Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2023-42703
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local …
Android
Mitigation only
MEDIUM 5.5
CVE-2023-42704
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
Android
Mitigation only
MEDIUM 5.5
CVE-2023-42671
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
Android
Mitigation only
MEDIUM 5.5
CVE-2023-42672
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
Android
Mitigation only
MEDIUM 5.5
CVE-2023-42673
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
Android
Mitigation only
MEDIUM 5.5
CVE-2023-42674
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
Android
Mitigation only
MEDIUM 5.5
CVE-2023-42675
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
Android
Mitigation only
MEDIUM 5.5
CVE-2023-42676
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
Android
Mitigation only
MEDIUM 5.5
CVE-2023-42677
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
Android
Mitigation only
MEDIUM 5.5
CVE-2023-42678
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
Android
Mitigation only
HIGH 7.8
CVE-2023-42681
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privilege…
Android
Mitigation only
HIGH 8.8
CVE-2023-47870
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Access…
Wpforo Forum
after 2.2.6
MEDIUM 6.5
CVE-2023-49620
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), …
Dolphinscheduler
3.1.0+
CRITICAL 9.8
CVE-2023-49654
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller f…
Matlab
2.11.1+
MEDIUM 5.3
CVE-2023-5611
The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, al…
Seraphinite Accelerator
2.20.32+
HIGH 7.5
CVE-2023-30581
The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.json definit…
Node.js
16.20.1 / 18.16.1+
MEDIUM 6.5
CVE-2023-6007
The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check o…
Userpro
after 5.1.1
MEDIUM 5.3
CVE-2023-2448
The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' f…
Userpro
after 5.1.4
HIGH 8.8
CVE-2023-47757
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead …
Aweber
7.3.10+
HIGH 8.8
CVE-2023-39544
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSaf…
Expresscluster X
Patch available
MEDIUM 5.4
CVE-2023-48222
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in bot…
Rundeck
4.17.3+
HIGH 7.5
CVE-2023-6020EPSS 15%
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
Ray
No fix yet
HIGH 7.5
CVE-2023-6038
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the ser…
H2o
No fix yet
MEDIUM 5.3
CVE-2023-4723
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the aj…
Elementor Addon Elements
after 1.12.7
HIGH 7.5
CVE-2023-6001
Prometheus metrics are available without
authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.
Yugabytedb
2.18.4.0+
HIGH 8.1
CVE-2023-43885
Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the dev…
Rx9 Pro Firmware
No fix yet
HIGH 7.5
CVE-2023-5454
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users t…
Templately
2.2.6+
MEDIUM 6.5
CVE-2023-4700
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed …
GitLab
16.3.6 / 16.4.2+
CRITICAL 9.1
CVE-2023-36621
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictio…
Boomerang
13.83+
MEDIUM 5.3
CVE-2023-43194
Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.
Submitty
Patch available