Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2021-39225
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows ano…
Deck
1.2.9 / 1.4.5+
MEDIUM 5.4
CVE-2021-36387
In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially craft…
Yellowfin
9.6.1+
HIGH 7.5
CVE-2021-36388
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability e…
Yellowfin
9.6.1+
HIGH 7.5
CVE-2021-36389
In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploita…
Yellowfin
9.6.1+
HIGH 7.5
CVE-2021-20599
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/…
R08sfcpu Firmware
Mitigation only
HIGH 8.1
CVE-2021-41129
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati…
Panel
1.6.2+
HIGH 7.5
CVE-2021-41120
sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was…
Paypal
1.2.4 / 1.3.1+
MEDIUM 5.3
CVE-2021-37331
Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade Lic…
Booking Core
No fix yet
HIGH 7.5
CVE-2021-37777
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just…
Gila Cms
No fix yet
HIGH 8.8
CVE-2021-41847
An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials assigned to…
Infinias Access Control
after 6.7.10708.0
HIGH 8.8
CVE-2021-41298
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on use…
Ecs Router Controller Ecs Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-41301
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. T…
Ecs Router Controller Ecs Firmware
Mitigation only
HIGH 8.8
CVE-2021-36874
Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).
Ulisting
after 2.0.5
MEDIUM 5.4
CVE-2021-29773
IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an i…
Security Guardium
Patch available
MEDIUM 6.5
CVE-2021-38624
Windows Key Storage Provider Security Feature Bypass Vulnerability
Windows 10
Patch available
HIGH 8.8
CVE-2021-40355
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (Al…
Teamcenter Visualization
12.4.0.8 / 13.0.0.7+
CRITICAL 9.8
CVE-2021-37184
A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker could change the the password of…
Industrial Edge Management
1.3+
HIGH 7.5
CVE-2021-37628
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares i…
Richdocuments
3.8.4 / 4.2.1+
MEDIUM 6.5
CVE-2021-37630
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed …
Circles
0.19.5 / 0.20.11+
MEDIUM 6.5
CVE-2021-37631
Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In aff…
Deck
1.2.9 / 1.4.4+
HIGH 8.8
CVE-2021-36032
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…
Adobe Commerce
after 2.4.2
MEDIUM 6.5
CVE-2021-40352EPSS 10%
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.
Openemr
No fix yet
HIGH 7.2
CVE-2021-22023
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to v…
Cloud Foundation
8.5.0+
HIGH 7.5
CVE-2021-24562
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue…
Lifterlms
4.21.2+
MEDIUM 6.5
CVE-2021-37709
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log…
Shopware
6.4.3.1+
MEDIUM 5.4
CVE-2021-37212
The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote at…
Flygo
1.91.1+
HIGH 8.8
CVE-2021-37214
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, re…
Flygo
1.91.1+
HIGH 8.1
CVE-2021-36801
Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed i…
Akaunting
after 2.1.12
MEDIUM 5.4
CVE-2021-24473
The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default aut…
User Profile Picture
2.6.0+
HIGH 7.5
CVE-2021-32744
Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gai…
Online
4.2.17-1 / 6.4.9-5+