Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2024-9202
In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a re…
Eclipse Dataspace Components
0.9.1+
MEDIUM 5.3
CVE-2024-9025
The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch…
Sight
1.1.3+
HIGH 8.8
CVE-2024-47330
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsys…
Slider
1.8.7+
MEDIUM 5.3
CVE-2024-8678
The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …
Revolut Gateway For Woocommerce
4.17.4+
MEDIUM 5.3
CVE-2024-6845
The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users…
Chatbot With Chatgpt
2.4.6+
MEDIUM 5.3
CVE-2024-8658
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooComm…
Mycred
2.7.4+
HIGH 7.2
CVE-2024-8349
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is du…
Uncanny Groups For Learndash
6.1.1+
MEDIUM 6.5
CVE-2022-25768
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. …
Mautic
4.4.13 / 5.1.1+
HIGH 8.5
CVE-2024-6406
Missing Authentication for Critical Function, Missing Authorization vulnerability in Yordam Information Technology Mobile Library Application allows …
Mitigation only
MEDIUM 5.3
CVE-2024-40852
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to s…
Ipados
18.0+
HIGH 7.5
CVE-2024-4660
An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all…
GitLab
17.1.7 / 17.2.5+
HIGH 7.5
CVE-2024-3305
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensiti…
Soliclub
4.4.0 / 5.2.1+
MEDIUM 5.3
CVE-2024-7727
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil…
Html5 Video Player
2.5.33+
HIGH 7.8
CVE-2024-40650
In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of p…
Android
Patch available
HIGH 7.8
CVE-2024-40652
In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing pe…
Android
Patch available
MEDIUM 5.3
CVE-2024-45591
XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed in…
Xwiki
15.10.9 / 16.3.0+
MEDIUM 6.4
CVE-2024-45393
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can acc…
Computer Vision Annotation Tool
2.18.0+
MEDIUM 5.3
CVE-2024-8369
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected eve…
Eventprime
4.0.4.4+
MEDIUM 5.4
CVE-2024-45285
The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By s…
Mitigation only
MEDIUM 5.4
CVE-2024-44117
The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and…
Mitigation only
MEDIUM 6.5
CVE-2024-45286
Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting …
Mitigation only
MEDIUM 5.4
CVE-2024-42371
The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to …
Mitigation only
HIGH 7.8
CVE-2024-40709
A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.
Mitigation only
HIGH 7.8
CVE-2023-39298
A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…
Qts
Mitigation only
HIGH 7.5
CVE-2024-44408
D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the down…
Dir 823g Firmware
No fix yet
HIGH 7.5
CVE-2024-1744
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive…
Accord Ors
7.3.2.1+
HIGH 8.8
CVE-2024-8480
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check…
Sirv
7.2.8+
MEDIUM 5.3
CVE-2024-7381
The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the a…
Geo Controller
after 8.6.9
MEDIUM 6.5
CVE-2024-6332
The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to…
Amelia
after 7.7
MEDIUM 5.4
CVE-2024-5309
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missi…
Form Vibes
1.4.13+