Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2024-24830
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability …
Openobserve
0.8.0+
MEDIUM 6.5
CVE-2024-25106
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne…
Openobserve
0.8.0+
MEDIUM 5.3
CVE-2024-23806
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
Omnikey Secure Elements Reader Configuration Cards Firmware
Mitigation only
MEDIUM 5.3
CVE-2024-24936
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
Teamcity
2023.11.2+
MEDIUM 6.5
CVE-2023-32967
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…
Qts
Mitigation only
MEDIUM 6.5
CVE-2024-23649
Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, ev…
Lemmy
0.19.1+
HIGH 8.8
CVE-2023-40683
IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By au…
Openpages With Watson
8.3.0.2.7+
MEDIUM 5.4
CVE-2024-20979
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0, 7.…
Bi Publisher
Patch available
MEDIUM 6.5
CVE-2023-6878
The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcss…
Slick Social Share Buttons
after 2.4.11
MEDIUM 5.3
CVE-2023-6496
The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_…
Manage Notification E Mails
1.8.6+
MEDIUM 5.5
CVE-2023-40430
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes without user…
macOS
14.0+
HIGH 8.8
CVE-2023-48252
The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.
Nexo Os
after 1500-sp2
CRITICAL 9.6
CVE-2023-52139
Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that …
Misskey
2023.12.1+
MEDIUM 5.4
CVE-2023-41673
An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or back…
Fortiadc
after 7.0.5
MEDIUM 6.5
CVE-2023-6538
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Se…
System Management Unit Firmware
14.8.7825.01+
MEDIUM 6.5
CVE-2023-5808
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage a…
Vantara Hitachi Network Attached Storage
after 14.8.7825.01
MEDIUM 5.3
CVE-2023-48309
NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization a…
Next Auth
4.24.5+
HIGH 7.5
CVE-2023-48241EPSS 73%
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based se…
Xwiki
14.10.5 / 15.5.1+
MEDIUM 6.7
CVE-2023-32662
Improper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a privilaged user to potential…
Battery Life Diagnostic Tool
2.2.1+
HIGH 7.8
CVE-2023-28378
Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially …
Quickassist Technology Library
1.10 / 2.04+
MEDIUM 5.4
CVE-2023-36633
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker …
Fortimail
7.0.6 / 7.2.3+
HIGH 8.1
CVE-2023-47109
PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When…
Customer Reassurance Block
5.1.4+
MEDIUM 5.3
CVE-2023-42541
Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.
Push Service
3.4.10+
HIGH 7.8
CVE-2023-28556
Cryptographic issue in HLOS during key management.
315 5g Iot Modem Firmware
No fix yet
MEDIUM 5.5
CVE-2023-5948
Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.
Amaze File Utilities
1.90+
CRITICAL 9.8
CVE-2023-42491
EisBaer Scada - CWE-285: Improper Authorization
Eisbaer Scada
after 3.0.6433.1964
HIGH 8.1
CVE-2020-36714
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versio…
Brizy
after 1.0.125
HIGH 8.8
CVE-2021-4334
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the f…
Fancy Product Designer
4.7.0+
MEDIUM 6.3
CVE-2021-4335
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing cap…
Fancy Product Designer
4.7.0+
MEDIUM 6.5
CVE-2023-5654
The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is acce…
React Devtools
4.28.4+