Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2024-21838
Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML c…
Command Centre
8.70.2526 / 8.80.1526+
HIGH 8.8
CVE-2024-1619
Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an a…
Security
after 8.0.3.30
MEDIUM 5.3
CVE-2024-21742
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message.
This can be exploited by an atta…
James Mime4j
after 0.8.9
CRITICAL 9.8
CVE-2024-1833
A vulnerability was found in SourceCodester Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functio…
Employee Management System
No fix yet
CRITICAL 9.8
CVE-2023-51388
Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no …
Hertzbeat
1.4.1+
CRITICAL 9.8
CVE-2023-51653
Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injec…
Hertzbeat
1.4.1+
HIGH 8.3
CVE-2024-23830
MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hija…
Mantisbt
2.26.1+
CRITICAL 9.3
CVE-2024-25625
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic…
Admin Classic Bundle
1.3.4+
CRITICAL 9.8
CVE-2024-22319EPSS 76%
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JND…
Operational Decision Manager
Patch available
HIGH 8.1
CVE-2023-51446
GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform L…
Glpi
10.0.12+
HIGH 8.8
CVE-2023-51939
An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive informat…
Relic
Patch available
HIGH 7.5
CVE-2023-36260
An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings …
Craft Cms
4.6.1.1+
HIGH 8.8
CVE-2024-23828
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when cha…
Nginx Ui
2.0.0+
HIGH 8.8
CVE-2024-23648
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a pas…
Admin Classic Bundle
1.2.3+
CRITICAL 9.8
CVE-2024-0579
A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDe…
X2000r Firmware
Mitigation only
MEDIUM 5.3
CVE-2021-4227
The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to …
Ark Wysiwyg Comment Editor
after 2.15.6
CRITICAL 9.8
CVE-2023-22527 KEVEPSS 100%
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an aff…
Confluence Data Center
8.5.4+
HIGH 7.6
CVE-2023-4818
PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PA…
Paydroid
No fix yet
MEDIUM 6.8
CVE-2023-42135
PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypass…
Paydroid
after 8.1.0_sagittarius_11.1.50_20230614
HIGH 7.8
CVE-2023-42136
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system …
Paydroid
after 8.1.0_sagittarius_11.1.50_20230614
CRITICAL 9.8
CVE-2024-0552
Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can exploit this vulnerability to e…
Smartrobot
after 6.0.0-202012tw
HIGH 7.5
CVE-2023-31025
NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead …
Dgx A100 Firmware
00.22.05+
MEDIUM 5.3
CVE-2024-21645EPSS 25%
pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any una…
Pyload
after 0.4.9
CRITICAL 9.6
CVE-2023-29050
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the i…
Ox App Suite
7.10.6+
MEDIUM 6.1
CVE-2023-50093
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
Api Gateway Manager
No fix yet
CRITICAL 9.6
CVE-2023-39655
A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in…
Couchauth
after 0.20.0
CRITICAL 9.8
CVE-2024-21623
OTCLient is an alternative tibia client for otserv. Prior to commit db560de0b56476c87a2f967466407939196dd254, the /mehah/otclient "`Analysis - SonarC…
Otclient
2023-12-30+
HIGH 8.8
CVE-2023-7114
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
Mattermost
2.10.1+
MEDIUM 5.3
CVE-2023-52081
ffcss is a CLI interface to apply and configure Firefox CSS themes. Prior to 0.2.0, the function `lookupPreprocess()` is meant to apply some transfor…
Firefox Css
0.2.0+
CRITICAL 9.8
CVE-2023-51664
tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows fo…
Changed Files
41.0.0+