Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-39289
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to con…
Mivoice Connect
after 9.6.2208.101
MEDIUM 6.5
CVE-2023-40580
Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phrase when the Freighter wallet …
Freighter
5.3.1+
HIGH 7.5
CVE-2023-3705
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthent…
Cp Vnr 3104 Firmware
Patch available
MEDIUM 5.3
CVE-2023-4230
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate th…
Iologik E4200 Firmware
after 1.6
HIGH 8.1
CVE-2023-37379
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…
Airflow
2.7.0+
HIGH 7.5
CVE-2023-25913
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP ad…
Ak Sm 800a Firmware
after 3.3
HIGH 7.5
CVE-2023-40735
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFLY BUTTON (Architecture flaw) …
Butterfly Button
after 2023-08-21
MEDIUM 5.3
CVE-2023-39974
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of sub…
Acymailing
8.7.0+
MEDIUM 5.3
CVE-2023-40348
The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its outp…
Gogs
after 1.0.15
HIGH 7.8
CVE-2023-32495
Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker…
Powerscale Onefs
after 9.5.0.3
MEDIUM 5.3
CVE-2023-2916EPSS 24%
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_no…
Infinitewp Client
1.12.1+
MEDIUM 5.5
CVE-2023-21267
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the c…
Android
Mitigation only
HIGH 7.5
CVE-2023-40023
yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file inclusion (LFI) vulnerability. Th…
Yaklang
Patch available
HIGH 7.5
CVE-2023-39393
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources…
Emui
Mitigation only
HIGH 7.5
CVE-2023-39383
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' d…
Emui
No fix yet
HIGH 7.5
CVE-2023-32561
A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypa…
Avalanche
6.4.1+
MEDIUM 5.5
CVE-2023-38245
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information Disclosure vulnerability. An u…
Acrobat Dc
20.005.30514.10514 / 20.005.30516.10516+
MEDIUM 6.5
CVE-2023-39951
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. OpenTelemetry Java Instrumenta…
Opentelemetry Instrumentation For Java
1.28.0+
MEDIUM 6.5
CVE-2023-36908
Windows Hyper-V Information Disclosure Vulnerability
Windows 10
10.0.10240.20107 / 10.0.14393.6167+
MEDIUM 6.5
CVE-2023-36894
Microsoft SharePoint Server Information Disclosure Vulnerability
Sharepoint Server
Patch available
MEDIUM 5.7
CVE-2023-4177
A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknown processing of the component…
Empowerid
after 7.205.0.0
HIGH 7.5
CVE-2023-4168EPSS 46%
A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-…
Adlisting
No fix yet
HIGH 8.8
CVE-2023-39508
Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apach…
Airflow
2.6.0+
HIGH 7.5
CVE-2023-38494
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not ha…
Metersphere
2.10.4+
HIGH 7.5
CVE-2023-4139
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction i…
Wp Ultimate Csv Importer
after 7.9.8
MEDIUM 5.5
CVE-2023-26441
Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker wi…
Open Xchange Appsuite Office
8.11+
MEDIUM 5.3
CVE-2023-31927
An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauth…
Brocade Fabric Operating System
9.1.1c+
MEDIUM 5.5
CVE-2023-28203
The issue was addressed with improved checks. This issue is fixed in Apple Music 4.2.0 for Android. An app may be able to access contacts.
Music
4.2.0+
MEDIUM 6.5
CVE-2023-38503
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permissi…
Directus
10.5.0+
MEDIUM 5.3
CVE-2023-38499
TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, …
TYPO3
9.5.42 / 10.4.39+