Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.3
CVE-2024-30061
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Dynamics 365
Patch available
HIGH 7.2
CVE-2024-39597
In SAP Commerce, a user can misuse the forgotten
password functionality to gain access to a Composable Storefront B2B site for
which early login and …
Mitigation only
MEDIUM 6.5
CVE-2024-6375
A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to ei…
MongoDB
5.0.22 / 6.0.11+
CRITICAL 9.8
CVE-2024-38371
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow…
Authentik
2024.2.4 / 2024.4.3+
CRITICAL 9.8
CVE-2024-37282
It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently …
Elastic Cloud Enterprise
3.7.2+
MEDIUM 6.5
CVE-2024-3959
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting …
GitLab
16.11.5 / 17.0.3+
MEDIUM 6.5
CVE-2024-37159
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a validator using vested tokens to…
Evmos
18.0.0+
HIGH 7.1
CVE-2024-6000
The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the …
Mitigation only
HIGH 8.2
CVE-2024-34104
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in …
Commerce
after 1.4.0
HIGH 8.8
CVE-2024-25949
Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authentic…
Networking Os10
10.5.3.10 / 10.5.4.11+
MEDIUM 5.3
CVE-2024-37154
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects …
Evmos
Mitigation only
MEDIUM 6.3
CVE-2024-36399
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php functio…
Kanboard
1.2.37+
HIGH 8.8
CVE-2024-23667
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…
Fortiwebmanager
6.2.5 / 7.0.5+
HIGH 8.8
CVE-2024-23670
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…
Fortiwebmanager
6.2.5 / 7.0.5+
HIGH 8.8
CVE-2024-23665
Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, ver…
Fortiweb
7.2.8 / 7.4.3+
CRITICAL 9.8
CVE-2024-36108
casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sens…
Patch available
MEDIUM 5.4
CVE-2024-3269
The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstal…
Mitigation only
MEDIUM 5.3
CVE-2024-0870
The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sav…
Mitigation only
HIGH 8.8
CVE-2024-4819
A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function o…
Online Laundry Management System
No fix yet
HIGH 8.1
CVE-2024-2441
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber…
Vikbooking Hotel Booking Engine \& Pms
1.6.8+
CRITICAL 9.8
CVE-2024-28285
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in t…
No fix yet
HIGH 7.1
CVE-2024-23576
Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthori…
Hcl Commerce
9.1.14+
CRITICAL 9.8
CVE-2024-34257
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary command…
Ex1800t Firmware
No fix yet
CRITICAL 9.1
CVE-2024-33749
DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
Dedecms
No fix yet
MEDIUM 6.1
CVE-2023-41819
A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized…
Mitigation only
HIGH 8.8
CVE-2023-44410
D-Link D-View showUsers Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges …
D View 8
Mitigation only
HIGH 8.8
CVE-2023-32168
D-Link D-View showUser Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges o…
D View 8
after 2.0.1.27
MEDIUM 6.9
CVE-2024-32359
An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the sec…
Mitigation only
HIGH 8.8
CVE-2023-47166
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request…
Ur32l Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-32881
Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Token…
Patch available