Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2024-42423
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogi…
Workspace
Mitigation only
HIGH 7.5
CVE-2024-6979
Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or view…
Axis Os 2024
11.11.94+
MEDIUM 6.5
CVE-2024-8601
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An auth…
Back Office Software
1.0.0+
MEDIUM 5.5
CVE-2024-34651
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
Android
Mitigation only
HIGH 8.1
CVE-2024-45588
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module …
Xts Mobile Trader
Mitigation only
HIGH 8.8
CVE-2024-45586
This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platfor…
Xts Mobile Trader
Mitigation only
HIGH 8.8
CVE-2024-45587
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module…
Xts Mobile Trader
Mitigation only
MEDIUM 6.5
CVE-2024-45509
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not…
Misp
2.4.197+
HIGH 8.3
CVE-2024-38868
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Cent…
Manageengine Endpoint Central
11.3.2400.15 / 11.3.2406.08+
HIGH 8.1
CVE-2024-41964
Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform …
Kirby
3.6.6.6 / 3.7.5.5+
MEDIUM 6.3
CVE-2024-43954
Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Droip: from…
Droip
after 1.1.1
MEDIUM 5.3
CVE-2024-45043
The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream messages and parsing the records …
Patch available
MEDIUM 6.4
CVE-2024-45037
The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own ap…
Aws Cloud Development Kit
2.148.1+
MEDIUM 5.5
CVE-2024-8011
Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the …
Options\+
1.72+
MEDIUM 5.4
CVE-2024-38869
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects En…
Manageengine Servicedesk Plus
after 14.7
CRITICAL 9.1
CVE-2024-42773
An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an una…
Hotel Management System
No fix yet
HIGH 7.8
CVE-2024-7604
Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This vulnerability allows local attackers to bypass auth…
Unified Secops Platform
Mitigation only
MEDIUM 6.5
CVE-2024-6337
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_reques…
Enterprise Server
3.10.16 / 3.11.14+
HIGH 8.8
CVE-2024-31842
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The quer…
Embrace
Mitigation only
HIGH 8.8
CVE-2024-39690
Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespa…
Capsule
after 0.7.0
MEDIUM 6.5
CVE-2024-43250
Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue …
Bit Form
after 2.6.4
CRITICAL 9.8
CVE-2024-42966
Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the userna…
N350rt Firmware
No fix yet
HIGH 8.1
CVE-2024-7624
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is …
Zephyr Project Manager
3.3.102+
HIGH 7.5
CVE-2024-43131
Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Co…
Docket
1.7.0+
HIGH 8.8
CVE-2024-41939
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This…
Sinec Nms
3.0+
CRITICAL 9.8
CVE-2024-42473
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model t…
Openfga
Mitigation only
HIGH 8.8
CVE-2024-7265
Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change…
Ezd Rp
15.84 / 16.15+
HIGH 7.2
CVE-2024-42062
CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register ran…
Cloudstack
4.18.2.3 / 4.19.1.1+
HIGH 8.8
CVE-2024-6358
Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.
Arcsight Intelligence
6.4.13+
CRITICAL 9.8
CVE-2024-6202
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymo…
Haloitsm
2.143.61 / 2.146.1+