Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-32499
SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the Emulator executable.
Sopas Engineering Tool
4.8.0+
HIGH 8.1
CVE-2020-35213
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.
Atomix
No fix yet
HIGH 7.5
CVE-2021-37262
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
Jfinal Cms
Patch available
CRITICAL 9.1
CVE-2021-43837EPSS 5%
vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli fea…
Vault Cli
3.0.0+
HIGH 7.2
CVE-2021-41276
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanit…
Tuleap
13.1-5 / 13.2-3+
HIGH 7.2
CVE-2021-43782
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a follow up to GHSA-887w-pv2r-x8pm…
Tuleap
13.1-6 / 13.2-4+
HIGH 7.1
CVE-2021-43818
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted scri…
Fedora
4.6.5+
HIGH 8.8
CVE-2021-43038
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL tr…
Unitrends Backup
10.5.5+
HIGH 7.8
CVE-2021-38873
IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by im…
Planning Analytics
Patch available
HIGH 7.2
CVE-2021-36313
Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially explo…
Cloudlink
7.1.1+
HIGH 7.5
CVE-2021-37033
There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
Emui
No fix yet
MEDIUM 6.1
CVE-2021-36322
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may pote…
X1008p Firmware
3.0.1.8+
MEDIUM 5.3
CVE-2021-34419
In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a use…
Zoom Client For Meetings
5.1.0+
CRITICAL 9.8
CVE-2021-43350
An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP…
Traffic Control
5.1.4 / 6.0.1+
HIGH 8.8
CVE-2021-25980
In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-r…
Talkyard
after 0.2021.02-wip-879ef3fe1
CRITICAL 9.8
CVE-2021-43185
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
Youtrack
2021.3.23639+
CRITICAL 9.8
CVE-2021-41170
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template eng…
Neoan3 Template
1.1.1+
MEDIUM 6.7
CVE-2021-36697
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file cont…
Pandora Fms
after 755
CRITICAL 9.8
CVE-2021-41232
Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerab…
Planning Poker
1.16.3+
CRITICAL 9.8
CVE-2021-38294EPSS 84%
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4…
Storm
1.2.4 / 2.1.1+
HIGH 8.0
CVE-2020-23050
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user a…
Tao Assessment Platform
No fix yet
CRITICAL 9.8
CVE-2021-41163EPSS 20%
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution.…
Discourse
2.7.9+
HIGH 7.5
CVE-2021-37933
An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, remote user to modify the logi…
Huntflow Enterprise
3.10.6+
MEDIUM 5.3
CVE-2021-20802
HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product.
Remote Service Manager
Mitigation only
CRITICAL 9.8
CVE-2021-38458
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite crit…
Mxview
after 3.2.2
HIGH 8.8
CVE-2021-41128
Hygeia is an application for collecting and processing personal and case data in connection with communicable diseases. In affected versions all CSV …
Hygeia
1.30.4+
HIGH 8.8
CVE-2021-31988
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed…
Axis Os
6.50.5.5 / 8.40.4.3+
HIGH 7.2
CVE-2021-35504
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.
Filerun
after 2021.03.26
HIGH 7.2
CVE-2021-35505
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.
Filerun
after 2021.03.26
CRITICAL 9.8
CVE-2021-41862
AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).
Aviatorscript
No fix yet