Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2021-23204
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to…
Command Centre
8.30.1359 / 8.40.1888+
MEDIUM 5.5
CVE-2020-13938EPSS 12%
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
HTTP Server
5.10.0+
MEDIUM 6.3
CVE-2021-21473
SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC…
Netweaver Application Server Abap
No fix yet
MEDIUM 6.0
CVE-2021-32015
In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to …
Npct75x Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-31921
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in th…
Istio
1.8.6 / 1.9.5+
MEDIUM 6.5
CVE-2020-10701
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connec…
Libvirt
6.2.0+
CRITICAL 9.8
CVE-2021-22891
A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow un…
Sharefile Storagezones Controller
5.7.3 / 5.9.3+
HIGH 7.5
CVE-2018-10865
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…
Certification
Mitigation only
CRITICAL 9.1
CVE-2018-10866
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…
Certification
Mitigation only
CRITICAL 9.1
CVE-2020-4669
IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …
Planning Analytics Cloud
Patch available
MEDIUM 5.3
CVE-2021-32917
An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP accou…
Debian Linux
0.11.9+
HIGH 8.8
CVE-2021-23014
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for …
Big Ip Advanced Web Application Firewall
14.1.4 / 15.1.3+
CRITICAL 9.8
CVE-2021-27573
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with n…
Emote Remote Mouse
after 4.0.0.0
CRITICAL 9.8
CVE-2021-21984
VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious ac…
Vrealize Business For Cloud
7.6.0+
MEDIUM 6.5
CVE-2021-32093
The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the Con…
Emissary
No fix yet
HIGH 8.1
CVE-2021-32095
U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files.
Emissary
Mitigation only
HIGH 7.5
CVE-2020-18888
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
Puppycms
No fix yet
HIGH 8.8
CVE-2021-1505
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…
Catalyst Sd Wan Manager
20.3.3 / 20.4.1+
HIGH 7.2
CVE-2021-1506
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…
Catalyst Sd Wan Manager
20.3.3 / 20.4.1+
HIGH 8.8
CVE-2021-1508
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…
Catalyst Sd Wan Manager
19.2.99 / 20.3.3+
MEDIUM 5.2
CVE-2021-21264
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1…
October
after 1.1.1
HIGH 7.5
CVE-2021-20693
Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and earlier allows a remote attacker…
Gurunavi
after 11.1.2
MEDIUM 5.3
CVE-2021-27598
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.5
CVE-2021-27609
SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData s…
Focused Run
Mitigation only
MEDIUM 5.5
CVE-2021-0428
In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could …
Android
Patch available
MEDIUM 6.5
CVE-2021-21432
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0…
Vela
0.7.5+
MEDIUM 5.3
CVE-2020-36287EPSS 9%
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from ve…
Data Center
8.13.5 / 8.15.1+
MEDIUM 6.5
CVE-2021-22513
Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and ea…
Application Automation Tools
after 6.7
HIGH 8.1
CVE-2021-27900
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console. Th…
Insider Threat Management
7.9.3 / 7.10.3+
HIGH 8.1
CVE-2020-13422
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
Openiam
4.2.0.3+