Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-41266EPSS 48%
Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are s…
Minio Console
0.12.3+
CRITICAL 9.8
CVE-2021-20136EPSS 10%
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthentica…
Manageengine Log360
after 5.2
MEDIUM 5.3
CVE-2021-33259
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query hi…
Dir 868lw Firmware
No fix yet
MEDIUM 5.3
CVE-2021-41157
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…
Freeswitch
1.10.6+
HIGH 7.5
CVE-2021-37624
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…
Freeswitch
1.10.7+
HIGH 8.8
CVE-2021-42539
The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved …
Wireless 1410 Gateway Firmware
4.7.94+
CRITICAL 9.8
CVE-2021-38457
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing …
Versiondog
8.0.0+
HIGH 8.1
CVE-2021-27395
A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 …
Simatic Process Historian 2013
Mitigation only
MEDIUM 6.5
CVE-2021-41568
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin b…
Tad Web
after 1.76
CRITICAL 9.1
CVE-2021-41974
Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content o…
Tad Book3
3.9+
CRITICAL 9.1
CVE-2021-41975
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the sy…
Tadtools
3.2.2+
MEDIUM 5.3
CVE-2021-41976
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in t…
Tad Uploader
3.5.4+
HIGH 8.1
CVE-2021-35979
An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform auth…
Realport
after 4.8.488.0
HIGH 7.5
CVE-2021-23858
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can …
Rexroth Indramotion Mlc L20 Firmware
after 12
CRITICAL 9.6
CVE-2021-3825
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to…
Liderahenk
after 2.1.15
HIGH 7.5
CVE-2021-41104
ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulne…
Esphome Firmware
2021.9.2+
HIGH 7.5
CVE-2021-22012
The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with networ…
Cloud Foundation
5.0+
MEDIUM 6.5
CVE-2021-37420
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
Manageengine Admanager Plus
6.1+
CRITICAL 9.8
CVE-2021-38412
Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require auth…
Portserver Ts 16 Firmware
Mitigation only
MEDIUM 5.3
CVE-2019-10941
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative …
Sinema Server
14.0+
CRITICAL 9.8
CVE-2021-33543EPSS 82%
Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user au…
G Cam Ebc 2110 Firmware
after 1.12.0.27
CRITICAL 9.8
CVE-2021-28913
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to validate the so called and har…
Eibport Firmware
3.9.1+
CRITICAL 9.8
CVE-2021-38540EPSS 81%
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint …
Airflow
2.1.3+
HIGH 8.1
CVE-2021-32800
Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextc…
Nextcloud Server
20.0.12 / 21.0.4+
CRITICAL 9.8
CVE-2021-37415 KEVEPSS 100%
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
Manageengine Servicedesk Plus
Mitigation only
MEDIUM 5.3
CVE-2021-27668
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.
Vault
1.6.3+
HIGH 8.6
CVE-2021-33882
A Missing Authentication for Critical Function vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to reconfigure the de…
Spacecom2
012u000062+
HIGH 8.5
CVE-2021-39144 KEVEPSS 98%
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…
Debian Linux
1.4.18+
MEDIUM 5.4
CVE-2021-31868
Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feat…
Nexpose
6.6.96+
MEDIUM 5.3
CVE-2021-35936
If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server…
Airflow
2.1.2+