Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-28340
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attacker…
Cbk40 Firmware
No fix yet
MEDIUM 5.5
CVE-2024-26177
Windows Kernel Information Disclosure Vulnerability
Windows 10 1507
10.0.10240.20526 / 10.0.14393.6796+
MEDIUM 5.5
CVE-2024-1302
Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application…
Monitool
4.7+
MEDIUM 6.2
CVE-2024-2371
Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol uses plaintext to transfer da…
Mitigation only
MEDIUM 5.3
CVE-2024-0906
The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. T…
F\(x\) Private Site
after 1.2.1
HIGH 7.5
CVE-2024-28120
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check …
Codeium
No fix yet
MEDIUM 5.3
CVE-2024-25114
Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Online is opened by a separate "K…
Online
21.11.9.4 / 22.05.22+
HIGH 7.5
CVE-2024-26309
Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could pote…
Archer
6.14.0.2.2+
MEDIUM 5.5
CVE-2023-28826
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4…
Ipados
12.7.4 / 13.6.5+
CRITICAL 9.8
CVE-2024-24765
CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files …
Casaos
0.4.7+
MEDIUM 5.5
CVE-2024-20292
A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view s…
Duo Authentication For Windows Logon And Rdp
4.3.0+
MEDIUM 6.1
CVE-2023-48644
An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance module…
Archibus
Mitigation only
MEDIUM 5.3
CVE-2024-1769
The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14 via the meta description dat…
Jm Twitter Cards
14.1.0+
HIGH 7.5
CVE-2022-43890
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att…
Security Verify Privilege On Premises
after 11.5
MEDIUM 5.9
CVE-2024-20019
In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additional execut…
Software Package
after 2023.11.10
MEDIUM 6.5
CVE-2019-25210
An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is use…
Helm
Mitigation only
MEDIUM 6.5
CVE-2024-0765
As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and r…
Anythingllm
1.0.0+
HIGH 7.5
CVE-2024-25839
An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to es…
Super Newsletter
after 1.4.21
MEDIUM 5.3
CVE-2024-27296
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being…
Directus
10.8.3+
MEDIUM 5.3
CVE-2023-50324
IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information…
Cognos Command Center
Mitigation only
MEDIUM 6.5
CVE-2024-23493
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a …
Mattermost Server
8.1.9 / 9.2.5+
HIGH 8.1
CVE-2024-26470
A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to lea…
.net 9 Starter Kit
No fix yet
HIGH 7.5
CVE-2024-23302
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
Couchbase Server
7.2.4+
MEDIUM 5.3
CVE-2024-0616
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc…
Passster
4.2.6.3+
MEDIUM 5.3
CVE-2024-0620
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 vi…
Password Protect Wordpress
1.9.0+
MEDIUM 6.5
CVE-2023-6922
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inc…
Under Construction \/ Maintenance Mode
after 2.6
MEDIUM 5.3
CVE-2024-26144
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By defau…
Rails
6.1.7.7 / 7.1.0+
CRITICAL 9.1
CVE-2024-27905
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora.
An endpoint exposing inte…
Aurora
Mitigation only
MEDIUM 5.3
CVE-2024-24720
An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists o…
Innovaphone Pbx
14r1+
HIGH 7.5
CVE-2024-27356EPSS 24%
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user infor…
Mt6000 Firmware
Mitigation only