Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2024-34005
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore databa…
Moodle
4.1.10 / 4.2.7+
MEDIUM 6.5
CVE-2021-44534
Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.
Mitigation only
MEDIUM 5.3
CVE-2024-5524
Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal li…
Astrotalks
Mitigation only
MEDIUM 6.5
CVE-2024-35189
Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records a…
Fides
2.37.0+
HIGH 7.7
CVE-2024-36955
In the Linux kernel, the following vulnerability has been resolved:
ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node()
The docum…
Linux Kernel
5.15.159 / 6.1.91+
HIGH 8.4
CVE-2024-36910
In the Linux kernel, the following vulnerability has been resolved:
uio_hv_generic: Don't free decrypted memory
In CoCo VMs it is possible for the …
Linux Kernel
6.1.91 / 6.6.31+
HIGH 8.6
CVE-2024-24919 KEVEPSS 100%
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote …
Quantum Spark Firmware
Patch available
MEDIUM 5.3
CVE-2024-36107
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` heade…
Patch available
HIGH 7.5
CVE-2024-35341
Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET request to /ConfigFile.ini or …
Mitigation only
CRITICAL 9.8
CVE-2024-35343
Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP GET request to the /playback/…
Mitigation only
MEDIUM 6.5
CVE-2024-5354
A vulnerability classified as problematic was found in anji-plus AJ-Report up to 1.4.1. This vulnerability affects unknown code of the file /reportSh…
Aj Report
after 1.4.1
HIGH 7.7
CVE-2024-5202
Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservices
Mitigation only
MEDIUM 5.3
CVE-2024-28188
Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-schedu…
Patch available
MEDIUM 5.3
CVE-2024-35223
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app in…
Patch available
MEDIUM 5.3
CVE-2024-5230EPSS 19%
A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functio…
No fix yet
HIGH 8.1
CVE-2024-21902
An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploit…
Qts
Mitigation only
HIGH 7.1
CVE-2021-47403
In the Linux kernel, the following vulnerability has been resolved:
ipack: ipoctal: fix module reference leak
A reference to the carrier module was…
Linux Kernel
4.4.286 / 4.9.285+
HIGH 7.5
CVE-2024-1968
In scrapy/scrapy, an issue was identified where the Authorization header is not removed during redirects that only change the scheme (e.g., HTTPS to …
Scrapy
2.11.2+
MEDIUM 5.3
CVE-2024-5096
A vulnerability classified as problematic was found in Hipcam Device up to 20240511. This vulnerability affects unknown code of the file /log/wifi.ma…
Mitigation only
HIGH 7.5
CVE-2024-32131
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affe…
Download Manager
3.2.83+
MEDIUM 6.5
CVE-2024-3182
Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6…
Mitigation only
MEDIUM 5.3
CVE-2024-4837
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Se…
Telerik Report Server
10.1.24.514+
MEDIUM 5.3
CVE-2024-34717
PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by s…
Prestashop
Mitigation only
MEDIUM 5.3
CVE-2024-34358
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…
TYPO3
9.5.48 / 10.4.45+
HIGH 7.5
CVE-2024-33865
An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endp…
Linqi
1.4.0.1+
MEDIUM 5.3
CVE-2024-27947
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwarded to a s…
Ruggedcom Crossbow
5.5+
MEDIUM 6.0
CVE-2024-22270
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor …
Workstation
13.5.2 / 17.5.2+
MEDIUM 6.0
CVE-2024-22269
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative p…
Workstation
13.5.2 / 17.5.2+
MEDIUM 5.3
CVE-2024-35171
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.…
Academy Lms
1.9.26+
HIGH 7.5
CVE-2024-35166
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.
Filebird
5.6.4+