Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2021-45339
Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process wh…
Antivirus
20.4+
HIGH 8.2
CVE-2021-23175
NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls f…
Geforce Experience
3.24.0.126+
HIGH 8.8
CVE-2021-38016
Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via…
Chrome
96.0.4664.45+
HIGH 8.8
CVE-2021-38017
Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions …
Chrome
96.0.4664.45+
CRITICAL 9.8
CVE-2021-23803
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When th…
Latte
2.10.6+
HIGH 8.8
CVE-2021-45102
An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may…
Htcondor
Mitigation only
HIGH 7.8
CVE-2021-0649
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CO…
Android
Mitigation only
MEDIUM 6.5
CVE-2021-24872
The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validat…
Get Custom Field Values
4.0+
HIGH 8.8
CVE-2021-41805EPSS 35%
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default…
Consul
1.8.17 / 1.9.11+
HIGH 8.7
CVE-2021-29678
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access o…
Db2
Mitigation only
CRITICAL 10.0
CVE-2021-38503
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navig…
Firefox
91.3 / 94.0+
MEDIUM 5.3
CVE-2021-41013
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Re…
Fortiweb
after 6.3.15
HIGH 8.8
CVE-2021-42758
An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to …
Fortiwlc
after 8.5.5
HIGH 7.5
CVE-2021-24917EPSS 72%
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a …
Wps Hide Login
1.9.1+
MEDIUM 5.4
CVE-2021-24842
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private…
Bulk Datetime Change
1.12+
MEDIUM 5.3
CVE-2021-43560
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks…
Moodle
3.9.11 / 3.10.8+
HIGH 8.8
CVE-2021-22966
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulk…
Concrete Cms
8.5.7+
MEDIUM 6.8
CVE-2021-39234
In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blo…
Ozone
1.2.0+
HIGH 7.2
CVE-2021-41244
Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enable…
Grafana
8.2.4+
HIGH 8.8
CVE-2021-3577EPSS 60%
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on …
Halo\+ Camera Firmware
03.40.00 / 03.40.02+
MEDIUM 5.3
CVE-2021-1903
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snap…
Aqt1000 Firmware
Mitigation only
HIGH 7.1
CVE-2021-20119
The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrato…
Arris Surfboard Sb8200 Firmware
No fix yet
MEDIUM 6.5
CVE-2021-42025
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions…
Mendix
8.18.13 / 9.6.2+
MEDIUM 6.5
CVE-2021-24783
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contr…
Post Expirator
2.6.0+
MEDIUM 6.5
CVE-2021-24788
The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a res…
Batch Cat
after 0.3
MEDIUM 6.5
CVE-2021-22051
Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. User…
Spring Cloud Gateway
2.2.10 / 3.0.5+
HIGH 8.8
CVE-2021-41230
Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflect…
Pomerium
0.15.6+
MEDIUM 5.5
CVE-2021-25506
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
Health
6.19.1.0001+
CRITICAL 9.8
CVE-2021-21693
When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earli…
Jenkins
2.303.3 / 2.319+
HIGH 8.2
CVE-2021-39341EPSS 22%
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorizatio…
Optinmonster
after 2.6.4