Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-48166
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and …
Wl Wn530hg4 Firmware
No fix yet
HIGH 8.8
CVE-2021-36225
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads an…
My Cloud Os
5.02.104+
MEDIUM 5.3
CVE-2023-0678EPSS 37%
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
Phpipam
1.5.1+
MEDIUM 5.4
CVE-2022-42909
WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This c…
Print Away
Mitigation only
HIGH 7.5
CVE-2023-25014
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the Invit…
Femanager
5.5.3 / 6.3.4+
MEDIUM 6.5
CVE-2023-0619
The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in ver…
Kraken.io Image Optimizer
after 2.6.8
MEDIUM 6.5
CVE-2023-22737
wire-server provides back end services for Wire, a team communication and collaboration platform. Prior to version 2022-12-09, every member of a Conv…
Wire
2022-12-09+
MEDIUM 6.5
CVE-2023-0556
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to…
Contentstudio
1.2.6+
CRITICAL 9.1
CVE-2022-39811
Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not ve…
Netmatch S Ci
No fix yet
HIGH 8.1
CVE-2023-0555
The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in version…
Quick Restaurant Menu
2.1.0+
MEDIUM 6.5
CVE-2023-24459
A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…
Bearychat
after 3.0.2
MEDIUM 6.5
CVE-2023-24448
A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permission to connect to an attacke…
Rabbitmq Consumer
after 2.8
MEDIUM 6.5
CVE-2023-24453
A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi…
Testquality Updater
after 1.3
MEDIUM 6.5
CVE-2023-24433
Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permission to connect to an attacke…
Orka By Macstadium
1.32+
MEDIUM 6.5
CVE-2023-24435
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect …
Github Pull Request Builder
after 1.42.2
MEDIUM 6.5
CVE-2023-24438
A missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers with Overall/Read permission to c…
Jira Pipeline Steps
after 2.0.165.v8846cf59f3db
MEDIUM 5.4
CVE-2023-23611
LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and …
Xblock Lti Consumer
7.2.2+
HIGH 8.5
CVE-2023-22736
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6…
Argo Cd
2.5.8+
HIGH 7.8
CVE-2023-20912
In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check…
Android
Mitigation only
HIGH 7.8
CVE-2023-20916
In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starting activities from the backgr…
Android
Mitigation only
MEDIUM 5.3
CVE-2022-3482
An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 all…
GitLab
15.4.6 / 15.5.5+
MEDIUM 5.4
CVE-2023-0404
The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJA…
Events Made Easy
after 2.3.16
MEDIUM 5.4
CVE-2023-0402
The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions u…
Social Warfare
after 4.3.0
HIGH 8.8
CVE-2023-0242
Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on th…
Velociraptor
0.6.7-5+
CRITICAL 9.8
CVE-2022-41417
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.
Blogengine.net
Patch available
MEDIUM 6.8
CVE-2020-22007
OS Command Injection vulnerability in OKER G955V1 v1.03.02.20161128, allows physical attackers to interrupt the boot sequence and execute arbitrary c…
G955v1 Firmware
No fix yet
HIGH 7.5
CVE-2023-22478
KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in…
Kubepi
1.6.4+
MEDIUM 5.4
CVE-2023-22488
Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private content and bypass access check…
Flarum
1.6.3+
MEDIUM 5.5
CVE-2022-44438
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio…
Android
Mitigation only
MEDIUM 5.5
CVE-2022-44439
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio…
Android
Mitigation only