Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2021-41315
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (w…
Remote Collector
17.05.01+
CRITICAL 9.8
CVE-2021-37913
The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote …
Oaklouds Portal
after 3.0-2
CRITICAL 9.8
CVE-2021-37912
The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remo…
Oaklouds Portal
after 3.0-2
HIGH 8.8
CVE-2021-23025
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote com…
Big Ip Access Policy Manager
13.1.3.5 / 14.1.3.1+
CRITICAL 9.9
CVE-2021-23031
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5…
Big Ip Advanced Web Application Firewall
after 16.0.1.1
HIGH 8.8
CVE-2021-37531
SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-adminis…
Netweaver Knowledge Management Xml Forms
No fix yet
CRITICAL 10.0
CVE-2021-31891
A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or …
Desigo Cc
Patch available
HIGH 7.2
CVE-2021-33550EPSS 57%
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …
G Cam Ebc 2110 Firmware
after 1.12.0.27
HIGH 7.2
CVE-2021-33551EPSS 49%
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …
G Cam Ebc 2110 Firmware
after 1.12.0.27
HIGH 7.2
CVE-2021-33552EPSS 49%
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …
G Cam Ebc 2110 Firmware
after 1.12.0.27
HIGH 7.2
CVE-2021-33553EPSS 49%
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …
G Cam Ebc 2110 Firmware
after 1.12.0.27
HIGH 7.2
CVE-2021-33554EPSS 57%
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …
G Cam Ebc 2110 Firmware
after 1.12.0.27
HIGH 7.2
CVE-2021-33548EPSS 57%
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …
G Cam Ebc 2110 Firmware
after 1.12.0.27
HIGH 7.2
CVE-2021-33544EPSS 95%
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely …
G Cam Ebc 2110 Firmware
after 1.12.0.27
HIGH 7.2
CVE-2021-40222
Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is pos…
Cmc Pu Iii 7030.000 Firmware
3.17.10+
HIGH 7.2
CVE-2021-39459
Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the ho…
Redaxo
No fix yet
HIGH 7.8
CVE-2021-34719
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate pr…
Ios Xr
7.3.2 / 7.4.1+
MEDIUM 6.7
CVE-2021-34721
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell…
Ios Xr
7.3.2 / 7.4.1+
MEDIUM 6.7
CVE-2021-34722
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell…
Ios Xr
7.3.2 / 7.4.1+
HIGH 7.8
CVE-2021-34728
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate pr…
Ios Xr
7.3.2 / 7.4.1+
CRITICAL 9.8
CVE-2020-26300
systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is …
Systeminformation
4.26.2+
CRITICAL 9.8
CVE-2020-26772
Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function.
Ppgo Jobs
No fix yet
HIGH 8.8
CVE-2021-28571
Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debuggi…
After Effects
after 18.1
HIGH 8.8
CVE-2021-36182
A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker t…
Fortiweb
6.3.14+
HIGH 8.8
CVE-2021-39279
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell…
Wac 2004 Firmware
No fix yet
HIGH 7.2
CVE-2021-36022
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the W…
Adobe Commerce
after 2.4.2
HIGH 7.2
CVE-2021-36024
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special E…
Adobe Commerce
after 2.4.2
HIGH 7.2
CVE-2021-27556
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to…
Zentao
No fix yet
HIGH 8.1
CVE-2021-35062
A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a C…
Testerfassung
No fix yet
CRITICAL 9.8
CVE-2021-33055EPSS 18%
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
Manageengine Adselfservice Plus
6.1+