Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-42772
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated at…
Hotel Management System
No fix yet
CRITICAL 9.1
CVE-2024-42775
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unau…
Hotel Management System
No fix yet
HIGH 7.2
CVE-2024-42776
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
Hotel Management System
No fix yet
MEDIUM 5.4
CVE-2024-36441
Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are rece…
Mitigation only
HIGH 7.6
CVE-2024-36443
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.
Mitigation only
HIGH 7.2
CVE-2024-8071
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system adm…
Mattermost
9.5.8 / 9.8.3+
HIGH 8.8
CVE-2024-38175
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges ov…
Azure Managed Instance For Apache Cassandra
Mitigation only
CRITICAL 9.8
CVE-2024-42919
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
Escan Management Console
No fix yet
HIGH 7.5
CVE-2024-27187
Improper Access Controls allows backend users to overwrite their username when disallowed.
Joomla\!
4.4.7 / 5.1.3+
MEDIUM 6.5
CVE-2024-43409
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform me…
Ghost
5.89.5+
CRITICAL 9.8
CVE-2024-42559
An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a val…
Mitigation only
CRITICAL 9.8
CVE-2024-7921
A vulnerability has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805 and classified as problematic. Affect…
Jielink\+ Jsotc2016
after 20240805
CRITICAL 9.8
CVE-2024-7919
A vulnerability, which was classified as critical, has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. T…
Jielink\+ Jsotc2016
after 20240805
CRITICAL 9.8
CVE-2024-7920
A vulnerability, which was classified as problematic, was found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. Aff…
Jielink\+ Jsotc2016
after 20240805
HIGH 7.5
CVE-2024-6221
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. T…
Flask Cors
Patch available
CRITICAL 9.8
CVE-2024-42967
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the usernam…
Lr350 Firmware
No fix yet
MEDIUM 5.5
CVE-2024-28050
Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to poten…
Arc A Graphics
31.0.101.4824+
HIGH 7.9
CVE-2024-25576
improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege…
Agilex 7 Fpga Firmware
24.1+
HIGH 7.8
CVE-2024-26022
Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable esca…
Aptio V Uefi Firmware Integrator Tools
5.05.04.0008 / 5.13.00.2106+
HIGH 8.8
CVE-2024-24986
Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an auth…
Ethernet 800 Series Controllers Driver
28.3+
MEDIUM 5.5
CVE-2023-43489
Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of servi…
Computing Improvement Program
2.4.10717+
HIGH 7.8
CVE-2024-38163
Windows Update Stack Elevation of Privilege Vulnerability
Windows 10 21h2
10.0.19041.3920 / 10.0.20348.2201+
MEDIUM 6.8
CVE-2024-38223
Windows Initial Machine Configuration Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20751 / 10.0.14393.7259+
HIGH 7.8
CVE-2024-38195
Azure CycleCloud Remote Code Execution Vulnerability
Azure Cyclecloud
8.6.3+
HIGH 7.8
CVE-2024-38162
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Azure Connected Machine Agent
1.44+
MEDIUM 5.5
CVE-2023-31341
Insufficient
validation of the Input Output Control (IOCTL) input buffer in AMD μProf may
allow an authenticated attacker to cause an out-of-bounds w…
Uprof
4.1.424 / 4.2.816+
MEDIUM 5.5
CVE-2024-36505
An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an …
Fortios
7.0.15 / 7.2.8+
MEDIUM 6.5
CVE-2024-41905
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access…
Sinec Traffic Analyzer
2.0+
MEDIUM 5.4
CVE-2024-41732
SAP NetWeaver Application Server ABAP allows
an unauthenticated attacker to craft a URL link that could bypass allowlist
controls. Depending on t…
Netweaver Application Server Abap
Mitigation only
CRITICAL 9.9
CVE-2024-42480
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC f…
Kamaji
Patch available