Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-44550
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
Corenlp
No fix yet
HIGH 7.2
CVE-2022-21705EPSS 9%
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before render…
October
1.0.474 / 1.1.10+
CRITICAL 9.8
CVE-2022-25337
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.
Ez Platform Kernel
1.3.12 / 7.5.26+
HIGH 7.5
CVE-2022-0391EPSS 8%
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into componen…
Python
3.6.14 / 3.7.11+
HIGH 8.8
CVE-2022-23616
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an un…
Xwiki
after 13.1
MEDIUM 5.4
CVE-2021-43929
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology …
Diskstation Manager
6.2.4-25556-3 / 7.0.1-42218-2+
CRITICAL 9.8
CVE-2022-23614EPSS 8%
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attac…
Twig
2.14.11 / 3.3.8+
HIGH 7.5
CVE-2020-12965
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits p…
Ryzen Pro 5650g Firmware
Mitigation only
HIGH 8.1
CVE-2021-36348
iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potential…
Integrated Dell Remote Access Controller 9 Firmware
5.00.20.00+
HIGH 8.8
CVE-2021-39031
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By usi…
Websphere Application Server
after 22.0.0.1
HIGH 7.8
CVE-2021-44537
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
Owncloud Desktop Client
2.9.2+
CRITICAL 9.8
CVE-2021-44530
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious…
Unifi Network Controller
after 6.5.53
HIGH 8.8
CVE-2021-32649
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…
October
1.0.473 / 1.1.6+
HIGH 8.8
CVE-2021-32650
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…
October
Patch available
HIGH 8.8
CVE-2021-42561EPSS 20%
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. Th…
Caldera
after 2.8.1
HIGH 8.8
CVE-2021-29454
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.…
Debian Linux
3.1.42 / 4.0.2+
HIGH 7.5
CVE-2021-24948
The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action…
The Plus Addons For Elementor
5.0.7+
HIGH 7.2
CVE-2022-21663
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Adm…
WordPress
5.8.3+
HIGH 8.8
CVE-2021-43852
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties …
Oroplatform
4.1.14 / 4.2.8+
HIGH 8.8
CVE-2021-25994
In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauth…
Userfrosting
4.6.3+
MEDIUM 6.1
CVE-2021-45818
SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.
Safari Montage
No fix yet
MEDIUM 6.6
CVE-2021-44832EPSS 98%
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) at…
Log4j
2.3.2 / 2.12.4+
MEDIUM 6.8
CVE-2021-45655
NETGEAR R6400 devices before 1.0.1.70 are affected by server-side injection.
R6400 Firmware
1.0.1.70+
HIGH 7.8
CVE-2021-45656
Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R60…
D6200 Firmware
1.0.0.48 / 1.0.0.66+
HIGH 7.8
CVE-2021-45657
Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R60…
D6200 Firmware
1.0.0.48 / 1.0.0.66+
CRITICAL 9.8
CVE-2021-45658
Certain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6…
D7800 Firmware
1.0.0.66 / 1.0.0.110+
HIGH 7.8
CVE-2021-45659
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK2…
Rbk40 Firmware
2.5.1.16+
HIGH 7.8
CVE-2021-45660
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK2…
Rbk40 Firmware
2.5.1.16+
HIGH 7.8
CVE-2021-45661
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK2…
Rbk40 Firmware
2.5.1.16+
HIGH 8.8
CVE-2021-43437
In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the a…
Engineers Online Portal
Mitigation only