-2021-24845
The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve…
Improved Include Page
after 1.2
MEDIUM 6.5
CVE-2021-22565
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to genera…
Exposure Notification Verification Server
1.1.2+
HIGH 8.8
CVE-2021-42124
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a …
Avalanche
6.3.3+
MEDIUM 6.8
CVE-2021-35245
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
Serv U
15.2.4+
HIGH 8.1
CVE-2020-10627
Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manu…
Omnipod Insulin Management System Firmware
Mitigation only
CRITICAL 9.9
CVE-2021-26334
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation an…
Amd Uprof
3.4.494 / 3.4.502+
MEDIUM 6.5
CVE-2021-3992
kimai2 is vulnerable to Improper Access Control
Kimai2
1.16.2+
HIGH 7.5
CVE-2021-36917
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can th…
Hide My Wp
after 6.2.3
CRITICAL 10.0
CVE-2021-3554
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows…
Endpoint Security Tools
6.6.27.390 / 6.24.1-1+
HIGH 8.1
CVE-2021-36909
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the enti…
Wp Reset Pro
after 5.98
HIGH 7.1
CVE-2021-35528
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlemen…
Counterparty Settlements And Billing
after 5.7.3
MEDIUM 5.4
CVE-2021-42360
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contrib…
Starter Templates
after 2.7.0
HIGH 7.5
CVE-2021-26338
Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting i…
Epyc 7f72 Firmware
Mitigation only
HIGH 8.8
CVE-2021-3062
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to co…
Pan Os
8.1.20 / 9.0.14+
MEDIUM 5.5
CVE-2020-12488
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without reques…
Jovi Smart Scene
6.2.2.52+
CRITICAL 9.1
CVE-2021-42359
WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available …
Wp Dsgvo Tools
after 3.1.23