Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2021-3560 KEVEPSS 22%
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r…
Debian Linux
0.119+
HIGH 7.8
CVE-2021-22042
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privile…
Cloud Foundation
4.4+
HIGH 8.8
CVE-2022-0580
Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.
Librenms
22.2.0+
MEDIUM 6.5
CVE-2022-0309
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a cra…
Chrome
97.0.4692.99+
MEDIUM 6.5
CVE-2022-0117
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Chrome
97.0.4692.71+
MEDIUM 5.5
CVE-2022-23998
Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(…
Camera
9.0.6.68 / 10.5.03.77+
MEDIUM 6.5
CVE-2020-13676
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are…
Drupal
8.9.19 / 9.1.13+
MEDIUM 5.4
CVE-2022-23615
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT ri…
Xwiki
13.0+
MEDIUM 6.8
CVE-2022-23627
ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, …
Archisteamfarm
5.2.2.5 / 5.2.3.2+
MEDIUM 6.5
CVE-2021-24947
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in…
Responsive Vector Maps
6.4.2+
MEDIUM 6.5
CVE-2021-29394
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated user…
Northstar Club Management
Mitigation only
CRITICAL 9.8
CVE-2022-24307
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD si…
Mastodon
3.3.2 / 3.4.6+
MEDIUM 6.5
CVE-2021-25097
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authent…
Labtools
after 1.0
MEDIUM 6.5
CVE-2021-41571
In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API…
Pulsar
2.6.4 / 2.7.3+
MEDIUM 6.5
CVE-2022-0273
Improper Access Control in Pypi calibreweb prior to 0.6.16.
Calibre Web
0.6.16+
HIGH 7.2
CVE-2021-46561
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational ad…
Cve Services
Patch available
HIGH 7.2
CVE-2022-23009
On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-I…
Big Iq Centralized Management
Mitigation only
HIGH 8.8
CVE-2021-4133
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default …
Keycloak
15.1.1+
HIGH 8.1
CVE-2022-21707
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In vers…
Host Runtime
0.52.2+
CRITICAL 9.8
CVE-2020-4877
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo…
Cognos Controller
Mitigation only
HIGH 8.8
CVE-2022-21701
Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation a…
Istio
Mitigation only
CRITICAL 9.3
CVE-2022-22157
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep …
Junos
Mitigation only
CRITICAL 9.8
CVE-2022-22167
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep …
Junos
Mitigation only
HIGH 7.8
CVE-2020-14110
AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web back…
Ax3600 Firmware
1.0.67+
MEDIUM 6.5
CVE-2021-37864
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view conte…
Mattermost
after 6.1
HIGH 7.8
CVE-2021-39630
In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. T…
Android
Mitigation only
MEDIUM 6.5
CVE-2021-4194
bookstack is vulnerable to Improper Access Control
Bookstack
21.12.1+
HIGH 7.5
CVE-2021-45457
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and p…
Kylin
3.1.3+
CRITICAL 9.8
CVE-2021-20149
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing…
Tew 827dru Firmware
Mitigation only
HIGH 8.8
CVE-2021-43858EPSS 35%
MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTT…
Minio
2021-12-27t07-23-18z+