Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2024-39837
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary cha…
Mattermost Server
9.5.7+
MEDIUM 6.4
CVE-2024-36492
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing user…
Mattermost
9.5.7 / 9.7.6+
CRITICAL 9.8
CVE-2024-38909
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows a…
Elfinder
Mitigation only
HIGH 7.8
CVE-2024-40812
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.…
Ipados
1.3 / 10.6+
HIGH 7.5
CVE-2024-40786
This issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Vent…
Ipados
13.6.8 / 16.7.9+
CRITICAL 9.1
CVE-2024-28805
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.
I Mcs Nfv
No fix yet
MEDIUM 5.4
CVE-2024-6727
A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionalit…
Mitigation only
HIGH 7.5
CVE-2024-7154
A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file…
A3700r Firmware
No fix yet
CRITICAL 9.8
CVE-2024-40117
Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting…
Mitigation only
MEDIUM 5.3
CVE-2024-41806
The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the ins…
Patch available
CRITICAL 9.8
CVE-2024-36535
Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
Meshery
Mitigation only
HIGH 7.2
CVE-2024-36537
Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tok…
Cert Manager
Mitigation only
HIGH 8.8
CVE-2024-38164
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to…
Groupme
Patch available
CRITICAL 9.8
CVE-2024-41703
LibreChat through 0.7.4-rc1 has incorrect access control for message updates.
Librechat
after 0.7.3
HIGH 7.5
CVE-2024-41600
Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login me…
Lin Cms Spring Boot
after 0.2.1
MEDIUM 6.5
CVE-2024-21169
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Partners). Supported versions that are affected are 12.2.3-12.2…
Marketing
after 12.2.13
MEDIUM 6.1
CVE-2024-21150
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …
Jd Edwards Enterpriseone Tools
9.2.8.2+
HIGH 8.1
CVE-2024-21153
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The…
Process Manufacturing Product Development
Mitigation only
MEDIUM 5.4
CVE-2024-21132
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Approvals). Supported versions that are affected are 12.2.3-12…
Purchasing
after 12.2.13
HIGH 7.5
CVE-2019-16640
An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mishandled (%00 and /var/./html …
Eg 2000se Firmware
Mitigation only
HIGH 7.3
CVE-2024-36438
eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card dupli…
Mitigation only
HIGH 8.8
CVE-2024-6737
The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers…
Electronic Official Document Management System
5.0.77+
MEDIUM 5.3
CVE-2024-6738
The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific fil…
Tronclass
1.69.61976+
MEDIUM 6.5
CVE-2024-40547
PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.
Publiccms
after 4.0.202302.e
CRITICAL 9.8
CVE-2024-6385EPSS 6%
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting …
GitLab
16.11.6 / 17.0.4+
HIGH 7.0
CVE-2024-34725
In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalat…
Android
Mitigation only
HIGH 7.8
CVE-2024-31320
In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM…
Android
Patch available
HIGH 7.8
CVE-2024-38100
Windows File Explorer Elevation of Privilege Vulnerability
Windows Server 2016
10.0.14393.7159 / 10.0.17763.6054+
HIGH 7.5
CVE-2024-38061
DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20710 / 10.0.14393.7159+
HIGH 8.8
CVE-2024-23663
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an at…
Fortiextender Firmware
after 7.4.2