Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2024-9082
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functional…
Online Eyewear Shop
No fix yet
HIGH 8.8
CVE-2024-43460
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over …
Dynamics 365 Business Central
Patch available
MEDIUM 6.5
CVE-2024-46942
In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an Op…
Model Driven Service Abstraction Layer
after 13.0.1
MEDIUM 6.6
CVE-2024-6840
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP req…
Mitigation only
HIGH 8.8
CVE-2024-20381
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management…
Ios Xr
Mitigation only
MEDIUM 6.5
CVE-2024-43482
Microsoft Outlook for iOS Information Disclosure Vulnerability
Outlook
4.2435.0+
HIGH 7.5
CVE-2024-38231
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Windows Server 2008
10.0.14393.7336 / 10.0.17763.6293+
HIGH 8.8
CVE-2024-45044
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes …
Patch available
HIGH 7.5
CVE-2024-8509
A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authenti…
Mitigation only
HIGH 7.5
CVE-2024-42039
Access control vulnerability in the SystemUI module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Emui
No fix yet
CRITICAL 9.8
CVE-2024-45307
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is …
Sudobot
9.26.7+
MEDIUM 5.1
CVE-2024-34463
BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authent…
Mitigation only
HIGH 7.5
CVE-2024-42490
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main …
Authentik
2024.4.4 / 2024.6.4+
CRITICAL 9.8
CVE-2024-7851
A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown co…
Yoga Class Registration System
No fix yet
MEDIUM 6.5
CVE-2024-6347
* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to…
Blind Spot Detection Sensor Ecu Firmware
Mitigation only
HIGH 8.1
CVE-2024-7624
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is …
Zephyr Project Manager
3.3.102+
HIGH 7.3
CVE-2024-7799
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown f…
Simple Online Bidding System
No fix yet
MEDIUM 5.4
CVE-2024-39418
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result …
Commerce
after 2.4.3
MEDIUM 5.3
CVE-2024-6384
"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoD…
MongoDB
6.0.16 / 7.0.11+
HIGH 7.5
CVE-2024-42036
Access permission verification vulnerability in the Notepad module
Impact: Successful exploitation of this vulnerability may affect service confident…
Emui
No fix yet
MEDIUM 5.5
CVE-2024-42032
Access permission verification vulnerability in the Contacts module
Impact: Successful exploitation of this vulnerability may affect service confiden…
Emui
No fix yet
CRITICAL 9.8
CVE-2024-7578
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the …
Alr F800 Firmware
after 19.10.24
CRITICAL 9.8
CVE-2024-36130
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute …
Endpoint Manager Mobile
12.1.0.1+
MEDIUM 6.3
CVE-2024-41962
Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscr…
Bostr
3.0.10+
MEDIUM 5.5
CVE-2024-40807
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut m…
macOS
12.7.6 / 13.6.8+
HIGH 7.1
CVE-2024-40814
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An app may b…
macOS
14.6+
MEDIUM 5.5
CVE-2024-40783
The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ve…
macOS
12.7.6 / 13.6.8+
HIGH 7.5
CVE-2024-41670
In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a maliciou…
Mitigation only
MEDIUM 5.9
CVE-2024-21166
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 …
MySQL
after 8.0.36
HIGH 7.3
CVE-2024-36438
eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card dupli…
Mitigation only