Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-3488
File Upload vulnerability in unauthenticated
session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a
f…
Imanager
3.2.6+
CRITICAL 9.8
CVE-2024-3968
Remote Code
Execution has been discovered in
OpenText™ iManager 3.2.6.0200. The vulnerability can
trigger remote code execution using custom file upl…
Imanager
3.2.6+
MEDIUM 6.4
CVE-2024-2248
A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over …
Mitigation only
HIGH 7.8
CVE-2024-34098
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitr…
Acrobat Dc
20.005.30635 / 20.005.30636+
HIGH 7.2
CVE-2021-22280
Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the co…
Automation Studio
4.12+
HIGH 7.5
CVE-2024-3676
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthentic…
Mitigation only
MEDIUM 6.5
CVE-2024-30054
Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability
Powerbi Javascript
2.23.1+
HIGH 8.8
CVE-2024-30040 KEV
Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows 10 1507
10.0.10240.20651 / 10.0.14393.6981+
MEDIUM 6.8
CVE-2024-30002
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows 10 1809
10.0.17763.5820 / 10.0.19044.4412+
MEDIUM 6.8
CVE-2024-29998
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows 10 1809
10.0.17763.5820 / 10.0.19044.4412+
HIGH 7.5
CVE-2024-3372
Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and m…
MongoDB
5.0.25 / 6.0.14+
MEDIUM 6.5
CVE-2024-25970
Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could pote…
Powerscale Onefs
9.4.0.18 / 9.5.0.8+
CRITICAL 9.1
CVE-2024-34365
** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave.
A…
Karaf Cave
Mitigation only
HIGH 7.5
CVE-2024-32992
Insufficient verification vulnerability in the baseband module
Impact: Successful exploitation of this vulnerability will affect availability.
Emui
No fix yet
HIGH 7.5
CVE-2024-32989
Insufficient verification vulnerability in the system sharing pop-up module
Impact: Successful exploitation of this vulnerability will affect availab…
Emui
No fix yet
HIGH 7.5
CVE-2024-32990
Permission verification vulnerability in the system sharing pop-up module
Impact: Successful exploitation of this vulnerability will affect availabil…
Emui
No fix yet
MEDIUM 5.3
CVE-2024-32669
Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers.
However, it occurs in the test cod…
Patch available
MEDIUM 5.3
CVE-2024-32672
A Segmentation Fault issue discovered in
Samsung Open Source Escargot JavaScript engine
allows remote attackers to cause a denial of service via …
Patch available
HIGH 7.5
CVE-2024-30258
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.…
Fast Dds
2.6.8 / 2.10.4+
CRITICAL 9.1
CVE-2024-2257
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of passwor…
Mitigation only
HIGH 7.2
CVE-2024-25641EPSS 86%
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable …
Fedora
1.2.27+
HIGH 7.5
CVE-2024-25581
When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker…
Mitigation only
HIGH 8.4
CVE-2024-1929
Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Confidentiality and Integrity v…
Dnf5
5.1.17+
HIGH 8.8
CVE-2024-2746
Incomplete fix for CVE-2024-1929
The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary configuration parameters from unpr…
Mitigation only
MEDIUM 5.5
CVE-2024-0022
In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profil…
Android
Patch available
HIGH 7.8
CVE-2024-23705
In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local…
Android
Patch available
HIGH 7.8
CVE-2024-23706
In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation…
Android
Patch available
HIGH 7.8
CVE-2024-23707
In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with…
Android
Patch available
HIGH 7.5
CVE-2024-32371
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administra…
Mailinspector
5.2.19+
MEDIUM 5.8
CVE-2023-7240
An improper authorization level has been detected in the login panel. It may lead to
unauthenticated Server Side Request Forgery and allows to perfo…
Mitigation only