Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2021-1017
In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permiss…
Android
Mitigation only
HIGH 7.8
CVE-2021-0985
In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check. This could lead to local esca…
Android
Patch available
MEDIUM 5.5
CVE-2021-0986
In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure about the device owner, profile owner, or device a…
Android
Patch available
HIGH 7.8
CVE-2021-0922
In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROFILES permission due to a miss…
Android
Mitigation only
HIGH 7.8
CVE-2021-0923
In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to loca…
Android
Mitigation only
HIGH 7.8
CVE-2021-0926
In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a missing permission check. This c…
Android
Mitigation only
HIGH 8.8
CVE-2021-0965
In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This …
Android
Patch available
MEDIUM 5.5
CVE-2021-0653
In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission ch…
Android
Mitigation only
HIGH 7.5
CVE-2021-41066
An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to acce…
Listary
after 6
MEDIUM 5.4
CVE-2021-42367
The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/c…
Variation Swatches For Woocommerce
after 2.1.1
HIGH 8.8
CVE-2021-44233
SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which c…
Access Control
Mitigation only
MEDIUM 6.5
CVE-2021-20867
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in …
Advanced Custom Fields
5.11+
HIGH 7.5
CVE-2021-20865
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in …
Advanced Custom Fields
5.11+
MEDIUM 6.5
CVE-2021-20866
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in …
Advanced Custom Fields
5.11+
HIGH 8.0
CVE-2021-24914
The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX act…
Tawk.to Live Chat
0.6.0+
HIGH 8.8
CVE-2021-35413
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary…
Chamilo Lms
after 1.11.16
MEDIUM 5.4
CVE-2021-24842
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private…
Bulk Datetime Change
1.12+
HIGH 7.5
CVE-2021-36917
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can th…
Hide My Wp
after 6.2.3
HIGH 7.5
CVE-2021-20835
Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan …
Mercari
4.49.1+
CRITICAL 9.1
CVE-2021-39231
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an att…
Ozone
1.2.0+
HIGH 8.8
CVE-2021-39232
In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.
Ozone
1.2.0+
HIGH 8.8
CVE-2021-39236
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
Ozone
1.2.0+
MEDIUM 5.5
CVE-2021-0672
In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no…
Android
Mitigation only
HIGH 8.1
CVE-2021-36909
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the enti…
Wp Reset Pro
after 5.98
HIGH 8.1
CVE-2021-40501
SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resul…
Abap Platform Kernel
Mitigation only
HIGH 8.8
CVE-2021-40502
SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in es…
Commerce
Mitigation only
CRITICAL 9.1
CVE-2021-42359
WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available …
Wp Dsgvo Tools
after 3.1.23
CRITICAL 9.1
CVE-2021-21687
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic lin…
Jenkins
2.303.3 / 2.319+
HIGH 7.5
CVE-2021-21688
The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not reject any operat…
Jenkins
2.303.3 / 2.319+
CRITICAL 9.8
CVE-2021-21694
FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions in Jenkins 2…
Jenkins
2.303.3 / 2.319+