Vulnerabilities
Summary — last 7 days
New vulnerabilities2,716▼ 25 vs. last week
Critical / high1,269▼ 244 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
268 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.2) | 1.3% | — | Hitachienergy Counterparty Settlement AND BillingHitachienergy Retail Operations | 8/20/2021 | 6/17/2026 | Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database credentials, shut down the product and access or alter. This issue affects: Hitachi ABB Power Grids… | |
| Modified | Critical (9.8) | 1.1% | — | Water Billing System Project Water Billing System | 7/22/2021 | 6/17/2026 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php. | |
| Modified | High (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 7/21/2021 | 8/25/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modified | High (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+20 | 7/13/2021 | 6/17/2026 | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | |
| Modified | High (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+22 | 7/13/2021 | 6/17/2026 | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | |
| Modified | High (7.5) | 13% | — | Apache Commons CompressOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Enterprise Default Management+30 | 7/13/2021 | 10/8/2026 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package. | |
| Modified | High (7.5) | 11% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Apis+23 | 7/13/2021 | 10/8/2026 | When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package. | |
| Modified | Medium (4.8) | 11% | 💥 PoC | Apache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+56 | 4/13/2021 | 10/7/2026 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling… | |
| Modified | Low (3.7) | 3.1% | — | Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+7 | 4/1/2021 | 6/17/2026 | curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server… | |
| Modified | Medium (5.3) | 5.3% | — | Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+8 | 4/1/2021 | 6/17/2026 | curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP… | |
| Analyzed | Critical (9.1) | 82% | 💥 Exploit | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to… | |
| Analyzed | Critical (9.8) | 15% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analyzed | High (8.6) | 47% | 💥 PoC | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+13 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed… | |
| Analyzed | High (7.5) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analyzed | Critical (9.8) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analyzed | Critical (9.8) | 76% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analyzed | Critical (9.9) | 72% | 💥 Exploit | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the… | |
| Analyzed | Critical (9.8) | 76% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analyzed | High (7.5) | 47% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+11 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.… | |
| Analyzed | High (7.5) | 78% | 💥 PoC | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+9 | 3/22/2021 | 10/7/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by… | |
| Modified | Medium (5.4) | 2.0% | 💥 Exploit | Ultimatekode NEO Billing | 3/2/2021 | 6/17/2026 | Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote attackers to inject arbitrary web script or HTML. | |
| Modified | High (7.8) | 1.1% | 💥 PoC | Gnupg LibgcryptOracle Communications Billing AND Revenue Management | 1/29/2021 | 6/17/2026 | _gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later. | |
| Modified | Medium (4.3) | 0.80% | — | Oracle Financial Services Revenue Management AND Billing | 1/20/2021 | 6/17/2026 | Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: On Demand Billing). Supported versions that are affected are 2.9.0.0 and 2.9.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modified | Medium (4.3) | 0.43% | — | Totalonlinesolutions Advanced Webhost Billing System | 1/8/2021 | 6/17/2026 | Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page. | |
| Modified | High (8.1) | 4.1% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 1/7/2021 | 8/25/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS. |