Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2022-26102
Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to acc…
Netweaver Application Server Abap
Mitigation only
HIGH 7.8
CVE-2022-20054
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no …
Android
Mitigation only
HIGH 7.8
CVE-2022-20053
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with …
Android
Mitigation only
MEDIUM 6.7
CVE-2022-20049
In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e…
Android
Mitigation only
HIGH 7.1
CVE-2022-0905
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
Gitea
1.16.4+
MEDIUM 5.3
CVE-2021-41239
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user…
Nextcloud Server
20.0.14 / 21.0.6+
MEDIUM 6.5
CVE-2022-0756
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
Suitecrm
7.12.5+
HIGH 7.5
CVE-2021-25087
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticate…
Download Manager
3.2.35+
MEDIUM 6.5
CVE-2022-0163
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authentic…
Smart Forms
2.6.71+
HIGH 8.8
CVE-2021-3656
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control bl…
Linux Kernel
4.14.245 / 4.19.205+
HIGH 7.8
CVE-2022-0492 KEVEPSS 6%
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circum…
Linux Kernel
4.9.301 / 4.14.266+
HIGH 8.1
CVE-2021-41112
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users cou…
Rundeck
3.4.5+
MEDIUM 6.1
CVE-2021-24977
The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthen…
Use Any Font
6.2.1+
MEDIUM 5.7
CVE-2021-25011
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which co…
Wp Google Map
1.8.1+
MEDIUM 5.4
CVE-2021-25042
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX act…
Visitor Statistics
5.5+
MEDIUM 5.3
CVE-2022-24594
In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
Waline
Patch available
MEDIUM 5.4
CVE-2022-0726
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
Peertube
4.1.0+
HIGH 8.8
CVE-2022-23642EPSS 74%
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` servi…
Sourcegraph
3.37+
CRITICAL 10.0
CVE-2022-0543 KEVEPSS 99%
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which c…
Redis
Patch available
HIGH 8.8
CVE-2020-25718
A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would all…
Fedora
4.13.14 / 4.14.10+
HIGH 8.8
CVE-2022-0611
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
Snipe It
5.3.11+
HIGH 8.8
CVE-2022-25206
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified databa…
Dbcharts
after 0.5.2
HIGH 8.8
CVE-2022-25208
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP…
Chef Sinatra
after 1.20
HIGH 8.8
CVE-2022-25211
A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifie…
Swamp
after 1.2.6
MEDIUM 6.5
CVE-2022-25193
Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission to connect to an attacker-sp…
Snow Commander
after 1.10
HIGH 8.8
CVE-2022-25199
A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-sp…
Scp Publisher
after 1.8
MEDIUM 6.5
CVE-2022-25201
Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-spe…
Checkmarx
after 2022.1.2
MEDIUM 6.5
CVE-2022-0588
Missing Authorization in Packagist librenms/librenms prior to 22.2.0.
Librenms
22.2.0+
MEDIUM 6.5
CVE-2022-0579
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
Snipe It
5.3.9+
HIGH 8.8
CVE-2022-22854
An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attackers to escalate privileges via …
Hospital\'s Patient Records Management System
No fix yet