Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2021-22232
HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
GitLab
13.11.6 / 13.12.6+
MEDIUM 6.1
CVE-2021-20101
Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to recei…
Machform
16+
HIGH 8.8
CVE-2021-23400
The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns …
Nodemailer
6.6.1+
HIGH 8.8
CVE-2021-20574
IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially cra…
Security Identity Manager Adapter
Patch available
MEDIUM 5.4
CVE-2021-29676
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-cra…
Security Verify
10.9.66+
MEDIUM 5.3
CVE-2021-29955
A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have …
Firefox
78.9 / 87.0+
HIGH 8.8
CVE-2021-24002
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed a…
Firefox
78.10 / 88.0+
HIGH 7.5
CVE-2021-29084
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report managemen…
Diskstation Manager
3.1-23033 / 6.2.3-25426-3+
HIGH 7.5
CVE-2021-29085
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component…
Diskstation Manager
3.1-23033 / 6.2.3-25426-3+
MEDIUM 6.5
CVE-2021-0551
In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. Th…
Android
Mitigation only
HIGH 7.3
CVE-2021-0553
In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local esc…
Android
Mitigation only
HIGH 7.8
CVE-2021-0567
In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of…
Android
Mitigation only
CRITICAL 9.1
CVE-2021-20736
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the databa…
Growi
4.2.20+
CRITICAL 9.8
CVE-2018-25016
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
Greenbone Security Assistant
5.0.0 / 7.0.3+
HIGH 7.5
CVE-2021-29702
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnorma…
Db2
after 11.5.5.0
MEDIUM 6.5
CVE-2021-28979
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability usin…
Safenet Keysecure
after 8.12.0
HIGH 7.8
CVE-2021-25682
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
Apport
2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+
HIGH 7.5
CVE-2021-33668
Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confid…
Infrabox
1.2.1+
MEDIUM 6.5
CVE-2021-30540
Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafte…
Chrome
91.0.4472.77+
MEDIUM 6.5
CVE-2021-31249EPSS 18%
A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validatio…
Bf 430 Firmware
No fix yet
HIGH 8.8
CVE-2021-30506
Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a we…
Chrome
90.0.4430.212+
CRITICAL 9.1
CVE-2021-32647
Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication Remote Code Execution (RCE).…
Emissary
Patch available
CRITICAL 9.4
CVE-2021-32642
radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-edu…
Fedora
1.9.0+
HIGH 7.0
CVE-2020-27212
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP lev…
Stm32cubel4 Firmware
after 1.16.0
MEDIUM 6.1
CVE-2021-29414
STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.
Stm32cubel4 Firmware
after 1.17.0
HIGH 7.8
CVE-2021-32622
Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the loca…
Matrix React Sdk
3.21.0+
MEDIUM 6.5
CVE-2021-3524
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection …
Ceph
14.2.21+
MEDIUM 5.4
CVE-2021-30214EPSS 24%
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.
Knowage
No fix yet
MEDIUM 5.3
CVE-2020-26142
An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversa…
OpenBSD
Mitigation only
HIGH 7.1
CVE-2021-27614
SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to i…
Business One Hana Chef Cookbook
Mitigation only