Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2021-34647
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/R…
Ninja Forms
after 3.5.7
MEDIUM 5.4
CVE-2021-24635
The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all…
Visual Link Preview
2.2.3+
HIGH 8.1
CVE-2021-24639
The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which …
Omgf
4.5.4+
HIGH 8.8
CVE-2021-33704
The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricte…
Business One
Patch available
HIGH 8.8
CVE-2021-22149
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate rou…
Enterprise Search
7.14.0+
MEDIUM 6.5
CVE-2021-22147
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining…
Elasticsearch
7.14.0+
HIGH 7.5
CVE-2021-41077
The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpected sharing that is not spec…
Travis Ci
after 2021-09-10
CRITICAL 9.8
CVE-2021-37535
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization…
Netweaver Application Server Java
Mitigation only
MEDIUM 5.4
CVE-2021-38164
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE …
Erp Financial Accounting
Mitigation only
HIGH 8.8
CVE-2021-38388
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.
Central Dogma
0.51.1+
CRITICAL 9.8
CVE-2020-24672
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This…
Base Software
after 6.1
HIGH 7.8
CVE-2021-30713 KEVEPSS 7%
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass …
Mac Os X
11.4+
MEDIUM 5.5
CVE-2021-30657 KEVEPSS 69%
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious…
Mac Os X
11.3+
MEDIUM 6.5
CVE-2021-38698
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service …
Consul
1.8.15 / 1.9.9+
HIGH 8.1
CVE-2021-40378EPSS 15%
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from t…
Ip70 Firmware
No fix yet
HIGH 7.5
CVE-2021-40379EPSS 22%
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.
Ip70 Firmware
No fix yet
HIGH 8.8
CVE-2021-36232
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
Mik.starlight
No fix yet
MEDIUM 5.4
CVE-2021-40088
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling cli…
Ejbca
7.6.0+
HIGH 7.5
CVE-2021-30874
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installe…
Ipados
12.0.1 / 15.0+
CRITICAL 9.1
CVE-2020-25359
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted r…
Rconfig
No fix yet
HIGH 7.8
CVE-2020-27464
An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via a crafted ZIP file.
Rconfig
after 3.9.6
HIGH 7.8
CVE-2020-27466
An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a craf…
Rconfig
Mitigation only
MEDIUM 5.5
CVE-2021-0415
In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information discl…
Android
Mitigation only
MEDIUM 5.5
CVE-2021-0641
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission …
Android
Patch available
MEDIUM 5.5
CVE-2021-0642
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permis…
Android
Patch available
MEDIUM 5.3
CVE-2021-38755
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
Hospital Management System
No fix yet
CRITICAL 9.8
CVE-2020-18753
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted pa…
Mac1100 Plc Firmware
No fix yet
HIGH 7.5
CVE-2020-18757
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.
Mac1100 Plc Firmware
No fix yet
HIGH 8.1
CVE-2021-24500
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer…
Workreap
2.2.2+
HIGH 8.1
CVE-2021-24501
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform criti…
Workreap
2.2.2+