Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2021-29502
WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to access sensible informations…
Warnsystem
1.3.18+
MEDIUM 6.5
CVE-2021-29501
Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users to expose sensitive informatio…
Dav Cogs
1.0.1+
HIGH 7.5
CVE-2021-3154
An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: thi…
Serv U
15.2.2+
HIGH 7.5
CVE-2021-31164
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
Unomi
1.5.5+
HIGH 7.5
CVE-2021-22331
There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit…
P30 Firmware
10.1.0.165 / 11.0.0.118+
MEDIUM 5.9
CVE-2019-25031
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HT…
Debian Linux
1.9.5+
CRITICAL 9.3
CVE-2021-0268
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buff…
Junos
Mitigation only
HIGH 8.0
CVE-2021-28829
The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO A…
Administrator
after 5.10.2
HIGH 7.5
CVE-2021-31402
The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
Dio
5.0.0+
HIGH 8.8
CVE-2021-27182
An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an…
Mdaemon
20.0.4+
HIGH 8.8
CVE-2021-22879
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to exec…
Desktop
3.1.3+
MEDIUM 5.3
CVE-2020-36308
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading ti…
Debian Linux
4.0.7 / 4.1.1+
HIGH 7.8
CVE-2021-21420
vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted so…
Stripe
1.7.3+
HIGH 8.8
CVE-2021-21372
Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in differ…
Nim
1.2.10 / 1.4.4+
MEDIUM 5.3
CVE-2020-7464
In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE before p10, 11.4-RELEASE before p4, and 11.3-RELEASE before p14, a pr…
FreeBSD
Mitigation only
MEDIUM 6.1
CVE-2021-21333
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…
Fedora
1.27.0+
MEDIUM 6.5
CVE-2021-3027
app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of specia…
Passhport
after 2.5
HIGH 7.5
CVE-2021-29156EPSS 76%
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-ch…
Openam
13.5.1+
HIGH 7.3
CVE-2021-1432
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlyi…
Ios Xe
Mitigation only
MEDIUM 5.3
CVE-2021-28963
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
Debian Linux
3.2.1+
MEDIUM 5.3
CVE-2021-26069
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project k…
Data Center
8.5.11 / 8.13.3+
MEDIUM 5.3
CVE-2020-36144
Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template sinc…
Redash
Mitigation only
HIGH 7.8
CVE-2021-24144
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers injec…
Contact Form 7 Database Addon
1.2.5.6+
MEDIUM 5.5
CVE-2020-4851
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and develo…
Spectrum Scale
5.0.5.5 / 5.1.0.2+
HIGH 8.8
CVE-2021-22191
Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture f…
Wireshark
after 3.4.3
HIGH 7.2
CVE-2020-14987
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because th…
Experience Manager
after 14.2.2
HIGH 8.2
CVE-2021-21381
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before versi…
Debian Linux
1.10.2+
MEDIUM 6.1
CVE-2021-21510
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit th…
Idrac8 Firmware
2.75.100.75+
MEDIUM 6.1
CVE-2021-21313
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In G…
Glpi
9.5.4+
CRITICAL 9.0
CVE-2021-21353
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty…
Pug
2.0.3 / 3.0.1+