Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2021-28506
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially…
Eos
after 4.26.2f
HIGH 7.8
CVE-2021-39622
In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privi…
Android
Mitigation only
MEDIUM 5.3
CVE-2021-1037
The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for i…
Android
Mitigation only
MEDIUM 5.4
CVE-2022-0178
Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
Snipe It
5.3.8+
MEDIUM 5.9
CVE-2021-40327
Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) …
Trusted Firmware M
Patch available
MEDIUM 6.5
CVE-2022-23112
A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-sp…
Publish Over Ssh
after 1.22
MEDIUM 5.4
CVE-2022-0179
snipe-it is vulnerable to Missing Authorization
Snipe It
5.3.7+
CRITICAL 9.8
CVE-2021-25032EPSS 7%
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation …
Capabilities
2.3.1+
HIGH 7.2
CVE-2021-46075
A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resourc…
Vehicle Service Management System
after 1.0
HIGH 8.8
CVE-2022-22111
In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled…
Daybyday Crm
Patch available
HIGH 7.5
CVE-2021-24831
All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated att…
Tab
1.3.2+
HIGH 8.1
CVE-2021-20873
Yappli is an application development platform which provides the function to access a requested URL using Custom URL Scheme. When Android apps are de…
Yappli
9.30.0+
MEDIUM 5.4
CVE-2021-24988
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which…
Wp Rss Aggregator
4.19.3+
MEDIUM 6.5
CVE-2021-24997
The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could …
Wp Guppy
1.3+
HIGH 7.5
CVE-2021-37572
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT76…
Mt7603e Firmware
Mitigation only
MEDIUM 6.5
CVE-2021-43847
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to bec…
Humhub
1.9.3 / 1.10.3+
HIGH 7.2
CVE-2021-40853
TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to a…
Gim
Mitigation only
HIGH 7.8
CVE-2021-0673
In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with …
Android
Mitigation only
MEDIUM 6.5
CVE-2021-44857
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by …
Mediawiki
1.35.5 / 1.36.3+
HIGH 7.5
CVE-2021-27857
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1…
Ipvpn Firmware
Mitigation only
MEDIUM 5.3
CVE-2021-27858
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1…
Ipvpn Firmware
Mitigation only
HIGH 8.8
CVE-2021-27859
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1…
Ipvpn Firmware
Mitigation only
HIGH 8.8
CVE-2021-27855
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privilege…
Ipvpn Firmware
Mitigation only
MEDIUM 6.8
CVE-2021-39639
In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege w…
Android
Patch available
HIGH 7.8
CVE-2021-39651
In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead…
Android
Patch available
MEDIUM 5.5
CVE-2021-1025
In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, du…
Android
Mitigation only
HIGH 7.8
CVE-2021-0999
In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permis…
Android
Patch available
HIGH 7.8
CVE-2021-1004
In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to…
Android
Mitigation only
MEDIUM 5.5
CVE-2021-1010
In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no addit…
Android
Mitigation only
MEDIUM 5.5
CVE-2021-1011
In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no…
Android
Mitigation only