Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.0
CVE-2021-33493
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
Ox App Suite
after 7.10.5
HIGH 8.8
CVE-2021-22053EPSS 13%
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within th…
Spring Cloud Netflix
2.2.10+
CRITICAL 9.8
CVE-2021-41269
cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A te…
Cron Utils
9.1.6+
CRITICAL 9.8
CVE-2021-41653EPSS 76%
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a cr…
Tl Wr840n Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-33816
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, a…
Dolibarr Erp\/crm
No fix yet
HIGH 7.8
CVE-2021-43208
3D Viewer Remote Code Execution Vulnerability
3d Viewer
7.2107.7012.0+
HIGH 7.8
CVE-2021-42296
Microsoft Word Remote Code Execution Vulnerability
365 Apps
Patch available
HIGH 7.8
CVE-2021-42298EPSS 5%
Microsoft Defender Remote Code Execution Vulnerability
Malware Protection Engine
1.1.18700.3+
CRITICAL 9.8
CVE-2021-43466
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
Thymeleaf
No fix yet
MEDIUM 6.5
CVE-2021-24721
The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .ph…
Loco Translate
2.5.4+
HIGH 7.2
CVE-2021-24537
The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened environment (ie with DISALLO…
Similar Posts
after 3.1.5
HIGH 7.8
CVE-2021-41228
TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is vulnerable to a code injectio…
Tensorflow
2.4.4 / 2.5.2+
HIGH 7.8
CVE-2021-42057
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft …
Obsidian Dataview
after 0.4.11
HIGH 7.2
CVE-2021-43281
MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module doe…
Mybb
1.8.29+
MEDIUM 5.0
CVE-2021-42754
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authen…
Forticlient
after 6.4.5
HIGH 7.2
CVE-2021-25877
AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag…
Youphptube
after 10.0
HIGH 8.8
CVE-2021-40348
Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename use…
Uyuni
Patch available
HIGH 8.3
CVE-2021-42694
An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adversary to produce sour…
Unicode
14.0.0+
HIGH 8.3
CVE-2021-42574EPSS 12%
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via …
Fedora
14.0.0+
HIGH 7.5
CVE-2021-36985
There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the…
Emui
Mitigation only
HIGH 7.2
CVE-2021-41619
An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The…
Enterprise
2021.1.2+
HIGH 8.8
CVE-2021-38450
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended c…
Tracer Concierge
4.4 / 5.5+
CRITICAL 9.8
CVE-2020-23037
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web script…
Playable
No fix yet
CRITICAL 9.8
CVE-2021-22961
A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in t…
Glasswire
Mitigation only
HIGH 8.8
CVE-2021-29679
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled inp…
Cognos Analytics
Patch available
HIGH 7.8
CVE-2021-40485
Microsoft Excel Remote Code Execution Vulnerability
365 Apps
Patch available
HIGH 8.1
CVE-2021-40487EPSS 48%
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Enterprise Server
Patch available
CRITICAL 9.8
CVE-2021-40499
Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD,…
Netweaver Application Server Abap
Mitigation only
HIGH 8.8
CVE-2021-24546
The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Vis…
Editorskit
1.31.6+
CRITICAL 9.8
CVE-2021-40889
CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents…
Cmsuno
No fix yet