Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2024-44253
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be abl…
macOS
13.7.1 / 14.7.1+
MEDIUM 5.5
CVE-2024-44196
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1.…
macOS
13.7.1 / 14.7.1+
MEDIUM 5.5
CVE-2024-40855
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2. A sandb…
macOS
13.7.1 / 14.7.1+
MEDIUM 5.4
CVE-2024-9825
The Chef Habitat builder-api on-prem-builder package with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect …
Mitigation only
MEDIUM 5.0
CVE-2024-48936
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute process…
Slurm
24.05.4+
CRITICAL 9.8
CVE-2024-48237
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
Wtcms
No fix yet
HIGH 8.8
CVE-2022-30358
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw pa…
Ovaledge
after 5.2.8
HIGH 8.8
CVE-2024-49376
Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0.…
Autolab
Patch available
MEDIUM 5.5
CVE-2024-47025
In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information di…
Android
Mitigation only
MEDIUM 5.5
CVE-2024-44099
There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additi…
Android
No fix yet
CRITICAL 9.8
CVE-2024-41617
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions…
Patch available
HIGH 8.0
CVE-2024-45261
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific use…
Mt2500 Firmware
4.6.4+
HIGH 8.0
CVE-2024-45260
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized gro…
Mt6000 Firmware
4.6.4+
HIGH 7.5
CVE-2024-10295
A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal…
3scale Api Management
Mitigation only
HIGH 8.4
CVE-2024-48541
Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by an…
Mitigation only
HIGH 8.4
CVE-2024-48542
Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive in…
Mitigation only
HIGH 8.4
CVE-2024-48544
Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information…
Mitigation only
HIGH 8.4
CVE-2024-48545
Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyz…
Mitigation only
HIGH 8.4
CVE-2024-48546
Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyz…
Mitigation only
HIGH 8.4
CVE-2024-48547
Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information b…
Mitigation only
CRITICAL 9.3
CVE-2024-48548
The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to …
Mitigation only
MEDIUM 6.2
CVE-2024-48540
Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.
Mitigation only
MEDIUM 6.5
CVE-2024-20482
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…
Secure Firewall Management Center
Mitigation only
MEDIUM 6.5
CVE-2024-48925
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version …
Umbraco Cms
14.3.0+
HIGH 8.8
CVE-2024-38002
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…
Digital Experience Platform
7.4.3.112 / 2023.q3.9+
HIGH 7.5
CVE-2024-10173
A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the compone…
Ddmq
No fix yet
HIGH 7.8
CVE-2024-29213
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified …
Desktop \& Server Management
2024.2+
HIGH 7.8
CVE-2024-29821
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified …
Desktop \& Server Management
2024.2+
HIGH 8.8
CVE-2024-20420
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote …
Ata 191 Firmware
11.2.5 / 12.0.2+
CRITICAL 9.8
CVE-2024-45216EPSS 91%
Improper Authentication vulnerability in Apache Solr.
Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…
Solr
8.11.4 / 9.7.0+