Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2021-44255
Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup fil…
Motioneye
0.42.1 / 20200606+
MEDIUM 5.5
CVE-2021-26264
A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service cond…
Deltav Workstation
No fix yet
MEDIUM 6.5
CVE-2021-34870
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 ro…
Xr1000
Patch available
CRITICAL 9.1
CVE-2022-23944EPSS 79%
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Patch available
HIGH 7.5
CVE-2022-23945
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Patch available
MEDIUM 5.3
CVE-2021-33843
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this function…
Agilia Sp Mc Wifi Firmware
Mitigation only
HIGH 7.8
CVE-2022-23220
USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g.…
Usbview
2.2+
HIGH 7.8
CVE-2021-23843
The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a pa…
Amc2 Firmware
4.9.1+
CRITICAL 9.8
CVE-2021-35587 KEVEPSS 96%
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 1…
Access Manager
Mitigation only
CRITICAL 9.1
CVE-2021-28506
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially…
Eos
after 4.26.2f
CRITICAL 9.8
CVE-2022-23227 KEVEPSS 49%
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because …
Nvrmini2 Firmware
after 3.11.0
MEDIUM 5.3
CVE-2021-43974
An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the serv…
Itil
No fix yet
CRITICAL 9.8
CVE-2021-43832
Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. Thi…
Spinnaker
1.25.8 / 1.26.7+
MEDIUM 6.5
CVE-2021-43333
The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or disclosure of configuration …
Dxu
after 2.1.3
MEDIUM 6.8
CVE-2021-20161
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to…
Tew 827dru Firmware
Mitigation only
MEDIUM 5.3
CVE-2021-20150EPSS 40%
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and…
Tew 827dru Firmware
Mitigation only
MEDIUM 6.5
CVE-2021-20152
Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyone is able to visit and modif…
Tew 827dru Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-20158EPSS 11%
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to …
Tew 827dru Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-45232EPSS 86%
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all…
Apisix Dashboard
2.10.1+
HIGH 8.1
CVE-2021-36780
A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica in…
Longhorn
1.1.3 / 1.2.3+
CRITICAL 9.6
CVE-2021-36779
A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the…
Longhorn
1.1.3 / 1.2.3+
CRITICAL 9.8
CVE-2021-36888EPSS 7%
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6…
Image Hover Effects
9.6.1+
CRITICAL 9.8
CVE-2021-22279
A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot contro…
Omnicore C30 Firmware
7.3.2+
CRITICAL 9.8
CVE-2021-44152EPSS 59%
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthentica…
Reprise License Manager
15.1+
HIGH 7.5
CVE-2021-34543
The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administr…
Solar Log 500 Firmware
after 2.8.1
HIGH 7.5
CVE-2021-38147EPSS 53%
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive inform…
Holmes
No fix yet
HIGH 7.5
CVE-2021-38283
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a pre…
Holmes
No fix yet
CRITICAL 9.8
CVE-2021-44077 KEVEPSS 93%
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentic…
Manageengine Servicedesk Plus
10.5 / 11.0+
CRITICAL 9.8
CVE-2021-42783
Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated attacker to…
Dwr 932c E1 Firmware
after 1.0.0.4
CRITICAL 9.1
CVE-2021-39233
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any …
Ozone
1.2.0+