Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2022-40186
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deploymen…
Vault
1.9.9 / 1.10.6+
MEDIUM 5.3
CVE-2022-2877
The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowi…
Titan Anti Spam \& Security
7.3.1+
CRITICAL 9.1
CVE-2022-38789
An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to arbitrary values, …
Air 4920 Firmware
2020-08-04+
HIGH 7.5
CVE-2022-36539
WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and chi…
Eigen\&wijzer Ouderapp
1.1.22+
MEDIUM 5.3
CVE-2022-32277
Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a re…
Matrix
Mitigation only
CRITICAL 9.8
CVE-2022-36202
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access…
Doctor\'s Appointment System
Mitigation only
MEDIUM 5.3
CVE-2022-2034
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to acce…
Sensei Lms
4.5.0+
HIGH 8.8
CVE-2022-3019
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comme…
Tooljet
1.23.0+
MEDIUM 5.5
CVE-2021-4142
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (sim…
Candlepin
after 4.1.8-1
HIGH 7.5
CVE-2022-34770
Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive information such as health stateme…
Tabit
3.27.0+
HIGH 7.5
CVE-2022-34775
Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the rese…
Tabit
3.27.0+
MEDIUM 5.4
CVE-2022-2312
The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in us…
Student Result Or Employee Database
1.7.5+
MEDIUM 6.5
CVE-2022-34621
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords …
Mealie
Mitigation only
MEDIUM 5.4
CVE-2022-2824
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
Openemr
7.0.0.1+
MEDIUM 5.3
CVE-2022-2535
The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allo…
Searchwp Live Ajax Search
1.6.2+
MEDIUM 6.5
CVE-2022-2730
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
Openemr
7.0.0.1+
HIGH 7.5
CVE-2022-2367
The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to th…
Wsm Downloader
after 1.4.0
MEDIUM 6.5
CVE-2022-36284
Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal …
Affiliate For Woocommerce
after 4.7.0
MEDIUM 5.3
CVE-2022-1600
The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possib…
Yop Poll
6.4.3+
MEDIUM 6.5
CVE-2022-33944
The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “De…
Mv720 Firmware
Mitigation only
MEDIUM 5.4
CVE-2022-34150
The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device ID…
Mv720 Firmware
Mitigation only
HIGH 8.8
CVE-2022-2193
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticato…
Hypr Server
6.14.1+
HIGH 7.5
CVE-2021-24655
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a r…
Wp User Manager
2.6.3+
MEDIUM 5.3
CVE-2022-1881
In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project E…
Octopus Server
2021.3.13021 / 2022.1.2894+
CRITICAL 9.8
CVE-2022-1245
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…
Keycloak
18.0.0+
MEDIUM 6.3
CVE-2022-23173
this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - de…
Priority
22.0+
HIGH 8.8
CVE-2022-31883
Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys i…
Marval Msm
Mitigation only
HIGH 7.3
CVE-2022-0624
Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.
Parse Path
5.0.0+
MEDIUM 5.7
CVE-2017-20101
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_down…
Projectsend
No fix yet
HIGH 7.5
CVE-2022-1614
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possi…
Wp Email
2.69.0+