Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2021-36039
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…
Adobe Commerce
after 2.4.2
MEDIUM 5.3
CVE-2021-34434
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is …
Fedora
after 2.0.11
MEDIUM 6.8
CVE-2021-28696
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to…
Fedora
Mitigation only
MEDIUM 5.4
CVE-2021-22256
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status
GitLab
13.12.9 / 14.0.7+
HIGH 8.8
CVE-2021-22236
Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability i…
GitLab
14.1.2+
HIGH 7.5
CVE-2021-39156
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a…
Istio
1.9.8 / 1.10.3+
HIGH 7.5
CVE-2021-39155
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a…
Istio
1.9.8 / 1.10.4+
HIGH 8.3
CVE-2021-32779
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrect…
Envoy
1.16.5 / 1.17.4+
HIGH 8.3
CVE-2021-32777
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz …
Envoy
1.16.5 / 1.17.4+
HIGH 8.6
CVE-2021-30975
This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. This issue is fixed in macOS Monterey 12.1, Securi…
Mac Os X
10.15.7 / 11.6.2+
MEDIUM 5.5
CVE-2021-30987
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.1. A device may be passively tracked via BS…
macOS
12.1+
MEDIUM 5.5
CVE-2021-30972
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-001 Catalina, macOS Big Sur 11.6.3. A malicious applicatio…
Mac Os X
10.15.7 / 11.6.3+
CRITICAL 9.1
CVE-2021-30925
The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious appl…
Ipados
8.0 / 11.6+
CRITICAL 9.1
CVE-2021-30856
This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS…
macOS
11.3+
CRITICAL 9.1
CVE-2021-26040
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
Joomla\!
Mitigation only
MEDIUM 5.4
CVE-2021-22253
Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments t…
GitLab
13.12.9 / 14.0.7+
MEDIUM 5.3
CVE-2021-37598
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
Wp Cerber
8.9.3+
MEDIUM 6.5
CVE-2021-39138
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup use…
Parse Server
4.5.1+
HIGH 7.8
CVE-2021-0645
In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, all…
Android
Patch available
CRITICAL 9.9
CVE-2021-32829
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networki…
Rest Api
3.8.21 / 3.10.8+
CRITICAL 9.8
CVE-2020-18701
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the applicatio…
Lin Cms Flask
No fix yet
CRITICAL 10.0
CVE-2021-37705
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allow…
Onefuzz
2.31.0+
MEDIUM 5.3
CVE-2021-27793
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fa…
Fabric Operating System
8.2.3 / 9.0.1+
HIGH 8.8
CVE-2020-25564
In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing Remote…
Sapphireims
No fix yet
MEDIUM 5.3
CVE-2020-28397
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl…
Cpu 1504d Tf Firmware
2.9.2 / 4.0+
HIGH 8.1
CVE-2021-38137
Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform act…
Securewatch Managed Services
Mitigation only
HIGH 7.2
CVE-2021-33335
Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows re…
Digital Experience Platform
7.3.5+
CRITICAL 9.8
CVE-2020-19301
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condi…
Vaethink
No fix yet
CRITICAL 9.6
CVE-2021-30571
Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious e…
Chrome
92.0.4515.107+
CRITICAL 9.8
CVE-2021-22389
There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.
Emui
Mitigation only