Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2021-41308
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication se…
Jira
8.6.0 / 8.13.12+
CRITICAL 10.0
CVE-2021-31384
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in …
Junos
Mitigation only
HIGH 8.5
CVE-2021-38486
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any req…
Ir615 Firmware
Mitigation only
HIGH 8.8
CVE-2021-42330
The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attacker…
Xinhe Teaching Platform System
Mitigation only
MEDIUM 5.4
CVE-2021-42331
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers…
Xinhe Teaching Platform System
Mitigation only
HIGH 8.8
CVE-2021-41137
Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that …
Minio
Patch available
MEDIUM 6.5
CVE-2021-33723
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any u…
Sinec Nms
1.0+
HIGH 8.8
CVE-2021-39317
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_insta…
Access Demo Importer
1.0.7+
MEDIUM 6.5
CVE-2021-41568
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin b…
Tad Web
after 1.76
CRITICAL 9.1
CVE-2021-41974
Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content o…
Tad Book3
3.9+
CRITICAL 9.1
CVE-2021-41975
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the sy…
Tadtools
3.2.2+
MEDIUM 5.3
CVE-2021-41976
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in t…
Tad Uploader
3.5.4+
MEDIUM 6.5
CVE-2021-41564
Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbit…
Tad Honor
1.47+
MEDIUM 5.5
CVE-2021-25499
Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provi…
Galaxy Store
4.5.32.4+
CRITICAL 9.8
CVE-2021-41093
Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by …
Wire
3.86+
CRITICAL 9.8
CVE-2021-41100
Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address…
Wire Server
2021-08-16+
MEDIUM 5.5
CVE-2021-25459
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZSe…
Android
Mitigation only
MEDIUM 5.5
CVE-2021-25460
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate Blockchain…
Android
Mitigation only
MEDIUM 6.5
CVE-2021-28567
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in …
Magento
after 2.4.2
HIGH 7.2
CVE-2021-36029
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vuln…
Adobe Commerce
after 2.4.2
MEDIUM 6.5
CVE-2021-36037
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vuln…
Adobe Commerce
after 2.4.2
MEDIUM 5.3
CVE-2021-34434
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is …
Fedora
after 2.0.11
CRITICAL 9.8
CVE-2021-27663
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequat…
Ac2000 Firmware
after 10.5
HIGH 7.5
CVE-2021-28626
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by an Improper Authorization vulnerability allow…
Experience Manager
after 6.5.8.0
CRITICAL 9.8
CVE-2021-3616
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware …
Smart Camera C2e Firmware
01.03.29.16+
CRITICAL 10.0
CVE-2021-37705
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allow…
Onefuzz
2.31.0+
HIGH 7.8
CVE-2021-36276
Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, d…
Dbutildrv2.sys Firmware
Patch available
CRITICAL 9.8
CVE-2021-35964
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the ma…
Orca Hcm
after 10.0
HIGH 8.8
CVE-2021-32688
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes.…
Nextcloud Server
19.0.13 / 20.0.11+
HIGH 8.8
CVE-2021-1576
Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attack…
Business Process Automation
3.1+