Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2021-24184
Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to m…
Tutor Lms
1.7.7+
HIGH 8.8
CVE-2021-24163
The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, ther…
Ninja Forms
3.4.34+
MEDIUM 5.5
CVE-2020-29621
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007…
Mac Os X
10.14.6 / 10.15.7+
MEDIUM 5.3
CVE-2020-36238
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.…
Data Center
8.5.13 / 8.13.5+
MEDIUM 6.5
CVE-2021-21632
A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an …
Owasp Dependency Track
after 3.1.0
MEDIUM 6.5
CVE-2021-21637
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to connect to a…
Team Foundation Server
after 5.157.1
HIGH 7.5
CVE-2021-28669
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.02…
Altalink B8045 Firmware
103.001.020.23120 / 103.002.020.23120+
CRITICAL 9.1
CVE-2021-26990
Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.
Cloud Manager
3.9.4+
HIGH 7.5
CVE-2021-27656
A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exa…
Exacqvision Web Service
after 20.12.2.0
HIGH 7.5
CVE-2021-24146EPSS 31%
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the exp…
Modern Events Calendar Lite
5.16.5+
HIGH 7.8
CVE-2021-28375
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from…
Linux Kernel
5.4.106 / 5.10.24+
CRITICAL 9.1
CVE-2021-28154
Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vul…
Modeler
after 4.6.0
HIGH 7.2
CVE-2020-14987
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because th…
Experience Manager
after 14.2.2
CRITICAL 9.8
CVE-2021-28141
An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web…
Telerik Ui For Asp.net Ajax
No fix yet
HIGH 7.8
CVE-2021-0380
In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony settings due to a missing permission…
Android
Patch available
HIGH 7.8
CVE-2021-0385
In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connection to untrusted WiFi networks…
Android
Patch available
HIGH 7.8
CVE-2021-0388
In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast handler. This could lead to …
Android
Patch available
HIGH 7.8
CVE-2021-0389
In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no …
Android
Patch available
HIGH 7.8
CVE-2021-0390
In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check. T…
Android
Mitigation only
HIGH 8.8
CVE-2021-21487
SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Payment Engine
Mitigation only
HIGH 8.8
CVE-2021-21486
SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authoriz…
Enterprise Financial Services
Mitigation only
MEDIUM 6.5
CVE-2021-21326
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
9.5.4+
HIGH 7.5
CVE-2021-21327
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
9.5.4+
MEDIUM 5.5
CVE-2021-25344
Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without per…
Android
Mitigation only
CRITICAL 9.8
CVE-2021-21978EPSS 99%
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authoriza…
View Planner
4.6+
MEDIUM 6.5
CVE-2021-22877
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration whe…
Nextcloud Server
20.0.6+
MEDIUM 5.7
CVE-2021-21255
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
Patch available
MEDIUM 6.5
CVE-2021-23975
The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function …
Firefox
86.0+
CRITICAL 9.8
CVE-2021-21307EPSS 89%
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before version…
Lucee Server
5.3.5.96 / 5.3.6.68+
HIGH 7.8
CVE-2021-0328
In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to…
Android
Patch available