Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-28120
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check …
Codeium
No fix yet
HIGH 8.8
CVE-2024-25501
An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.
Winmail
after 7.1
CRITICAL 9.8
CVE-2024-2281
A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulnerability affects unknown code…
Automated Mess Management System
Mitigation only
MEDIUM 5.5
CVE-2024-23266
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be ab…
macOS
12.7.4 / 13.6.5+
MEDIUM 5.5
CVE-2024-23267
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be ab…
macOS
12.7.4 / 13.6.5+
HIGH 8.6
CVE-2024-0258
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A…
Ipad Os
10.4 / 14.4+
HIGH 7.8
CVE-2024-28115
FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local priv…
Freertos
10.6.2+
CRITICAL 9.1
CVE-2023-51786
An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive inf…
Mitigation only
CRITICAL 9.8
CVE-2023-38945
Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_p…
Re160 Firmware
No fix yet
HIGH 8.8
CVE-2023-38946
An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access …
Re160 Firmware
No fix yet
HIGH 8.8
CVE-2023-43318
TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' value…
Tl Sg2210p Firmware
Mitigation only
MEDIUM 5.3
CVE-2024-1478
The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST AP…
Maintenance Mode
3.0.2+
MEDIUM 5.3
CVE-2024-1088
The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin…
Password Protected Store For Woocommerce
2.3+
HIGH 7.2
CVE-2024-0795
If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from…
Anythingllm
1.0.0+
CRITICAL 9.8
CVE-2023-49543
Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions withou…
Book Store Management System
No fix yet
HIGH 7.5
CVE-2023-49545
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application witho…
Customer Support System
No fix yet
CRITICAL 9.4
CVE-2024-21767
A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.
No fix yet
HIGH 8.8
CVE-2024-27497EPSS 27%
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
E2000 Firmware
No fix yet
CRITICAL 9.8
CVE-2024-25830EPSS 24%
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker…
Datacube3 Firmware
No fix yet
MEDIUM 5.8
CVE-2024-20291
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalon…
Nx Os
Mitigation only
MEDIUM 5.3
CVE-2024-1472
The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.6 via the REST API. This make…
Wp Maintenance
6.1.7+
MEDIUM 5.3
CVE-2024-1475
The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via…
Coming Soon Maintenance Mode
1.0.6+
MEDIUM 5.3
CVE-2024-1492
The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta …
Woo Czech
4.0.9+
MEDIUM 5.3
CVE-2024-1294
The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions…
Sunshine Photo Cart
3.1+
MEDIUM 5.3
CVE-2024-1044
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the…
Customer Reviews For Woocommerce
5.39.0+
MEDIUM 5.3
CVE-2024-0978
The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST AP…
My Private Site
3.1.0+
HIGH 8.4
CVE-2023-51774
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE …
Json Jwt
No fix yet
CRITICAL 9.8
CVE-2023-49930
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
Couchbase Server
7.2.4+
CRITICAL 9.8
CVE-2023-49931
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
Couchbase Server
7.2.4+
CRITICAL 9.8
CVE-2022-34270
An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.
Worldserver
11.7.3+