Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2019-19755
ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of al…
Mitigation only
HIGH 7.6
CVE-2024-28320
Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthori…
Hospital Management System
No fix yet
HIGH 8.8
CVE-2024-4294
A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is s…
Doctor Appointment Management System
No fix yet
CRITICAL 9.1
CVE-2024-33668
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker c…
Zammad
6.3.0+
HIGH 8.8
CVE-2024-32808
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.
Profilegrid
5.8.0+
MEDIUM 5.3
CVE-2024-32823
Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rat…
Rate My Post
3.4.5+
HIGH 8.8
CVE-2024-32772
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.
Profilegrid
5.8.0+
HIGH 8.8
CVE-2024-32166
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction …
Webid
No fix yet
HIGH 7.5
CVE-2024-32683
Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.…
Wp Ultimate Review
2.3.0+
HIGH 8.1
CVE-2024-1626
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, within the project update endpoint…
Lunary
1.0.0+
MEDIUM 5.4
CVE-2023-45808
iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In othe…
Itop
2.7.10 / 3.0.4+
MEDIUM 6.9
CVE-2024-22439
A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series products. This vulnerability could be exploited to ga…
No fix yet
MEDIUM 6.5
CVE-2023-51141
An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization compone…
Biotime
No fix yet
MEDIUM 6.5
CVE-2024-1625
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allowing unauthorized deletion of …
Lunary
Patch available
MEDIUM 5.4
CVE-2024-1289
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.…
Learnpress
4.2.6.4+
CRITICAL 9.8
CVE-2023-6317
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without …
Webos
No fix yet
HIGH 7.5
CVE-2024-27630
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the t…
Savane
3.13+
CRITICAL 9.1
CVE-2024-31815
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
Ex200 Firmware
No fix yet
HIGH 7.1
CVE-2024-31291
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.
Profilegrid
5.7.7+
MEDIUM 5.4
CVE-2024-31296
Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1…
Bookingpress
1.0.82+
HIGH 8.8
CVE-2023-6523
Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse.
This issue affects Extreme XD…
Mitigation only
MEDIUM 5.4
CVE-2024-3139
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue…
Computer Laboratory Management System
No fix yet
MEDIUM 6.5
CVE-2024-30543
Authorization Bypass Through User-Controlled Key vulnerability in UPQODE Whizz.This issue affects Whizzy: from n/a through 1.1.18.
Mitigation only
MEDIUM 5.3
CVE-2024-31095
Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.…
No fix yet
MEDIUM 6.5
CVE-2024-30513
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.
Profilegrid
5.7.3+
MEDIUM 5.3
CVE-2024-29020
JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive informa…
Jumpserver
3.10.6+
MEDIUM 5.3
CVE-2024-29024
JumpServer is an open source bastion host and an operation and maintenance security audit system.
An authenticated user can exploit the Insecure Dire…
Jumpserver
3.10.6+
MEDIUM 6.5
CVE-2024-1313
It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE …
Mitigation only
HIGH 8.3
CVE-2024-29194
OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data wit…
Oneuptime
7.0.1815+
MEDIUM 6.8
CVE-2024-1604
Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and ma…
Control M
9.0.20.238 / 9.0.21.201+