Top 4 vulnerabilities
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
In Spring Security versions 5.5.6 and 5.5.7 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
We collect the tweet related to vulnerability, then process them to create rankings and graphs.
The CVSS is a good value to think about the severity of the vulnerability. But the popularity is also should be considered as a good barometer. Because when the vulnerability becomes very popular, it is very likely to have more attacks.