Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-31182
EasyTor Applications – Authorization Bypass - EasyTor Applications may allow authorization bypass via unspecified method.
Easytor
No fix yet
MEDIUM 5.4
CVE-2023-30216
Insecure permissions in the updateUserInfo function of newbee-mall before commit 1f2c2dfy allows attackers to obtain user account information.
Newbee Mall
2022-10-27+
HIGH 8.1
CVE-2023-28656
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.
Note: So…
Nginx Api Connectivity Manager
1.3.0 / 1.5.0+
MEDIUM 6.5
CVE-2023-1125
The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an a…
Ruby Help Desk
1.3.4+
HIGH 8.8
CVE-2023-2260
Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
Alf
2.0-m4-2304+
MEDIUM 6.5
CVE-2022-48313
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may…
Emui
No fix yet
HIGH 7.5
CVE-2018-17449
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers co…
GitLab
11.1.7 / 11.2.4+
HIGH 7.5
CVE-2018-17455
An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive …
GitLab
11.1.7 / 11.2.4+
MEDIUM 6.5
CVE-2022-45175
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/…
Vdesk
after 018
MEDIUM 6.5
CVE-2023-0967
Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that sh…
Bhima
No fix yet
MEDIUM 6.5
CVE-2023-1749
The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could se…
Nxal 100 Firmware
Mitigation only
HIGH 7.1
CVE-2023-1750
The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could re…
Nxal 100 Firmware
Mitigation only
HIGH 8.1
CVE-2023-26984
An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted re…
Peppermint
No fix yet
MEDIUM 5.3
CVE-2023-24842
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial …
Oaklouds Mailsherlock
Mitigation only
MEDIUM 6.5
CVE-2023-24834
WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this…
Tronclass Ilearn
1.52.29198+
MEDIUM 6.5
CVE-2023-24625
Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.
Faveo Servicedesk
No fix yet
HIGH 7.1
CVE-2023-28686
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attac…
Fedora
0.2.3 / 0.3.2+
HIGH 8.8
CVE-2023-1462
Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Authentication Bypass, Authentic…
Digikent
23.03.20+
HIGH 8.8
CVE-2023-0865
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete an…
Woocommerce Multiple Customer Addresses \& Shipping
21.7+
MEDIUM 5.4
CVE-2023-1463
Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
Teampass
3.0.0.23+
MEDIUM 6.5
CVE-2023-28109
Play With Docker is a browser-based Docker playground. Versions 0.0.2 and prior are vulnerable to domain hijacking.
Because CORS configuration was no…
Play With Docker
Patch available
MEDIUM 5.3
CVE-2021-36400
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
Moodle
3.9.8 / 3.10.5+
HIGH 7.5
CVE-2023-25403
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format cha…
Yf Exam
No fix yet
HIGH 8.8
CVE-2023-0882
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abu…
Single Connect
2.16.1+
MEDIUM 5.3
CVE-2023-25160
Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access th…
Mail
1.11.8 / 1.12.9+
HIGH 7.5
CVE-2022-34138
Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive informati…
Baby Camera Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-0558
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in v…
Contentstudio
1.2.6+
HIGH 8.1
CVE-2023-0550
The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due…
Quick Restaurant Menu
2.1.0+
MEDIUM 6.5
CVE-2021-36539
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL…
Canvas Learning Management Service
2022-10-15+
HIGH 8.8
CVE-2022-45927
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication …
Opentext Extended Ecm
22.4+