Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-3701
The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform maliciou…
Hios
Mitigation only
CRITICAL 9.8
CVE-2024-3777
The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.
Qbibot
Mitigation only
MEDIUM 5.3
CVE-2024-3774
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, al…
A\+hrd
Mitigation only
HIGH 7.8
CVE-2024-26235
Windows Update Stack Elevation of Privilege Vulnerability
Windows Server 2022 23h2
10.0.25398.830+
HIGH 8.8
CVE-2024-3281
A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process d…
Poly Ccx 350
8.1.3.1301 / 8.1.1301+
CRITICAL 9.8
CVE-2023-1083
An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot…
Mitigation only
MEDIUM 6.7
CVE-2023-25493
A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that coul…
Mitigation only
CRITICAL 10.0
CVE-2023-48426
u-boot bug that allows for u-boot shell and interrupt over UART
Chromecast Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-31218
Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in versions 0.9.0 and earlier ar…
Patch available
MEDIUM 5.2
CVE-2023-6949
A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could all…
Mitigation only
HIGH 7.5
CVE-2023-51571
Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…
Viewpower
Mitigation only
CRITICAL 9.8
CVE-2024-2921
Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to…
Devolutions Server
2024.1.8.0+
CRITICAL 9.8
CVE-2022-38057
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through…
Th Advance Product Search
1.2.2+
CRITICAL 9.1
CVE-2020-26942
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminP…
Axigen Mail Server
10.3.1.27 / 10.3.3.1+
CRITICAL 9.8
CVE-2024-28179
Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access.…
Jupyter Server Proxy
3.2.3 / 4.1.1+
CRITICAL 9.8
CVE-2024-24578EPSS 9%
RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 co…
Raspberrymatic
3.75.6.20240316+
MEDIUM 5.3
CVE-2024-21824
Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES…
Mitigation only
MEDIUM 5.5
CVE-2024-22513
djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even afte…
Mitigation only
HIGH 8.8
CVE-2024-2450
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership wh…
Mattermost Server
8.1.10 / 9.2.6+
HIGH 8.2
CVE-2022-34321
Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The v…
Pulsar
2.10.6 / 2.11.3+
HIGH 8.4
CVE-2024-27758
In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_net…
Mitigation only
HIGH 7.5
CVE-2024-2076
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown f…
House Rental Management System
Mitigation only
MEDIUM 5.9
CVE-2023-37495
Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino…
Domino
14.0+
HIGH 7.5
CVE-2022-48621
Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect service c…
Emui
Mitigation only
HIGH 7.5
CVE-2024-26263
EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive…
Risweb
3.0+
HIGH 7.4
CVE-2024-25618
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (…
Mastodon
3.5.18 / 4.0.14+
HIGH 8.8
CVE-2024-23783
Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-…
Jh Rvb1 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-40545
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted r…
Pingfederate
Mitigation only
CRITICAL 9.8
CVE-2024-23917EPSS 54%
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
Teamcity
2023.11.3+
CRITICAL 9.1
CVE-2023-49617
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could…
Feverwarn Firmware
Mitigation only