Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-27730
Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the…
Friendica
Patch available
MEDIUM 5.7
CVE-2024-21981
Improper key usage control in AMD Secure Processor
(ASP) may allow an attacker with local access who has gained arbitrary code
execution privilege in…
Mitigation only
MEDIUM 6.5
CVE-2024-39642
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality Not Properly Constrained by ACL…
Mitigation only
MEDIUM 5.3
CVE-2024-7658
A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the f…
Projectsend
Patch available
HIGH 8.1
CVE-2024-3035
A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 1…
GitLab
17.0.6 / 17.1.4+
HIGH 8.8
CVE-2024-6357
Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.
Arcsight Intelligence
6.4.13+
MEDIUM 5.3
CVE-2024-41254
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attacke…
Litestream
after 0.3.13
HIGH 8.8
CVE-2024-38701
Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
Academy Lms
2.0.5+
MEDIUM 6.5
CVE-2024-34457
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone'…
Streampark
2.1.4+
MEDIUM 5.4
CVE-2024-5977
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a…
Givewp
3.14.0+
CRITICAL 9.6
CVE-2024-5619
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Con…
Mitigation only
HIGH 8.1
CVE-2024-38447
NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbit…
Advisor Network
No fix yet
MEDIUM 6.5
CVE-2024-38446
NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of tha…
Advisor Network
No fix yet
MEDIUM 5.4
CVE-2024-39900
OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin …
Observability
2.14+
MEDIUM 5.4
CVE-2024-39901
OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugin…
Observability
2.14+
MEDIUM 6.5
CVE-2023-3286
A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in una…
Easyappointments
1.5.0+
HIGH 8.8
CVE-2023-3287
A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege e…
Easyappointments
1.5.0+
HIGH 8.8
CVE-2023-3288
A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege …
Easyappointments
1.5.0+
MEDIUM 6.5
CVE-2023-3289
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in…
Easyappointments
1.5.0+
MEDIUM 5.0
CVE-2023-3290
A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauth…
Easyappointments
1.5.0+
HIGH 8.1
CVE-2023-38055
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (incl…
Easyappointments
1.5.0+
HIGH 8.1
CVE-2023-38050
A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (includi…
Easyappointments
1.5.0+
HIGH 8.1
CVE-2023-38051
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (se…
Easyappointments
1.5.0+
HIGH 8.1
CVE-2023-38052
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). Th…
Easyappointments
1.5.0+
HIGH 8.1
CVE-2023-38053
A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (in…
Easyappointments
1.5.0+
HIGH 8.1
CVE-2023-38054
A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (custo…
Easyappointments
1.5.0+
HIGH 8.1
CVE-2023-38047
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (i…
Easyappointments
1.5.0+
HIGH 8.1
CVE-2023-38048
A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider)…
Easyappointments
1.5.0+
HIGH 8.1
CVE-2023-38049
A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any …
Easyappointments
1.5.0+
HIGH 7.7
CVE-2023-3285
A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This r…
Mitigation only