Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2021-34578
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically construct…
750 890\/040 000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-39177
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNAPSHOT allow anyone that can c…
Geyser
1.4.2+
CRITICAL 9.8
CVE-2021-37417
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
Manageengine Adselfservice Plus
6.1+
HIGH 7.5
CVE-2021-36370
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked …
Midnight Commander
after 4.8.26
CRITICAL 9.8
CVE-2021-32967
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized…
Diaenergie
after 1.7.5
HIGH 7.5
CVE-2021-22025
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unaut…
Cloud Foundation
8.5.0+
MEDIUM 6.5
CVE-2021-39165EPSS 10%
Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearc…
Cachet
2.3.18+
HIGH 7.4
CVE-2021-29487
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vuln…
October
1.0.472 / 1.1.5+
CRITICAL 9.1
CVE-2021-32648 KEVEPSS 90%
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an accoun…
October
1.1.5+
MEDIUM 5.5
CVE-2021-30867
The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access phot…
Ipados
12.0.1 / 15.0+
CRITICAL 9.8
CVE-2021-37597
WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
Wp Cerber
8.9.3+
MEDIUM 6.5
CVE-2021-39138
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup use…
Parse Server
4.5.1+
MEDIUM 5.4
CVE-2021-1561
A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow…
Secure Email And Web Manager
after 14.1
CRITICAL 9.8
CVE-2021-24527EPSS 8%
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin o…
Profile Builder
3.4.9+
HIGH 7.1
CVE-2021-36949
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
Azure Active Directory Connect
1.1.582.0+
HIGH 8.8
CVE-2021-36921
AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An a…
Application Insight Manager
Mitigation only
HIGH 7.8
CVE-2021-27794
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a us…
Fabric Operating System
7.4.2h / 8.2.3a+
MEDIUM 6.5
CVE-2021-3046
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any o…
Pan Os
8.1.19 / 9.0.14+
HIGH 7.5
CVE-2021-37172
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against con…
Simatic S7 1200 Cpu Firmware
after 13.0
CRITICAL 9.8
CVE-2021-21564
Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentiall…
Openmanage Enterprise
3.6.1+
CRITICAL 9.8
CVE-2014-9320
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privilege…
Businessobjects Edge
Patch available
MEDIUM 5.3
CVE-2021-20598
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R0…
R08sfcpu Firmware
Mitigation only
HIGH 7.5
CVE-2021-37545
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
Teamcity
2021.1+
HIGH 7.8
CVE-2021-32579
Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (wh…
True Image
Mitigation only
MEDIUM 5.3
CVE-2021-25445
Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Intern…
Internet
14.2+
HIGH 7.5
CVE-2020-16839
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthentic…
Dm Nvx Dir 80 Firmware
Mitigation only
CRITICAL 10.0
CVE-2021-21538
Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated at…
Idrac9 Firmware
4.40.10.00+
HIGH 7.5
CVE-2021-32794
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /…
Archisteamfarm
5.1.2.4+
MEDIUM 5.3
CVE-2020-21932
A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially auth…
Cx2 Firmware
No fix yet
HIGH 7.5
CVE-2021-34675
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
Nex Forms
after 7.8.7