Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2021-45878
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the web manger pages allows any use…
Wallbox Gtb Firmware
after 185
HIGH 7.5
CVE-2022-26267
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.
Piwigo
No fix yet
MEDIUM 6.1
CVE-2022-22652
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA auth…
Ipados
15.4+
CRITICAL 9.8
CVE-2022-26501 KEV
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
Veeam Backup \& Replication
10.0.1.4854 / 11.0.1.1261+
CRITICAL 9.8
CVE-2021-44259
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access thi…
Wl Wn531g3 Firmware
No fix yet
HIGH 7.5
CVE-2021-44260EPSS 7%
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to acce…
Wl Wn531g3 Firmware
No fix yet
MEDIUM 5.3
CVE-2021-44261EPSS 20%
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page wi…
Wac104 Firmware
after 1.1.0.34_1.0.1
HIGH 7.5
CVE-2021-44262
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page wit…
Mbr1517 Firmware
after 1.0.4.13
CRITICAL 9.8
CVE-2022-25247
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port with…
Axeda Agent
6.9.1 / 6.9.215+
HIGH 7.5
CVE-2022-25250
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a cert…
Axeda Agent
6.9.1 / 6.9.215+
CRITICAL 9.8
CVE-2022-25251
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certai…
Axeda Agent
6.9.1 / 6.9.215+
HIGH 7.8
CVE-2021-33658
atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modif…
Atune
after 0.8
HIGH 7.5
CVE-2022-25508
An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service…
Freetakserver Ui
No fix yet
CRITICAL 9.8
CVE-2022-26143 KEVEPSS 87%
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain s…
Micollab
9.4+
CRITICAL 9.1
CVE-2022-25922
Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked by replaying J2497 messages.…
Plc4trucks Firmware
Mitigation only
HIGH 7.8
CVE-2022-24396
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed v…
Simple Diagnostics Agent
after 1.57
MEDIUM 6.6
CVE-2022-20060
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privil…
Android
Mitigation only
CRITICAL 9.8
CVE-2021-46384
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker…
Mcms
after 5.2.5
CRITICAL 9.1
CVE-2022-25359EPSS 37%
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
Scadaflex Ii Firmware
No fix yet
CRITICAL 9.8
CVE-2020-10640
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execut…
Openenterprise Scada Server
after 3.3.4
HIGH 7.5
CVE-2021-46371
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage …
Antd Admin
No fix yet
CRITICAL 9.8
CVE-2021-45420EPSS 18%
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cg…
Dixell Xweb 500 Firmware
Mitigation only
MEDIUM 5.3
CVE-2022-0188
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
Cmp
4.0.19+
CRITICAL 9.1
CVE-2021-22805
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user …
Interactive Graphical Scada System Data Collector
after 15.0.0.21243
CRITICAL 9.1
CVE-2021-22823EPSS 21%
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user …
Interactive Graphical Scada System Data Collector
after 15.0.0.21320
MEDIUM 6.1
CVE-2021-31814
In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the…
Stormshield Network Security
after 2.9.0
MEDIUM 5.3
CVE-2022-24111
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios…
Mahara
21.04.3+
MEDIUM 5.3
CVE-2022-22809
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unautho…
Spacelynk Firmware
after 2.6.2
MEDIUM 5.5
CVE-2022-21816
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on…
Cloud Gaming Virtual Gpu
8.10 / 11.7+
HIGH 7.4
CVE-2021-21964
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-craft…
Seaconnect 370w Firmware
No fix yet