Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-37239
Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the …
Emui
No fix yet
CRITICAL 9.8
CVE-2021-46891
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect servic…
Emui
No fix yet
CRITICAL 9.1
CVE-2023-3455
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.
Emui
No fix yet
MEDIUM 5.5
CVE-2023-21624
Information disclosure in DSP Services while loading dynamic module.
Fastconnect 6700 Firmware
No fix yet
CRITICAL 9.1
CVE-2023-36817
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repos…
The King\'s Temple Church Website
Mitigation only
HIGH 7.5
CVE-2023-36539
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
Meetings
No fix yet
MEDIUM 5.5
CVE-2023-36476
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions versio…
Calamares Nixos Extensions
0.3.13+
MEDIUM 5.5
CVE-2023-21237 KEV
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insuffic…
Android
Mitigation only
HIGH 7.5
CVE-2023-30993
IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another ten…
Cloud Pak For Security
after 1.9.2.0
HIGH 7.5
CVE-2023-28857
Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X50…
Central Authentication Service
6.5.9.1 / 6.6.6+
MEDIUM 6.5
CVE-2022-34352
IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned t…
Qradar Security Information And Event Manager
Patch available
MEDIUM 5.3
CVE-2023-34098
Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript c…
Shopware
5.7.18+
HIGH 7.5
CVE-2023-3132
The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient c…
Mainwp Child
after 4.4.1.1
MEDIUM 5.3
CVE-2023-2991
Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Glo…
Eft Server
after 8.1.0.14
MEDIUM 6.5
CVE-2023-25499
When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0,…
Vaadin
10.0.23 / 14.10.1+
MEDIUM 6.5
CVE-2023-35005
In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations.
This vulnerability is mitigated by the fact…
Airflow
2.6.2+
MEDIUM 6.5
CVE-2023-2792
Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg com…
Mattermost
after 7.9.3
MEDIUM 5.3
CVE-2023-34242
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to version 1.13.4, when Gateway API is enabled in Ci…
Cilium
1.13.4+
MEDIUM 5.3
CVE-2023-29287
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Information Exposure vulnerability …
Commerce
Mitigation only
HIGH 7.7
CVE-2023-28175
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted …
Video Management System
after 11.1.1
MEDIUM 6.5
CVE-2022-33159
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by an authenticated user. IBM X…
Security Directory Suite Va
after 8.0.1.19
HIGH 7.5
CVE-2023-25683
IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.00 through FW1030.11 could all…
Powervm Hypervisor
Mitigation only
MEDIUM 6.8
CVE-2023-2820
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an…
Threat Response Auto Pull
5.10.0+
HIGH 7.5
CVE-2023-33933
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach…
Traffic Server
8.1.7 / 9.2.1+
HIGH 7.5
CVE-2022-47184
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach…
Traffic Server
8.1.7 / 9.2.1+
MEDIUM 6.5
CVE-2023-3231
A vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown code of the component ZIP Packa…
Ujcms
after 6.0.2
MEDIUM 5.3
CVE-2023-34250
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passe…
Discourse
3.0.4+
MEDIUM 6.5
CVE-2022-43684
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality.
Additional…
Servicenow
No fix yet
HIGH 7.5
CVE-2023-22586
The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter.
Ak Em100 Firmware
2.2.0.12+
MEDIUM 5.3
CVE-2023-25912
The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information s…
Ak Em100 Firmware
2.2.0.12+