Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2023-1777
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the con…
Mattermost Server
7.1.6+
HIGH 7.5
CVE-2023-1769
A vulnerability, which was classified as problematic, was found in SourceCodester Grade Point Average GPA Calculator 1.0. Affected is an unknown func…
Grade Point Average \(gpa\) Calculator
Mitigation only
MEDIUM 5.3
CVE-2023-1258
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) all…
Flow X\/m Firmware
after 3.2.6
HIGH 7.5
CVE-2023-28732
Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access…
Acymailing
8.3.0+
HIGH 7.5
CVE-2023-0836
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 …
Haproxy
2.2.27+
HIGH 7.5
CVE-2023-1680
A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayr…
Xunruicms
No fix yet
HIGH 7.5
CVE-2022-48430
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
Intellij Idea
2023.1+
HIGH 7.5
CVE-2023-1683
A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/…
Xunruicms
No fix yet
HIGH 7.5
CVE-2023-1681
A vulnerability, which was classified as problematic, was found in Xunrui CMS 4.61. Affected is an unknown function of the file /config/myfield/test.…
Xunruicms
No fix yet
MEDIUM 5.5
CVE-2023-25722
A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured…
Veracode
23.3.19.0+
HIGH 7.5
CVE-2022-48346
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.
Emui
No fix yet
HIGH 7.5
CVE-2022-48347
The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.
Emui
No fix yet
CRITICAL 9.1
CVE-2022-48348
The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and …
Emui
No fix yet
CRITICAL 9.8
CVE-2023-24838
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the admini…
Powerstation Firmware
Mitigation only
HIGH 7.5
CVE-2023-28444
angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables.…
Angular Server Side Configuration
15.1.0+
HIGH 7.5
CVE-2023-21067
Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/A
Android
No fix yet
MEDIUM 5.3
CVE-2023-28442
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Prior to versions 2.20.6, 2.19.6…
Geonode
2.18.7 / 2.19.6+
HIGH 8.8
CVE-2023-20055
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the w…
Catalyst Center
2.3.3.6+
HIGH 7.5
CVE-2023-28432 KEVEPSS 84%
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T2…
Minio
2023-03-20t20-16-18z+
HIGH 7.5
CVE-2022-45124EPSS 13%
An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted …
Kinghistorian
No fix yet
HIGH 7.5
CVE-2023-27591
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instan…
Miniflux
2.0.43+
HIGH 7.5
CVE-2023-22880
Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 c…
Rooms
5.13.1 / 5.13.3+
MEDIUM 5.5
CVE-2023-21449
Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information with…
Android
Mitigation only
MEDIUM 6.5
CVE-2023-25680
IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obf…
Robotic Process Automation
21.0.6+
HIGH 8.2
CVE-2020-4927
A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary d…
Spectrum Scale
5.1.7.0+
MEDIUM 6.5
CVE-2023-22876
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive in…
Sterling B2b Integrator
6.0.3.8 / 6.1.2.2+
HIGH 7.5
CVE-2022-38456
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions.
Ajax Search
after 4.10.3
MEDIUM 5.5
CVE-2023-24923
Microsoft OneDrive for Android Information Disclosure Vulnerability
Onedrive
6.73+
MEDIUM 5.5
CVE-2023-24882
Microsoft OneDrive for Android Information Disclosure Vulnerability
Onedrive
6.73+
MEDIUM 5.3
CVE-2023-27894
SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameter…
Businessobjects Business Intelligence
Mitigation only