Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2024-48217
An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.
Mitigation only
CRITICAL 9.8
CVE-2024-37277
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACL…
Paid Memberships Pro
3.0.5+
CRITICAL 9.1
CVE-2024-10654
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functiona…
Lr350 Firmware
No fix yet
HIGH 7.5
CVE-2024-51066
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unaut…
Beauty Parlour Management System
No fix yet
MEDIUM 5.3
CVE-2024-9700
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…
Forminator Forms
1.36.1+
MEDIUM 6.5
CVE-2024-7473
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability all…
Lunary
Patch available
HIGH 8.1
CVE-2024-7474
In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by ma…
Lunary
1.3.4+
CRITICAL 9.8
CVE-2024-50483
Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: fr…
Meetup
after 0.1
HIGH 7.5
CVE-2024-10439
The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specifi…
Ehrd Ctms
10.8+
HIGH 8.8
CVE-2024-9637
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, a…
Wpschoolpress
2.2.11+
CRITICAL 9.8
CVE-2024-10121
A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Inter…
Radar
after 1.0.8
CRITICAL 9.8
CVE-2024-9263
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privileg…
Mitigation only
CRITICAL 9.8
CVE-2024-9862
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, …
Otp Verification With Firebase
3.6.1+
HIGH 8.8
CVE-2024-9215
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct O…
Mitigation only
MEDIUM 5.9
CVE-2023-32189
Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys
Mitigation only
HIGH 7.7
CVE-2024-8040
An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated…
Mitigation only
MEDIUM 6.5
CVE-2023-7286
The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes …
Mitigation only
CRITICAL 9.1
CVE-2024-49388
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) befo…
Cyber Protect
after 15
HIGH 8.8
CVE-2024-9687
The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficie…
Wp 2fa With Telegram
3.1+
MEDIUM 6.7
CVE-2024-47495
An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of t…
Junos Os Evolved
21.2+
MEDIUM 6.5
CVE-2024-7041
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint…
Open Webui
No fix yet
HIGH 8.8
CVE-2024-47316
Authorization Bypass Through User-Controlled Key vulnerability in Dimitri Grassi Salon booking system salon-booking-system.This issue affects Salon b…
Salon Booking System
10.9.1+
MEDIUM 6.5
CVE-2024-47657
This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker co…
Net Back Office
5.5.002+
MEDIUM 5.3
CVE-2024-20513
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthentic…
Meraki Mx65 Firmware
18.211.2+
MEDIUM 6.8
CVE-2021-37577
Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 th…
Mitigation only
MEDIUM 5.3
CVE-2024-39319
aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 20…
Aimeos Frontend Controller
2020.10.15 / 2021.10.8+
HIGH 8.8
CVE-2024-8290
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direc…
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible
6.7.13+
CRITICAL 9.8
CVE-2024-8485
The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.…
Rest Api To Miniprogram
after 4.7.1
CRITICAL 9.8
CVE-2024-8791
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation i…
Charitable
1.8.1.15+
MEDIUM 6.5
CVE-2024-45806
Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy hea…
Envoy
1.28.7 / 1.29.9+