Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2024-6562
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3…
Mitigation only
MEDIUM 6.5
CVE-2024-38200EPSS 20%
Microsoft Office Spoofing Vulnerability
365 Apps
Patch available
MEDIUM 5.3
CVE-2024-42493
Dorsett Controls InfoScan is vulnerable due to a leak of possible
sensitive information through the response headers and the rendered
JavaScript pr…
Infoscan
Mitigation only
HIGH 7.5
CVE-2024-39287
Dorsett Controls Central Server update server has potential information
leaks with an unprotected file that contains passwords and API keys.
Infoscan
Mitigation only
MEDIUM 6.5
CVE-2024-7554
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, …
GitLab
17.0.6 / 17.1.4+
MEDIUM 5.3
CVE-2024-6552
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu…
Mitigation only
MEDIUM 6.5
CVE-2024-34788
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive in…
Endpoint Manager Mobile
12.1.0.1+
CRITICAL 9.8
CVE-2024-42394
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploit…
Arubaos
8.10.0.13 / 8.12.0.2+
MEDIUM 6.5
CVE-2024-39817
Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product…
Office
10.8.7+
HIGH 7.5
CVE-2024-42010EPSS 53%
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-m…
Mitigation only
MEDIUM 5.0
CVE-2024-7319
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon …
Openstack Platform
Mitigation only
MEDIUM 5.3
CVE-2024-6567
The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin ut…
Ebook Store
after 5.8001
HIGH 7.5
CVE-2024-38761
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Mana…
Zephyr Project Manager
3.3.100+
CRITICAL 9.1
CVE-2024-41259
Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.
Navidrome
after 0.52.3
HIGH 7.5
CVE-2024-41264
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
Casdoor
Mitigation only
MEDIUM 5.3
CVE-2024-7339EPSS 32%
A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as…
Sh 4050a5 5l\(mm\) Firmware
No fix yet
HIGH 7.5
CVE-2024-6687
The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via…
Ctt Expresso Para Woocommerce
3.2.13+
MEDIUM 5.3
CVE-2024-7328
A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown processing of the file /t.php?a…
Youdiancms
No fix yet
MEDIUM 5.9
CVE-2024-41108
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only …
Fogproject
1.5.10.41+
MEDIUM 6.5
CVE-2024-41109
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user e…
Admin Classic Bundle
1.3.10 / 1.4.6+
MEDIUM 5.3
CVE-2024-41701
AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
No fix yet
MEDIUM 5.3
CVE-2024-41694
Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
No fix yet
HIGH 7.5
CVE-2024-41696
Priority
PRI WEB Portal Add-On for Priority ERP on prem
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
No fix yet
MEDIUM 5.5
CVE-2024-40836
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, w…
Ipados
10.6 / 14.6+
MEDIUM 5.5
CVE-2024-40823
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be ab…
macOS
12.7.6 / 13.6.8+
MEDIUM 5.5
CVE-2024-40793
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monter…
Ipados
10.6 / 12.7.6+
MEDIUM 5.5
CVE-2024-40804
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A malicious application may be able to access private informa…
macOS
14.6+
MEDIUM 5.5
CVE-2024-27884
This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS…
Iphone Os
1.2 / 10.5+
MEDIUM 5.5
CVE-2024-40775
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ven…
macOS
12.7.6 / 13.6.8+
HIGH 7.5
CVE-2024-7156EPSS 13%
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. Affected by this issue is some unknown functionalit…
A3700r Firmware
No fix yet