Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2021-42309
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Enterprise Server
Patch available
HIGH 7.8
CVE-2021-43065
A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows a…
Fortinac
8.8.10 / 9.1.4+
HIGH 7.1
CVE-2021-36133
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the No…
Op Tee
Mitigation only
HIGH 7.0
CVE-2021-44512
World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of sessi…
Tmate Ssh Server
after 2.3.0
HIGH 7.8
CVE-2021-43034
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as th…
Unitrends Backup
10.5.5+
HIGH 8.8
CVE-2021-43359
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a …
Ehrd
Mitigation only
HIGH 7.2
CVE-2021-40101
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
Concrete Cms
8.5.7+
MEDIUM 6.5
CVE-2021-44230
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privi…
Burp Suite
after 2021.11
MEDIUM 6.5
CVE-2021-43998
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multipl…
Vault
after 1.7.5
CRITICAL 9.1
CVE-2021-42115
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated re…
Topease
after 7.1.27
MEDIUM 5.7
CVE-2021-24703
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any aut…
Download Plugin
1.6.1+
HIGH 7.8
CVE-2021-43019
Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe servi…
Creative Cloud Desktop Application
after 5.5
MEDIUM 6.5
CVE-2021-39235
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block to…
Ozone
1.2.0+
HIGH 7.8
CVE-2021-0064
Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated…
Ax210 Firmware
22.40+
HIGH 7.8
CVE-2021-33091
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit audio driver pack before version 1.3 may allow an authenticated u…
Nuc M15 Laptop Kit Audio Driver Pack
1.3+
HIGH 7.8
CVE-2021-33093
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Serial IO driver pack before version 30.100.2104.1 may allow an a…
Nuc M15 Laptop Kit Serial Io Driver Pack
30.100.2104.1+
HIGH 7.8
CVE-2021-33094
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow…
Nuc M15 Laptop Kit Keyboard Led Service Driver Pack
1.0.0.4+
HIGH 7.8
CVE-2021-42954
Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is v…
Manageengine Remote Access Plus
10.1.2121.1+
HIGH 7.8
CVE-2021-42955
Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because…
Manageengine Remote Access Plus
10.1.2132+
MEDIUM 5.3
CVE-2020-4146
IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote at…
Security Siteprotector System
Mitigation only
HIGH 7.8
CVE-2021-37207
A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific …
Sentron Powermanager 3
after 3.6
CRITICAL 9.8
CVE-2021-41170
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template eng…
Neoan3 Template
1.1.1+
MEDIUM 5.3
CVE-2021-20526
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote at…
Planning Analytics
Patch available
CRITICAL 9.8
CVE-2021-41589
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when r…
Build Cache Node
10.0 / 2021.3+
HIGH 7.8
CVE-2021-37364
OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/…
Openclinic Ga
No fix yet
HIGH 7.8
CVE-2021-40343
An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileg…
Nagios Xi
No fix yet
HIGH 8.8
CVE-2021-38475
The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.
Versiondog
8.0.0+
MEDIUM 5.5
CVE-2021-31377
An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated a…
Junos
Mitigation only
MEDIUM 6.1
CVE-2021-26589
A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Si…
Superdome Flex Firmware
3.40.106+
MEDIUM 5.4
CVE-2021-41802
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with…
Vault
1.7.5 / 1.8.4+