Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-38965
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
Lost And Found Information System
No fix yet
HIGH 8.8
CVE-2023-46478
An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.
Minical
No fix yet
MEDIUM 5.3
CVE-2023-3869
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment functi…
Wpdiscuz
after 7.6.3
MEDIUM 5.3
CVE-2023-3998
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in…
Wpdiscuz
after 7.6.3
HIGH 8.1
CVE-2022-24401
Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TD…
Tetra\
Mitigation only
MEDIUM 5.9
CVE-2022-24400
A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.
Tetra\
Mitigation only
CRITICAL 9.8
CVE-2023-43668
Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,
some se…
Inlong
after 1.8.0
MEDIUM 6.5
CVE-2023-45393
An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information v…
Utime Master
No fix yet
MEDIUM 6.5
CVE-2023-45396
An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter running on version 3.12.
Etg150 Firmware
Mitigation only
CRITICAL 9.1
CVE-2023-44981
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru…
Zookeeper
3.7.2 / 3.8.3+
MEDIUM 6.5
CVE-2023-44249
An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer…
Fortianalyzer
7.2.4+
HIGH 8.8
CVE-2023-42455
Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API admin…
Wazuh Dashboard
4.4.2+
MEDIUM 6.7
CVE-2023-26237
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.
Epp Firmware
8.00.22.0010+
MEDIUM 6.5
CVE-2023-2544
Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an authenticated user could chan…
Peix
Mitigation only
MEDIUM 5.4
CVE-2023-32669
Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other…
Buddyboss
Mitigation only
MEDIUM 6.5
CVE-2023-4099
The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions t…
Qsige
Mitigation only
MEDIUM 6.5
CVE-2023-4101
The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. A…
Qsige
Mitigation only
HIGH 8.8
CVE-2023-4934
Authorization Bypass Through User-Controlled Key vulnerability in Usta AYBS allows Authentication Abuse, Authentication Bypass.
This issue affects A…
Aybs
1.0.3+
MEDIUM 5.3
CVE-2023-44205
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before…
Cyber Protect
15+
CRITICAL 9.1
CVE-2023-44206
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux…
Cyber Protect
15+
HIGH 8.1
CVE-2023-44154
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux…
Cyber Protect
15+
MEDIUM 6.5
CVE-2023-42334
An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user par…
Crew
No fix yet
HIGH 8.8
CVE-2023-4213
The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.4.5. T…
Simplr Registration Form Plus\+
after 2.4.5
MEDIUM 5.3
CVE-2023-41368
The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by …
S\/4 Hana
Mitigation only
HIGH 8.8
CVE-2020-10130
SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system.
Searchblox
9.1+
MEDIUM 5.5
CVE-2023-4587
An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered…
Zem800 Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-38201
A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allo…
Enterprise Linux
Patch available
HIGH 7.5
CVE-2023-32078
Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions prior to 0.17.1 and 0.18.6 in …
Netmaker
0.17.1+
MEDIUM 6.7
CVE-2023-27576
An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, al…
Phplist
Patch available
HIGH 8.8
CVE-2023-28481
An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergra…
Tigergraph
No fix yet