Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-43551
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Secur…
315 5g Iot Modem Firmware
Mitigation only
HIGH 8.8
CVE-2024-5201
Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege of another user via HTTP Req…
No fix yet
MEDIUM 5.3
CVE-2024-28188
Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-schedu…
Patch available
CRITICAL 9.8
CVE-2024-29849EPSS 17%
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
Veeam Backup \& Replication
12.1.2.172+
HIGH 8.1
CVE-2024-5044
A vulnerability was found in Emlog Pro 2.3.4. It has been classified as problematic. This affects an unknown part of the component Cookie Handler. Th…
Emlog
No fix yet
HIGH 8.8
CVE-2023-41956
Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.
Simple Membership
4.3.5+
MEDIUM 5.5
CVE-2024-35184
Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prio…
Patch available
CRITICAL 9.8
CVE-2024-3487
Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This
vulnerability allows an attacker to manipulate certain paramete…
Imanager
3.2.6+
HIGH 8.8
CVE-2024-4129
Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication By…
Mitigation only
CRITICAL 9.8
CVE-2024-3263
YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for syst…
Mitigation only
CRITICAL 9.1
CVE-2024-34340
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set t…
Fedora
1.2.27+
HIGH 8.0
CVE-2020-18305
Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing …
Extremexos
22.7+
MEDIUM 6.7
CVE-2024-4601
An incorrect authentication vulnerability has been found in Socomec Net Vision affecting version 7.20. This vulnerability allows an attacker to perfo…
Mitigation only
MEDIUM 5.3
CVE-2024-34093
An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attacker cou…
Archer
2024.03+
CRITICAL 9.1
CVE-2024-33110
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.
Dir 845l Firmware
after 1.01krb03
CRITICAL 9.8
CVE-2023-38096EPSS 82%
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp…
Prosafe Network Management System
1.7.0.20+
HIGH 7.5
CVE-2024-26331EPSS 51%
ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session…
Mitigation only
HIGH 8.8
CVE-2024-4303
ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentia…
Mitigation only
CRITICAL 9.8
CVE-2023-47222
An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow us…
Media Streaming Add On
500.1.1.5+
MEDIUM 6.8
CVE-2024-30939
An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an acc…
Vp59 Firmware
No fix yet
HIGH 8.8
CVE-2023-6787
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijack…
Build Of Keycloak
22.0.10 / 24.0.3+
HIGH 8.8
CVE-2024-4024EPSS 15%
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4,…
GitLab
16.9.6 / 16.10.4+
MEDIUM 5.0
CVE-2023-3597
A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows…
Mitigation only
CRITICAL 9.8
CVE-2023-51484
Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as Us…
Mitigation only
CRITICAL 9.9
CVE-2023-51482
Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…
Mitigation only
CRITICAL 9.8
CVE-2023-51478
Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a thro…
Build App Online
1.0.20+
HIGH 8.2
CVE-2023-51471
Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Accessing Functionality Not Properly Constrained by ACLs.This issue…
Mitigation only
CRITICAL 9.8
CVE-2023-51472
Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affects Checkout Mestres WP: from n…
Mitigation only
CRITICAL 9.8
CVE-2023-51477
Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Constrained by ACLs.This issue af…
Mitigation only
CRITICAL 9.8
CVE-2023-51405
Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…
Bookingpress
1.0.75+