Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2021-32809
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](htt…
Fedora
4.16.2 / 21.1.4+
HIGH 7.2
CVE-2021-37626
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files …
Contao
4.4.56 / 4.9.18+
HIGH 7.8
CVE-2021-37694
@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection …
Java Spring Cloud Stream Template
0.7.0+
CRITICAL 9.8
CVE-2021-38196
An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitr…
Better Macro
after 2021-07-22
CRITICAL 9.1
CVE-2021-36800
Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/…
Akaunting
2.1.13+
HIGH 8.8
CVE-2021-32706EPSS 60%
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface ve…
Pi Hole
5.5.1+
HIGH 8.8
CVE-2021-31630EPSS 27%
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/har…
Openplc V3 Firmware
No fix yet
HIGH 7.2
CVE-2021-24430
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_qu…
Speed Booster Pack
4.2.0+
HIGH 8.8
CVE-2017-18113
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system admi…
Data Center
8.18.1+
CRITICAL 9.8
CVE-2020-18172
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.
Bridge
No fix yet
HIGH 7.8
CVE-2021-25808
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
Bludit
No fix yet
HIGH 8.8
CVE-2021-1518
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbi…
Firepower Device Manager On Box
6.4.0 / 6.7.0.2+
HIGH 8.8
CVE-2021-32756
ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module o…
Manageiq
Mitigation only
HIGH 8.1
CVE-2021-32749
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0…
Fedora
0.10.7 / 0.11.3+
MEDIUM 6.5
CVE-2021-33678
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75…
Netweaver Application Server Abap
No fix yet
CRITICAL 9.8
CVE-2021-23390
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
Total4
0.0.43+
CRITICAL 9.8
CVE-2021-23389
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
Total.js
3.4.9+
HIGH 8.1
CVE-2021-1585EPSS 20%
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary co…
Adaptive Security Device Manager
7.18.1.152+
HIGH 8.8
CVE-2020-23219
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" …
Monstra Cms
No fix yet
CRITICAL 9.8
CVE-2021-35514
Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
Narou
3.8.0+
CRITICAL 9.8
CVE-2020-21784
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
Phpwcms
No fix yet
HIGH 8.8
CVE-2020-22201
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
Phpcms
No fix yet
MEDIUM 5.5
CVE-2021-25415
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writ…
Android
Mitigation only
MEDIUM 6.5
CVE-2021-25416
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel…
Android
Mitigation only
MEDIUM 5.5
CVE-2021-25393
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system ui…
Android
No fix yet
HIGH 7.3
CVE-2021-31949
Microsoft Outlook Remote Code Execution Vulnerability
365 Apps
Patch available
CRITICAL 9.8
CVE-2021-32673
reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin throu…
Reg Keygen Git Hash
after 0.10.15
HIGH 7.5
CVE-2021-22336
There is an Improper Control of Generation of Code vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause denial…
Emui
Mitigation only
HIGH 8.8
CVE-2021-32924EPSS 20%
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages…
Ips Community Suite
4.6.0+
HIGH 7.2
CVE-2021-24312
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of …
Wp Super Cache
1.7.3+