Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2024-42049
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
Mitigation only
MEDIUM 5.3
CVE-2024-5614
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 vi…
Mitigation only
MEDIUM 5.3
CVE-2024-6569
The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is d…
Mitigation only
MEDIUM 5.3
CVE-2024-6573
The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0. This is due the plugin not p…
Mitigation only
MEDIUM 5.3
CVE-2024-6546
The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due to t…
Mitigation only
MEDIUM 5.3
CVE-2024-6547
The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin …
Mitigation only
MEDIUM 5.3
CVE-2024-6548
The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to the plu…
Mitigation only
MEDIUM 5.3
CVE-2024-6549
The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to the pl…
Mitigation only
MEDIUM 5.3
CVE-2024-6566
The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due …
Mitigation only
MEDIUM 5.3
CVE-2024-6545
The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to the p…
Mitigation only
MEDIUM 5.3
CVE-2024-7128
A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions.…
Mitigation only
MEDIUM 5.0
CVE-2024-7091
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting f…
GitLab
17.0.5 / 17.1.3+
MEDIUM 6.5
CVE-2024-7060
An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1…
GitLab
17.0.5 / 17.1.3+
HIGH 7.5
CVE-2024-41672
DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading using `sniff_csv`, even with…
Duckdb
1.1.0+
HIGH 7.5
CVE-2024-39676
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot.
This issue affects Apache Pinot: from 0.1 before 1.0.0.
U…
Pinot
1.0.0+
MEDIUM 5.3
CVE-2024-6553
The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.3…
Wp Meteor
3.4.4+
MEDIUM 5.3
CVE-2024-6571
The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and…
Optimize Images Alt Text \(alt Tag\) \& Names For Seo Using Ai
3.1.2+
HIGH 8.8
CVE-2024-23321
For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even i…
Rocketmq
5.3.0+
MEDIUM 5.3
CVE-2024-6560
The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. Th…
Mitigation only
MEDIUM 5.3
CVE-2024-6455
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a miss…
Elements Kit Elementor Addons
3.2.1+
MEDIUM 5.3
CVE-2024-40647
sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocess…
Patch available
MEDIUM 5.3
CVE-2024-40633
Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, whi…
Mitigation only
MEDIUM 6.5
CVE-2024-20396
A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information.
…
Webex Teams
Mitigation only
HIGH 8.1
CVE-2024-21152
Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Allocation Rules). Supported versions th…
Process Manufacturing Financials
after 12.2.13
HIGH 7.4
CVE-2024-21147
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo…
Active Iq Unified Manager
Mitigation only
HIGH 8.6
CVE-2024-21136
Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected a…
Retail Xstore Office
Mitigation only
MEDIUM 5.3
CVE-2024-6395
An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories…
Enterprise Server
3.9.17 / 3.10.14+
MEDIUM 5.3
CVE-2024-6336
A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterp…
Enterprise Server
3.9.17 / 3.10.14+
MEDIUM 6.3
CVE-2020-25836
Exposure of Sensitive Information
to an Unauthorized Access vulnerability in OpenText NetIQ Directory and
Resource Administrator. This issue affects …
Mitigation only
MEDIUM 6.5
CVE-2022-45449
Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15…
Cyber Protect
15+