Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-13185
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
No fix yet
HIGH 7.5
CVE-2024-13186
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
Mitigation only
HIGH 7.5
CVE-2024-13173
The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.
Mitigation only
HIGH 7.5
CVE-2025-21623
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the templat…
Clipbucket
5.5.1-238+
HIGH 7.5
CVE-2024-12106EPSS 10%
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
Whatsup Gold
24.0.2+
CRITICAL 10.0
CVE-2024-56799
Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, s…
Patch available
MEDIUM 6.8
CVE-2024-7726
There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was disco…
Cm6 Firmware
No fix yet
CRITICAL 9.8
CVE-2024-54983
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.
Mitigation only
CRITICAL 9.8
CVE-2024-54984
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.
Mitigation only
CRITICAL 9.3
CVE-2024-12371
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder u…
Mitigation only
HIGH 7.9
CVE-2021-26280
Locally installed application can bypass the permission check and perform system operations that require permission.
No fix yet
MEDIUM 6.3
CVE-2021-26278
The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.
No fix yet
MEDIUM 6.4
CVE-2020-12484
When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi th…
Mitigation only
CRITICAL 9.4
CVE-2024-10205
Authentication Bypass
vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infr…
Mitigation only
CRITICAL 9.8
CVE-2024-11639
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
Cloud Services Appliance
5.0.3+
HIGH 7.3
CVE-2024-10774
Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authenti…
Mitigation only
HIGH 8.2
CVE-2024-10776
Lua apps can be deployed, removed, started, reloaded or stopped without authorization via
AppManager. This allows an attacker to remove legitimate ap…
Mitigation only
MEDIUM 5.3
CVE-2024-54155
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
Youtrack
2024.3.51866+
MEDIUM 6.5
CVE-2024-54153
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
Youtrack
2024.3.51866+
HIGH 8.8
CVE-2024-42456
A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical co…
Veeam Backup \& Replication
12.3.0.310+
HIGH 8.8
CVE-2024-40717
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating exis…
Veeam Backup \& Replication
12.3.0.310+
HIGH 8.1
CVE-2024-42455EPSS 15%
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by se…
Veeam Backup \& Replication
12.3.0.310+
MEDIUM 5.3
CVE-2024-37303
Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a downloa…
Synapse
1.106.0+
HIGH 8.8
CVE-2024-50381
A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The atta…
Mitigation only
HIGH 7.5
CVE-2024-53623
Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.
Mitigation only
HIGH 8.6
CVE-2024-11980
Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly acc…
Mitigation only
CRITICAL 9.8
CVE-2024-49052
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.
Azure Functions
Mitigation only
CRITICAL 9.8
CVE-2024-50375
A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= …
Eki 6333ac 2g Firmware
1.2.2 / 1.6.5+
CRITICAL 9.8
CVE-2024-11680 KEVEPSS 92%
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw…
Projectsend
Patch available
MEDIUM 5.3
CVE-2024-33616
Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporat…
Mitigation only