Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2021-31552
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts…
Mediawiki
after 1.35.2
MEDIUM 5.4
CVE-2021-31554
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks for certain automatically cre…
Mediawiki
after 1.35.2
CRITICAL 9.8
CVE-2021-28793
vscode-restructuredtext before 146.0.0 contains an incorrect access control vulnerability, where a crafted project folder could execute arbitrary bin…
Restructuredtext
147.0.0+
HIGH 7.8
CVE-2021-3493 KEVEPSS 49%
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files …
Ubuntu Linux
18.04 / 20.04+
MEDIUM 6.5
CVE-2021-29452
a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0…
A12n Server
0.18.2+
HIGH 7.8
CVE-2021-28825
The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Mes…
Messaging Eclipse Mosquitto Distribution Core
after 1.3.0
HIGH 7.8
CVE-2021-28826
The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO M…
Messaging Eclipse Mosquitto Distribution Bridge
after 1.3.0
MEDIUM 6.8
CVE-2021-29437
ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and mod…
Scratchoauth2
2021-04-13+
HIGH 7.2
CVE-2021-29439
The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.logi…
Grav Admin
1.10.11+
HIGH 7.8
CVE-2021-27086
Windows Services and Controller App Elevation of Privilege Vulnerability
Windows 10
Patch available
CRITICAL 9.1
CVE-2021-29943EPSS 5%
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests usi…
Solr
8.8.2+
HIGH 7.5
CVE-2019-15059
In Liberty lisPBX 2.0-4, configuration backup files can be retrieved remotely from /backup/lispbx-CONF-YYYY-MM-DD.tar or /backup/lispbx-CDR-YYYY-MM-D…
Lispbx
Mitigation only
CRITICAL 9.8
CVE-2020-28872
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to crea…
Monitorr
No fix yet
HIGH 8.8
CVE-2021-25356
An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary a…
Android
No fix yet
MEDIUM 5.3
CVE-2020-36287EPSS 9%
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from ve…
Data Center
8.13.5 / 8.15.1+
MEDIUM 5.5
CVE-2020-14106
The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.…
Miui
2021.01.26+
MEDIUM 6.3
CVE-2020-27901
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update…
macOS
11.0.1 / 11.1.0+
MEDIUM 5.5
CVE-2021-26718
KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.
Internet Security
21.1+
MEDIUM 5.3
CVE-2020-36238
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.…
Data Center
8.5.13 / 8.13.5+
MEDIUM 5.3
CVE-2021-29642
GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of GitHub access tokens.
Gistpad
0.2.7+
HIGH 7.5
CVE-2021-28936
The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET …
Wireless N Wifi Repeater Firmware
No fix yet
HIGH 8.8
CVE-2021-21389EPSS 14%
BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-pr…
Buddypress
7.2.1+
MEDIUM 5.5
CVE-2021-21411
OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group…
Oauth2 Proxy
7.1.0+
MEDIUM 5.9
CVE-2021-27195
Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic.
Vision Pro
after 9.7.1
HIGH 7.8
CVE-2021-28821
The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, a…
Enterprise Message Service
after 8.5.1
HIGH 7.8
CVE-2021-28823
The Windows Installation component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterpri…
Eftl
6.6.0+
HIGH 8.8
CVE-2021-28824
The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO…
Activespaces
4.6.0+
HIGH 7.8
CVE-2021-28819
The Windows Installation component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise …
Ftl
6.6.0+
MEDIUM 6.5
CVE-2021-28146
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authent…
Grafana
7.4.5+
HIGH 7.8
CVE-2021-28791
The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a maliciou…
Swiftformat
1.3.7+