Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-42139
Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
Deno Standard Modules
0.107.0+
HIGH 8.8
CVE-2020-21650
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() meth…
Myucms
No fix yet
CRITICAL 9.8
CVE-2020-21651
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() metho…
Myucms
No fix yet
CRITICAL 9.8
CVE-2020-21652
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() me…
Myucms
No fix yet
HIGH 7.9
CVE-2021-25470
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
Android
Mitigation only
HIGH 7.8
CVE-2021-22557
SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Genera…
Slo Generator
2.0.1+
CRITICAL 9.8
CVE-2021-40323EPSS 87%
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
Cobbler
after 3.3.0
HIGH 8.8
CVE-2020-20124
Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
Wuzhicms
No fix yet
HIGH 8.8
CVE-2021-22952
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequen…
Unifi Talk
after 1.12.3
HIGH 7.1
CVE-2021-3583
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i…
Ansible Automation Platform
2.9.23 / 3.7.0+
HIGH 7.2
CVE-2021-39402
MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate m…
Maianaffiliate
No fix yet
HIGH 7.2
CVE-2021-39128
Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators acc…
Jira Data Center
8.13.12 / 8.19.1+
MEDIUM 6.8
CVE-2021-33693
SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potenti…
Cloud Connector
Patch available
CRITICAL 9.8
CVE-2021-40373
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that …
Playsms
1.4.5+
HIGH 8.1
CVE-2021-32836
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserializat…
Zstack
3.10.12 / 4.1.6+
CRITICAL 9.9
CVE-2021-32834
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy…
Keti
No fix yet
HIGH 7.2
CVE-2021-39503
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker ca…
Phpmywind
No fix yet
HIGH 7.2
CVE-2021-39115
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arb…
Jira Service Desk
4.13.9 / 4.18.0+
HIGH 7.2
CVE-2021-32831
Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django …
Total.js
3.4.9+
CRITICAL 9.8
CVE-2021-29772
IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.
Api Connect
after 5.0.8.11
HIGH 7.2
CVE-2020-19822
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" an…
Zzcms
No fix yet
CRITICAL 9.8
CVE-2021-39159
BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In a…
Binderhub
0.2.0-n653+
HIGH 8.8
CVE-2021-39160
nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted li…
Nbgitpuller
0.10.2+
CRITICAL 9.8
CVE-2021-40084
opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execut…
Opensysusers
after 0.6
HIGH 8.5
CVE-2021-39144 KEVEPSS 98%
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…
Debian Linux
1.4.18+
HIGH 8.8
CVE-2020-22120
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitr…
Imcat
Patch available
CRITICAL 9.8
CVE-2020-22937
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to th…
Empirecms
No fix yet
MEDIUM 6.8
CVE-2021-3615
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file exists on the attached SD card…
Smart Camera C2e Firmware
01.03.29.16+
CRITICAL 9.9
CVE-2021-32829
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networki…
Rest Api
3.8.21 / 3.10.8+
MEDIUM 5.3
CVE-2021-32822
The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnera…
Hbs
No fix yet