Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2021-21685
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs.
Jenkins
2.303.3 / 2.319+
CRITICAL 9.1
CVE-2020-25366
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspe…
Dir 823g Firmware
Mitigation only
HIGH 7.5
CVE-2021-41238
Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows Service or separate process re…
Hangfire
Mitigation only
HIGH 7.5
CVE-2015-20067EPSS 8%
The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data …
Wp Attachment Export
0.2.4+
HIGH 7.5
CVE-2018-25019
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment…
Learndash
after 2.5.4
HIGH 8.1
CVE-2021-39225
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows ano…
Deck
1.2.9 / 1.4.5+
MEDIUM 6.5
CVE-2021-24779
The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF che…
Wp Debugging
2.11.0+
MEDIUM 5.5
CVE-2021-0706
In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This coul…
Android
Mitigation only
MEDIUM 5.5
CVE-2021-0643
In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due t…
Android
Mitigation only
CRITICAL 10.0
CVE-2021-31384
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in …
Junos
Mitigation only
HIGH 8.5
CVE-2021-38486
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any req…
Ir615 Firmware
Mitigation only
MEDIUM 5.3
CVE-2021-24677
The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enume…
Find My Blocks
3.4.0+
HIGH 7.5
CVE-2021-37738
A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10…
Clearpass Policy Manager
6.10.2+
MEDIUM 5.4
CVE-2021-42331
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers…
Xinhe Teaching Platform System
Mitigation only
MEDIUM 6.1
CVE-2021-20834
Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 and Nike App for iOS versions p…
Nike
2.177.1 / 2.177.3.3688+
HIGH 8.6
CVE-2021-39184
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, …
Electron
11.5.0 / 12.1.0+
HIGH 8.1
CVE-2021-40884
Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php a…
Projectsend
No fix yet
MEDIUM 6.5
CVE-2021-37976 KEVEPSS 20%
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information f…
Chrome
94.0.4606.71+
CRITICAL 9.8
CVE-2021-32172EPSS 66%
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
Maian Cart
No fix yet
MEDIUM 5.5
CVE-2021-0680
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…
Android
Mitigation only
MEDIUM 5.5
CVE-2021-0681
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…
Android
Mitigation only
MEDIUM 5.5
CVE-2021-0682
In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. …
Android
Patch available
MEDIUM 5.5
CVE-2021-0686
In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user d…
Android
Patch available
HIGH 7.3
CVE-2021-39226 KEVEPSS 100%
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit…
Grafana
7.5.11 / 8.1.6+
HIGH 8.8
CVE-2021-41554
ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endp…
Web Central
No fix yet
HIGH 7.5
CVE-2021-39893
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
GitLab
14.1.7 / 14.2.5+
CRITICAL 9.1
CVE-2021-41729
BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through…
Baicloud Cms
No fix yet
HIGH 8.8
CVE-2021-3653
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control bl…
Linux Kernel
4.4.282 / 4.9.281+
CRITICAL 9.8
CVE-2021-33924
Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allow…
Ansible
Mitigation only
CRITICAL 9.8
CVE-2021-37270
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly…
Cms Enterprise Website Construction System
Mitigation only