Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2021-24742
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action bec…
Logo Slider And Showcase
1.3.37+
MEDIUM 5.3
CVE-2021-24757
The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unau…
Stylish Price List
6.9.0+
MEDIUM 6.5
CVE-2021-24770
The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authentic…
Stylish Price List
6.9.1+
HIGH 8.8
CVE-2021-24717
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, d…
Automatorwp
1.7.6+
HIGH 7.2
CVE-2021-41189
DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up t…
Dspace
Patch available
HIGH 8.8
CVE-2021-39321
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action…
Sassy Social Share
Patch available
MEDIUM 6.5
CVE-2021-38345
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in…
Brizy Page Builder
1.0.1.126+
MEDIUM 5.4
CVE-2021-20803
Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the dat…
Remote Service Manager
Mitigation only
MEDIUM 5.3
CVE-2021-40456
Windows AD FS Security Feature Bypass Vulnerability
Windows Server
Patch available
MEDIUM 5.3
CVE-2021-42137
An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of ticke…
Zammad
5.0.1+
CRITICAL 9.8
CVE-2021-41093
Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by …
Wire
3.86+
MEDIUM 6.5
CVE-2021-24652
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform som…
Postx Gutenberg Blocks For Post Grid
2.4.10+
MEDIUM 6.5
CVE-2021-40654
An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the /…
Dir 615 Firmware
No fix yet
HIGH 7.5
CVE-2021-40655 KEVEPSS 87%
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a po…
Dir 605l Firmware
Mitigation only
MEDIUM 6.5
CVE-2021-36749EPSS 81%
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate…
Druid
0.22.0+
MEDIUM 6.5
CVE-2021-34647
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/R…
Ninja Forms
after 3.5.7
HIGH 8.8
CVE-2020-19551
Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.
Wuzhicms
after 4.1.0
HIGH 7.5
CVE-2021-41082
Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user…
Discourse
2021-09-14+
MEDIUM 6.8
CVE-2020-16630
TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just W…
15.4 Stack
No fix yet
MEDIUM 5.3
CVE-2019-16651
An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechani…
Super Hub 3 Firmware
No fix yet
HIGH 7.5
CVE-2021-40639
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.confi…
Jfinal Cms
No fix yet
CRITICAL 9.8
CVE-2020-21124
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
Ureport
No fix yet
HIGH 8.6
CVE-2021-39206
Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-202…
Envoy
0.14.8 / 1.16.5+
CRITICAL 9.8
CVE-2021-28911
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. devi…
Eibport Firmware
3.9.1+
MEDIUM 6.5
CVE-2021-28567
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in …
Magento
after 2.4.2
HIGH 7.8
CVE-2021-35526
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensi…
Sdm600 Firmware
1.2.14002.257+
HIGH 7.5
CVE-2020-19765
An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a reentrancy attack.
Proofofdiligencetoken
No fix yet
MEDIUM 5.3
CVE-2021-35949
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list meta…
Owncloud
10.8.0+
MEDIUM 6.5
CVE-2021-38312
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints regis…
Gutenberg Template Library \& Redux Framework
after 4.2.11
MEDIUM 5.3
CVE-2021-39119
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even afte…
Data Center
8.19.0+