Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-33912EPSS 10%
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated …
Debian Linux
1.2.11+
CRITICAL 9.8
CVE-2022-23221EPSS 65%
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FO…
Debian Linux
2.0.206+
CRITICAL 9.8
CVE-2022-23218
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on t…
Debian Linux
2.31+
CRITICAL 9.8
CVE-2022-23219
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on …
Debian Linux
2.31+
CRITICAL 9.8
CVE-2022-22822
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Debian Linux
2.4.3 / 3.1+
CRITICAL 9.8
CVE-2022-22823
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Debian Linux
2.4.3 / 3.1+
CRITICAL 9.8
CVE-2022-22824
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Debian Linux
2.4.3 / 3.1+
CRITICAL 9.8
CVE-2021-42392EPSS 63%
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attack…
Debian Linux
after 2.0.204
CRITICAL 9.1
CVE-2021-43845
PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data fi…
Debian Linux
after 2.11.1
CRITICAL 9.8
CVE-2021-40393
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a…
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2021-40394
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a…
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2021-37706
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…
Debian Linux
16.8.0 / 16.24.1+
CRITICAL 9.8
CVE-2021-44732
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
Debian Linux
2.16.12 / 2.28.0+
CRITICAL 9.8
CVE-2021-23450EPSS 30%
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Debian Linux
1.17.0+
CRITICAL 9.8
CVE-2021-43113EPSS 5%
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghost…
Debian Linux
7.1.17+
CRITICAL 9.8
CVE-2021-44538
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic…
Debian Linux
1.6.0 / 1.9.7-sc1+
CRITICAL 9.8
CVE-2021-44143
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted ma…
Debian Linux
after 1.4.3
CRITICAL 9.8
CVE-2021-40391
An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forke…
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2021-3918
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Debian Linux
0.4.0+
CRITICAL 9.8
CVE-2021-3907
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr…
Debian Linux
1.3.0+
CRITICAL 9.1
CVE-2021-43400
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu…
Debian Linux
Patch available
CRITICAL 9.6
CVE-2021-3693
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, thi…
Debian Linux
after 1.8.17
CRITICAL 9.6
CVE-2021-3694
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this fla…
Debian Linux
after 1.8.17
CRITICAL 9.8
CVE-2021-38171
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the sec…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2021-38173
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorize…
Debian Linux
0.31.2+
CRITICAL 9.1
CVE-2021-35942
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called…
Debian Linux
2.31+
CRITICAL 9.8
CVE-2021-33833
ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A …
Debian Linux
after 1.39
CRITICAL 9.1
CVE-2020-36330
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this …
Debian Linux
1.0.1 / 14.7+
CRITICAL 9.8
CVE-2021-20204
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This …
Debian Linux
Mitigation only
CRITICAL 9.8
CVE-2021-31870
An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer…
Debian Linux
2.0.9+