Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2023-31416
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being a…
Elastic Cloud On Kubernetes
2.8+
HIGH 7.5
CVE-2023-38845
An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Line
No fix yet
HIGH 7.5
CVE-2023-38846
An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Line
No fix yet
HIGH 7.5
CVE-2023-38847
An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Line
No fix yet
HIGH 7.5
CVE-2023-38849
An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Line
No fix yet
MEDIUM 6.8
CVE-2023-41988
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPad…
Ipados
10.1 / 14.1+
MEDIUM 5.3
CVE-2023-42846
This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, tvOS 17.1, iOS 17.1 and …
Ipados
10.1 / 16.7.2+
MEDIUM 6.5
CVE-2023-46125
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem…
Fides
2.22.1+
MEDIUM 6.5
CVE-2023-46128
Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobo…
Nautobot
2.0.3+
HIGH 7.5
CVE-2023-42490
EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Eisbaer Scada
after 3.0.6433.1964
HIGH 8.2
CVE-2023-39735
The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mess…
Uomasa Saiji New
No fix yet
HIGH 8.2
CVE-2023-39736
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast m…
Fukunaga Memberscard
No fix yet
HIGH 8.2
CVE-2023-39737
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Matsuya
No fix yet
HIGH 8.2
CVE-2023-39739
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast m…
Regina Sweets\&bakery
No fix yet
HIGH 7.5
CVE-2023-46315
The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion w…
Stable Diffusion Webui Infinite Image Browsing
5.0+
MEDIUM 6.5
CVE-2023-5070
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inc…
Social Media Share Buttons \& Social Sharing Icons
2.8.6+
CRITICAL 9.3
CVE-2023-5576
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.9…
Migration\, Backup\, Staging
after 0.9.91
MEDIUM 5.4
CVE-2023-41893
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logg…
Home Assistant
2023.9.0+
MEDIUM 5.5
CVE-2023-46115
Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base it…
Tauri
2.0.0+
MEDIUM 5.3
CVE-2023-42666
The affected product is vulnerable to an exposure of sensitive information to an unauthorized actor vulnerability, which may allow an attacker to cre…
Dexgate
Mitigation only
MEDIUM 5.3
CVE-2023-5254
The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_chec…
Wpbot
4.9.1+
HIGH 7.5
CVE-2023-34437
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a vulnerability in their password retrieval functionality which could a…
Bentley Nevada 3500 System Firmware
Mitigation only
HIGH 7.5
CVE-2023-45912
WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underl…
Comscale
No fix yet
CRITICAL 9.8
CVE-2023-5642EPSS 17%
Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa…
R Seenet
No fix yet
HIGH 7.5
CVE-2023-5552
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewa…
Firewall
after 19.5.3
HIGH 7.5
CVE-2023-22086
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…
Weblogic Server
Patch available
HIGH 7.5
CVE-2023-22019
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12…
HTTP Server
Patch available
MEDIUM 5.5
CVE-2023-5339
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including pa…
Mattermost Desktop
after 5.4.0
HIGH 7.5
CVE-2023-41752
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.…
Traffic Server
8.1.9 / 9.2.3+
MEDIUM 5.3
CVE-2021-38859
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that co…
Security Verify Privilege On Premises
11.5+