Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.0
CVE-2021-29795
IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of hypervisor calls from a part…
Powervm Hypervisor
Patch available
CRITICAL 9.8
CVE-2021-41392
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed …
Boostnote
after 0.22.0
HIGH 8.0
CVE-2021-41390
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.
Enterprise Content Management
No fix yet
HIGH 8.8
CVE-2021-41314EPSS 14%
Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentica…
Gc108p Firmware
1.0.3.2 / 1.0.5.3+
HIGH 8.8
CVE-2021-39213
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable…
Glpi
9.5.6+
HIGH 7.8
CVE-2021-30777
An injection issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Upd…
Mac Os X
11.5+
HIGH 8.2
CVE-2021-40143
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may d…
Nexus Repository Manager 3
3.34.0+
HIGH 7.5
CVE-2021-39187
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes…
Parse Server
4.10.3+
MEDIUM 6.1
CVE-2021-39175
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the …
Hedgedoc
1.9.0+
HIGH 8.8
CVE-2020-18875
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocit…
Dotcms
5.1.0+
CRITICAL 9.6
CVE-2021-32827
MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim…
Mockserver
Patch available
CRITICAL 9.8
CVE-2021-20509
IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the sys…
Maximo Asset Management
7.6.1.2+
HIGH 7.5
CVE-2021-38371
The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
Exim
after 4.94.2
HIGH 7.5
CVE-2020-23148
The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive inform…
Rconfig
No fix yet
HIGH 8.1
CVE-2021-38290
A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset…
Fuel Cms
after 1.5.0
MEDIUM 6.1
CVE-2021-37541
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
Hub
2021.1.13402+
MEDIUM 5.5
CVE-2020-24821
A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation …
Libelfin
No fix yet
MEDIUM 5.5
CVE-2020-24822
A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault…
Libelfin
No fix yet
MEDIUM 5.5
CVE-2020-24823
A vulnerability in the dwarf::to_string function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault vi…
Libelfin
No fix yet
MEDIUM 5.5
CVE-2020-24825
A vulnerability in the line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fa…
Libelfin
No fix yet
MEDIUM 5.5
CVE-2020-24826
A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation f…
Libelfin
No fix yet
HIGH 8.1
CVE-2021-38084
An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the PO…
Courier Mail Server
1.1.5+
HIGH 7.2
CVE-2021-35450
A Server Side Template Injection in the Entando Admin Console 6.3.9 and before allows a user with privileges to execute FreeMarker template with comm…
Admin Console
after 6.3.9
HIGH 7.3
CVE-2021-33195
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may c…
Go
1.15.13 / 1.16.5+
HIGH 7.5
CVE-2021-32558EPSS 9%
An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Aster…
Debian Linux
13.38.3 / 16.19.1+
CRITICAL 9.8
CVE-2021-3169
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have acce…
Jumpserver
2.4.5 / 2.5.4+
HIGH 8.8
CVE-2021-32756
ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module o…
Manageiq
Mitigation only
HIGH 8.1
CVE-2020-5323
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection v…
Emc Openmanage Enterprise
1.10.00 / 3.2+
HIGH 8.0
CVE-2021-0594
In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead to remote …
Android
Mitigation only
MEDIUM 5.3
CVE-2021-36381
In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_err…
Transaction Management
after 2021-07-12