Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2024-54662
Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.
Mitigation only
HIGH 7.5
CVE-2024-37775
Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.
Dctrack
Mitigation only
MEDIUM 5.3
CVE-2024-8116
An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a s…
GitLab
17.4.6 / 17.5.4+
MEDIUM 5.3
CVE-2024-8650
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed…
GitLab
17.4.6 / 17.5.4+
HIGH 8.8
CVE-2024-55662
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extensio…
Xwiki
15.10.9 / 16.3.0+
MEDIUM 6.5
CVE-2024-55633
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed…
Superset
4.1.0+
MEDIUM 5.5
CVE-2024-54495
The issue was addressed with improved permissions logic. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to modify…
macOS
14.7.2 / 15.2+
MEDIUM 6.5
CVE-2024-53949
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users …
Superset
4.1.0+
HIGH 8.8
CVE-2024-55579
An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create …
Mitigation only
MEDIUM 6.5
CVE-2024-12196
Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password hi…
Devolutions Server
2024.3.8.0+
MEDIUM 6.5
CVE-2024-42451
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a s…
Veeam Backup \& Replication
12.3.0.310+
HIGH 8.8
CVE-2024-42452
A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectiv…
Veeam Backup \& Replication
12.3.0.310+
HIGH 8.1
CVE-2024-45106
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…
Ozone
Mitigation only
HIGH 8.8
CVE-2024-53937
An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by defau…
Mitigation only
HIGH 8.8
CVE-2024-53941
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximity to a W…
Mitigation only
CRITICAL 9.1
CVE-2024-52732
Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused.
Mitigation only
HIGH 7.5
CVE-2024-36611
In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where t…
Patch available
HIGH 7.5
CVE-2024-48651
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups…
Patch available
HIGH 8.8
CVE-2024-54124
In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.
Mitigation only
HIGH 7.8
CVE-2018-9374
In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User…
Android
Patch available
HIGH 7.5
CVE-2024-11669
An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API end…
GitLab
17.4.5 / 17.5.3+
HIGH 7.8
CVE-2024-7915
The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the ro…
Mitigation only
MEDIUM 5.4
CVE-2024-11670
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malici…
Remote Desktop Manager
after 2024.3.10.0
MEDIUM 5.3
CVE-2024-11176
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorre…
Mitigation only
HIGH 7.8
CVE-2023-21270
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to …
Android
Patch available
HIGH 7.5
CVE-2024-21287 KEV
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The suppor…
Agile Product Lifecycle Management
Mitigation only
MEDIUM 5.4
CVE-2024-52584
Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view…
Autolab
Patch available
MEDIUM 5.4
CVE-2024-52518
Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would b…
Nextcloud Server
28.0.12 / 29.0.9+
HIGH 7.5
CVE-2024-50647
The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access …
Mitigation only
HIGH 7.5
CVE-2024-50650
python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by mod…
Python Book
No fix yet