Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2024-11291
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive …
Membership \& Content Restriction Paid Member Subscriptions
2.13.5+
MEDIUM 5.3
CVE-2024-11295
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 …
Mitigation only
MEDIUM 5.3
CVE-2024-12250
The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includin…
Mitigation only
MEDIUM 5.3
CVE-2024-11280
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 vi…
Mitigation only
HIGH 8.8
CVE-2024-8326
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable …
Mitigation only
MEDIUM 5.3
CVE-2024-11294
The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress cor…
Mitigation only
MEDIUM 5.5
CVE-2021-26281
Some parameters of the alarm clock module are improperly stored, leaking some sensitive information.
No fix yet
MEDIUM 5.9
CVE-2021-26279
Some parameters of the weather module are improperly stored, leaking some sensitive information.
No fix yet
MEDIUM 5.3
CVE-2024-35230
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and…
Geoserver
2.25.1+
MEDIUM 5.3
CVE-2024-12578
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via …
Mitigation only
HIGH 8.7
CVE-2024-55946
Playloom Engine is an open-source, high-performance game development engine. Engine Beta v0.0.1 has a security vulnerability related to data storage,…
Mitigation only
MEDIUM 5.3
CVE-2024-9945
An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resou…
Mitigation only
CRITICAL 9.8
CVE-2024-55875
http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vuln…
Patch available
HIGH 7.5
CVE-2024-54119
Cross-process screen stack vulnerability in the UIExtension module
Impact: Successful exploitation of this vulnerability may affect service confident…
Harmonyos
No fix yet
HIGH 7.5
CVE-2024-54117
Cross-process screen stack vulnerability in the UIExtension module
Impact: Successful exploitation of this vulnerability may affect service confident…
Harmonyos
No fix yet
MEDIUM 6.9
CVE-2024-12564
Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installi…
Mitigation only
MEDIUM 5.3
CVE-2024-12255
The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 …
Accept Stripe Payments Using Contact Form 7
2.6+
MEDIUM 5.3
CVE-2024-11351
The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Expos…
Mitigation only
MEDIUM 5.3
CVE-2024-11008
The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in…
Mitigation only
MEDIUM 5.7
CVE-2024-53244
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2403.109, and 9.1.2312.206, a …
Splunk
9.1.7 / 9.1.2312.206+
MEDIUM 5.3
CVE-2024-11106
The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the WordPres…
Mitigation only
HIGH 7.5
CVE-2024-54151
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting…
Directus
11.3.0+
HIGH 7.5
CVE-2024-54137
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been iden…
Liboqs
0.12.0+
MEDIUM 5.3
CVE-2024-11292
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the …
Mitigation only
HIGH 8.3
CVE-2024-54134
A publish-access account was compromised for `@solana/web3.js`, a JavaScript library that is commonly used by Solana dapps. This allowed an attacker …
Mitigation only
HIGH 7.5
CVE-2024-53862
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When using `--auth-mode=client`, Arc…
Argo Workflows
3.5.13 / 3.6.2+
HIGH 7.5
CVE-2024-11961
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This issue affects the function pre…
Jeewms
No fix yet
MEDIUM 6.5
CVE-2024-53858
The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that could leak authentication toke…
Mitigation only
HIGH 7.5
CVE-2024-53859
go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerability has been identified in …
Go Gh
2.11.1+
HIGH 8.1
CVE-2024-52323
Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve s…
Manageengine Analytics Plus
6.1+