Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-27730
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_4…
Fta
after 9_12_432
CRITICAL 9.8
CVE-2021-27132EPSS 16%
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition head…
Agcombo Vd625 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-3197EPSS 72%
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an…
Fedora
2015.8.10 / 2015.8.13+
HIGH 8.8
CVE-2021-26068
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via …
Jira Server For Slack
2.0.15+
HIGH 8.8
CVE-2020-12873
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a w…
Alfresco Enterprise Content Management
6.2.1+
HIGH 7.8
CVE-2021-21316
less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming reso…
Less Openui5
0.10.0+
HIGH 7.5
CVE-2020-35564
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malici…
Mbconnect24
after 2.6.2
CRITICAL 9.8
CVE-2020-35775EPSS 13%
CITSmart before 9.1.2.23 allows LDAP Injection.
Citsmart
9.1.2.23+
MEDIUM 6.1
CVE-2021-20644
ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.
Wrc 1467ghbk A Firmware
Mitigation only
HIGH 7.5
CVE-2021-23335
All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.
Is User Valid
No fix yet
CRITICAL 9.1
CVE-2021-21479EPSS 10%
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the sys…
Scimono
0.0.19+
MEDIUM 6.5
CVE-2021-21137EPSS 6%
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information…
Chrome
88.0.705.50 / 88.0.4324.96+
MEDIUM 6.5
CVE-2021-21141EPSS 5%
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy v…
Chrome
88.0.705.74 / 88.0.4324.96+
HIGH 8.8
CVE-2021-21305EPSS 13%
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions…
Carrierwave
1.3.2 / 2.1.1+
MEDIUM 6.8
CVE-2021-21303
Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-co…
Helm
3.5.2+
HIGH 8.8
CVE-2021-21277
angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2…
Angular Expressions
1.1.2+
CRITICAL 9.8
CVE-2020-15690
In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.
Nim
1.2.6+
CRITICAL 9.8
CVE-2021-21278
RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk …
Rsshub
2021-01-25+
MEDIUM 5.3
CVE-2021-21263
Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit…
Laravel
6.20.11 / 7.30.2+
CRITICAL 9.8
CVE-2021-21242EPSS 74%
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code exe…
Onedev
4.0.3+
HIGH 8.8
CVE-2021-21247
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAj…
Onedev
4.0.3+
HIGH 8.8
CVE-2021-21248
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. I…
Onedev
4.0.3+
HIGH 8.8
CVE-2021-21249
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote …
Onedev
4.0.3+
CRITICAL 9.8
CVE-2021-21243EPSS 54%
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted da…
Onedev
4.0.3+
CRITICAL 9.8
CVE-2021-21244
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injectio…
Onedev
4.0.3+
HIGH 8.8
CVE-2021-21261
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` ser…
Debian Linux
1.8.5 / 1.10.0+
MEDIUM 5.4
CVE-2020-26298
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-…
Redcarpet
3.5.1+
MEDIUM 6.5
CVE-2020-5019
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. B…
Spectrum Protect Plus
10.1.7+
MEDIUM 5.3
CVE-2020-27260
Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow phys…
Vital Signs Monitor Vc150 Firmware
1.7.15+
CRITICAL 9.8
CVE-2020-28468
This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template …
Pwntools
4.3.1+