Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2024-30472
Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local acces…
Telemetry Dashboard
Mitigation only
HIGH 8.1
CVE-2024-37325
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
Azure Data Science Virtual Machine
24.05.24+
MEDIUM 5.7
CVE-2024-35263
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Dynamics 365
Patch available
MEDIUM 5.5
CVE-2024-30096
Windows Cryptographic Services Information Disclosure Vulnerability
Windows 10 1809
10.0.17763.5936 / 10.0.19044.4529+
HIGH 7.5
CVE-2024-4266
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in…
Metform Elementor Contact Form Builder
3.8.9+
MEDIUM 6.5
CVE-2020-11843
This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before
Access Manager
4.4+
MEDIUM 6.0
CVE-2024-34684
On Unix, SAP BusinessObjects Business
Intelligence Platform (Scheduling) allows an authenticated attacker with
administrator access on the local serv…
Businessobjects Business Intelligence Platform
Patch available
MEDIUM 5.3
CVE-2024-28164
SAP NetWeaver AS Java (CAF - Guided Procedures)
allows an unauthenticated user to access non-sensitive information about the
server which would other…
Netweaver Application Server Java
Mitigation only
MEDIUM 5.5
CVE-2024-36307
A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive in…
Apex One
after 14.0.13139
HIGH 7.5
CVE-2024-36471
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project administrators can run these imp…
Allura
1.17.0+
MEDIUM 5.5
CVE-2024-27806
This issue was addressed with improved environment sanitization. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS…
Ipados
10.5 / 12.7.5+
MEDIUM 5.3
CVE-2022-32933
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to t…
macOS
12.5+
MEDIUM 6.5
CVE-2024-35691
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Marketing Fire, LLC Widget Options - Extended.This issue affects Widget O…
No fix yet
MEDIUM 5.3
CVE-2024-35682
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a …
Otter Blocks
2.6.12+
MEDIUM 5.3
CVE-2024-35710
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Podlove Podlove Web Player.This issue affects Podlove Web Player: from n/…
No fix yet
HIGH 8.1
CVE-2024-5133
In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses. Specifi…
Lunary
1.2.14+
MEDIUM 6.5
CVE-2024-37150
An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the regis…
Deno
Patch available
HIGH 7.5
CVE-2024-35178
The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attacke…
Jupyter Server
2.14.1+
MEDIUM 5.3
CVE-2024-5615
The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_d…
Open Graph
1.11.3+
MEDIUM 5.3
CVE-2024-0910
The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 due to im…
Restrict For Elementor
1.0.8+
MEDIUM 6.2
CVE-2024-3716
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce…
Satellite
Mitigation only
MEDIUM 5.3
CVE-2024-5483
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.…
Learnpress
4.2.6.8.1+
CRITICAL 9.1
CVE-2024-36121
netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and us…
Netty Incubator Codec Ohttp
0.0.11+
MEDIUM 5.3
CVE-2024-4220
Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.
Beyondinsight
23.1+
MEDIUM 5.3
CVE-2023-49774
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functi…
Mitigation only
MEDIUM 5.3
CVE-2024-34754
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Contact Form Widget.This issue affects Contact Form Widget: fro…
Mitigation only
MEDIUM 5.5
CVE-2024-23107
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0…
Fortiweb
7.0.9 / 7.2.5+
MEDIUM 6.5
CVE-2024-34002
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedba…
Moodle
4.1.10 / 4.2.7+
MEDIUM 5.9
CVE-2024-34003
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore worksh…
Moodle
4.1.10 / 4.2.7+
MEDIUM 6.5
CVE-2024-34004
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki m…
Moodle
4.1.10 / 4.2.7+