Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2024-4341
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by U…
Extreme Xds
3928+
HIGH 7.5
CVE-2024-39321
Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allo…
Traefik
2.11.6 / 3.0.4+
CRITICAL 9.8
CVE-2024-39223
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to …
Mitigation only
MEDIUM 5.4
CVE-2024-31898
IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using in…
Infosphere Information Server
Mitigation only
MEDIUM 5.4
CVE-2024-5942
The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'con…
Page And Post Clone
6.1+
CRITICAL 9.8
CVE-2024-1107
Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Contr…
Travel Apps
17.0.68+
MEDIUM 6.5
CVE-2023-49112
Kiuwan provides an API endpoint
/saas/rest/v1/info/application
to get information about any
application, providing only its name via the "applicat…
Mitigation only
MEDIUM 6.5
CVE-2024-37889
MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method …
Myfinances
0.4.6+
MEDIUM 6.3
CVE-2024-33373
An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authenti…
Bl W1210m Firmware
Mitigation only
CRITICAL 9.1
CVE-2024-2472
The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on …
Latepoint
4.9.91+
MEDIUM 6.5
CVE-2024-5131
An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability a…
Lunary
1.2.25+
HIGH 8.8
CVE-2024-5128
An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulne…
Lunary
1.2.25+
HIGH 7.5
CVE-2024-5130
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete …
Lunary
1.2.8+
MEDIUM 6.3
CVE-2024-36399
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php functio…
Kanboard
1.2.37+
MEDIUM 5.3
CVE-2024-4750
The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID …
Buddyboss
2.6.0+
MEDIUM 5.9
CVE-2024-32045
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linki…
Mattermost Server
8.1.13 / 9.5.4+
MEDIUM 6.5
CVE-2024-5166
An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML mode…
Looker
Mitigation only
MEDIUM 6.5
CVE-2024-4154
In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to…
Lunary
1.2.26+
HIGH 8.1
CVE-2024-4151
An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to…
Lunary
1.2.25+
MEDIUM 6.5
CVE-2024-4279
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Delet…
Tutor Lms
2.7.1+
HIGH 7.1
CVE-2023-40720
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allo…
Fortivoice
after 6.4.8
HIGH 8.8
CVE-2024-4819
A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function o…
Online Laundry Management System
No fix yet
HIGH 8.8
CVE-2024-4817
A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code …
Online Laundry Management System
No fix yet
HIGH 7.5
CVE-2024-33818
Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.
Mitigation only
HIGH 7.5
CVE-2024-4538
IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain a user's event ticket…
Mitigation only
HIGH 7.5
CVE-2024-4537
IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of a…
Mitigation only
MEDIUM 5.3
CVE-2024-34383
Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n/a through 7.7…
Mitigation only
MEDIUM 5.4
CVE-2024-2346
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …
Filebird
5.6.4+
HIGH 7.5
CVE-2024-24312
SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/UserMod…
Mitigation only
HIGH 7.5
CVE-2024-33383
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request u…
Novel Plus
after 4.3.0