Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.0
CVE-2021-41503
DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command int…
Dcs 932l Firmware
after 2.17
CRITICAL 9.8
CVE-2021-22869
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not ha…
Enterprise Server
3.0.16 / 3.1.8+
CRITICAL 9.8
CVE-2021-31917
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat…
Data Grid
11.0.12 / 12.1.4+
CRITICAL 9.8
CVE-2021-38412
Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require auth…
Portserver Ts 16 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-41317
XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.
Xss Hunter Express
2021-09-17+
CRITICAL 9.8
CVE-2021-41303EPSS 77%
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul…
Shiro
1.8.0+
CRITICAL 9.8
CVE-2021-33044 KEVEPSS 100%
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authenti…
Ipc Hum7xxx Firmware
2.800.0000000.29.r.210630 / 2.812.0000007.0.r.210706+
CRITICAL 9.8
CVE-2021-33045 KEVEPSS 100%
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authenti…
Ipc Hum7xxx Firmware
2.800.0000000.29.r.210630 / 2.820.0000000.5.r.210705+
HIGH 7.8
CVE-2021-33700
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim wit…
Business One
Patch available
HIGH 7.5
CVE-2021-39215
Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms…
Jitsi Meet
Patch available
MEDIUM 6.7
CVE-2021-3145
In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
Identity Vault
5.0+
HIGH 7.5
CVE-2021-37414EPSS 5%
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
Manageengine Desktop Central
10.0.709+
MEDIUM 5.9
CVE-2021-25466
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Sa…
Internet
15.0.2.47+
CRITICAL 10.0
CVE-2021-39296
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
Openbmc
Mitigation only
HIGH 8.8
CVE-2021-28494
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypasse…
Metamako Operating System
after 0.34.0
CRITICAL 9.8
CVE-2021-28495
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can b…
Metamako Operating System
0.32.0+
HIGH 7.8
CVE-2021-28493
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to exe…
Metamako Operating System
after 0.32.0
HIGH 7.2
CVE-2021-34785
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user ac…
Broadworks Commpilot Application Software
22.0.2021.09 / 23.0.2021.09+
HIGH 7.8
CVE-2021-30605
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing …
Chrome Os Readiness Tool
1.0.2.0+
MEDIUM 5.4
CVE-2021-30667
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in WiFi range may be able to force…
Ipados
14.6+
MEDIUM 5.5
CVE-2021-30769
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitr…
Iphone Os
7.6 / 14.7+
MEDIUM 5.5
CVE-2021-30770
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved …
Iphone Os
7.6 / 14.7+
MEDIUM 5.4
CVE-2021-30720
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4…
Safari
7.5 / 11.4+
CRITICAL 9.8
CVE-2020-11264EPSS 13%
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Aut…
Apq8053 Firmware
Patch available
HIGH 7.5
CVE-2020-11301EPSS 11%
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdra…
Apq8009 Firmware
Patch available
MEDIUM 6.5
CVE-2021-39196
pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to u…
Pcapture
3.12+
CRITICAL 9.8
CVE-2021-34746EPSS 18%
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) cou…
Enterprise Nfv Infrastructure Software
4.6.1+
CRITICAL 9.8
CVE-2021-40350
webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafted query containing an unspeci…
Dwu850 Gs Firmware
No fix yet
CRITICAL 9.8
CVE-2021-22002
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a …
Identity Manager
Patch available
CRITICAL 9.6
CVE-2021-22943
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subseq…
Unifi Protect
1.19.0+