Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-42006
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.
Aws Orchestrator
2.01+
HIGH 7.5
CVE-2024-41700
Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Sip Client Firmware
No fix yet
HIGH 7.5
CVE-2024-41698
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Priority
24.0+
HIGH 7.5
CVE-2024-7925
A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/e…
Zzcms
No fix yet
CRITICAL 9.8
CVE-2024-42658
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
Ntpl Xpon1gfevn Firmware
Mitigation only
HIGH 7.5
CVE-2024-42657
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption dur…
Ntpl Xpon1gfevn Firmware
Mitigation only
HIGH 7.2
CVE-2024-42486
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1…
Cilium
after 1.15.8
HIGH 7.5
CVE-2024-7630
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2…
Relevanssi
4.23.0+
HIGH 7.5
CVE-2024-7843
A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function …
Online Graduate Tracer System
No fix yet
HIGH 7.5
CVE-2024-7842
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unk…
Online Graduate Tracer System
No fix yet
MEDIUM 6.1
CVE-2024-27731
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filterin…
Friendica
Patch available
MEDIUM 5.3
CVE-2024-7411
The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not pr…
Mitigation only
HIGH 7.5
CVE-2024-27120
A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacke…
Comfortkey
24.1.2+
MEDIUM 6.5
CVE-2024-39822
Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an …
Workplace Desktop
6.0.12 / 6.1.0+
HIGH 7.5
CVE-2024-38749
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality N…
Olive One Click Demo Import
after 1.1.2
MEDIUM 5.3
CVE-2024-38756
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrai…
Mitigation only
MEDIUM 5.3
CVE-2024-38760
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Accessing Functionality Not Properl…
Mitigation only
MEDIUM 5.3
CVE-2024-38742
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Accessing Functionality Not Properl…
Mitigation only
HIGH 7.5
CVE-2024-38747
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce a…
Mitigation only
MEDIUM 5.3
CVE-2024-41733
In SAP Commerce, valid user accounts can be
identified during the customer registration and login processes. This allows a
potential attacker to lear…
Commerce
Mitigation only
CRITICAL 9.1
CVE-2024-33003
Some OCC API endpoints in SAP Commerce Cloud
allows Personally Identifiable Information (PII) data, such as passwords, email
addresses, mobile number…
Commerce Cloud
Mitigation only
MEDIUM 5.3
CVE-2024-37924
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Cons…
Mitigation only
HIGH 7.5
CVE-2024-7704
A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/…
E Cology
No fix yet
HIGH 7.5
CVE-2024-7697
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
Carlcare
No fix yet
MEDIUM 5.3
CVE-2024-7412
The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin …
No Update Nag
after 1.4.12
MEDIUM 5.3
CVE-2024-7413
The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin…
Mitigation only
MEDIUM 5.3
CVE-2024-7414
The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.116. This is due to …
Mitigation only
MEDIUM 5.3
CVE-2024-7416
The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7. This is due to the plugin a…
Mitigation only
MEDIUM 5.3
CVE-2024-7382
The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1. This is due to the plugin ut…
Mitigation only
MEDIUM 5.3
CVE-2024-7410
The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.3. This is due the plu…
Mitigation only