Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2023-50181
An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticate…
Fortiadc
7.2.5 / 7.4.2+
HIGH 8.6
CVE-2024-39697
phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due …
Patch available
HIGH 7.7
CVE-2024-39701
Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators.…
Directus
10.6.0+
HIGH 8.8
CVE-2024-39943EPSS 39%
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have…
Http File Server
0.52.10+
HIGH 7.8
CVE-2024-39934
Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shar…
Patch available
MEDIUM 6.5
CVE-2024-6428
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows…
Mattermost
9.5.6 / 9.6.3+
MEDIUM 5.3
CVE-2024-36257
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server…
Mattermost
9.5.6+
MEDIUM 5.4
CVE-2024-39361
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which a…
Mattermost
9.5.6 / 9.6.3+
HIGH 8.8
CVE-2024-37905
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to g…
Authentik
2024.2.4 / 2024.4.3+
CRITICAL 9.8
CVE-2024-38371
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow…
Authentik
2024.2.4 / 2024.4.3+
CRITICAL 9.8
CVE-2024-39376
TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their design…
Markoni D \(compact\) Firmware
2.0.1+
HIGH 8.8
CVE-2024-5655EPSS 7%
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting …
GitLab
16.11.5 / 17.0.3+
MEDIUM 5.3
CVE-2024-2191
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting …
GitLab
16.11.5 / 17.0.3+
HIGH 8.2
CVE-2024-37742
Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB k…
Mitigation only
HIGH 7.4
CVE-2024-21740
Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.
No fix yet
CRITICAL 9.8
CVE-2024-21741
GigaDevice GD32E103C8T6 devices have Incorrect Access Control.
No fix yet
CRITICAL 9.8
CVE-2024-33898
Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows r…
Mitigation only
HIGH 7.5
CVE-2024-37677
An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacker to obtain sensitive informa…
Access Management Specialist
No fix yet
MEDIUM 5.3
CVE-2024-38873
An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails t…
Mitigation only
MEDIUM 6.5
CVE-2022-41324
Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to so…
Mitigation only
HIGH 8.8
CVE-2022-45929
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their rol…
Mitigation only
MEDIUM 5.4
CVE-2024-38273
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
Moodle
4.1.11 / 4.2.8+
HIGH 8.2
CVE-2022-23829
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Manage…
Mitigation only
HIGH 8.5
CVE-2024-5650
DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to int…
Mitigation only
MEDIUM 5.4
CVE-2024-37884
Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got sh…
Nextcloud Server
25.0.13.7 / 26.0.13+
HIGH 8.1
CVE-2024-37882
Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissi…
Nextcloud Server
23.0.12.17 / 24.0.12.13+
MEDIUM 6.3
CVE-2024-37312
user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account…
User Oidc
5.0.0+
MEDIUM 5.4
CVE-2024-28965
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabl…
Secure Connect Gateway
after 5.22.00.18
MEDIUM 5.4
CVE-2024-28966
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabl…
Secure Connect Gateway
after 5.22.00.18
MEDIUM 5.4
CVE-2024-28967
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if …
Secure Connect Gateway
after 5.22.00.18