Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2024-34130
Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Securit…
Acrobat Reader
24.5.0.33694+
MEDIUM 5.3
CVE-2024-34106
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in…
Commerce
after 1.4.0
HIGH 7.5
CVE-2024-2098
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLib…
Download Manager
3.2.90+
HIGH 8.1
CVE-2024-37300
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusO…
Patch available
CRITICAL 9.8
CVE-2024-36265
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.
This issue affects Apache Submarine Server Co…
Submarine
Mitigation only
HIGH 8.8
CVE-2024-2698
A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardabl…
Freeipa
4.11.2+
MEDIUM 6.8
CVE-2024-0160
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this…
Xps 17 9700 Firmware
1.28.0 / 1.29.0+
MEDIUM 5.4
CVE-2024-31403
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.
Garoon
6.0.1+
MEDIUM 5.3
CVE-2024-2473
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypas…
Wps Hide Login
1.9.16+
HIGH 7.8
CVE-2024-27848
This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may …
Ipados
14.5 / 17.5+
MEDIUM 6.5
CVE-2022-45168
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code end…
Vdesk
after 018
CRITICAL 9.8
CVE-2024-4146
In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects…
Lunary
Patch available
MEDIUM 6.5
CVE-2024-3404
In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. T…
Chuanhuchatgpt
20240919-4+
MEDIUM 5.3
CVE-2024-37154
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects …
Evmos
Mitigation only
CRITICAL 9.4
CVE-2024-3033
An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-…
Anythingllm
1.0.0+
MEDIUM 6.5
CVE-2024-3504
An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization us…
Lunary
1.2.7+
HIGH 8.8
CVE-2024-5324
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check o…
Login\/signup Popup
2.6.1 / 2.6.2+
HIGH 8.8
CVE-2024-23669
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…
Fortiwebmanager
6.2.5 / 7.0.5+
CRITICAL 9.8
CVE-2024-31682
Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint au…
Mitigation only
HIGH 7.5
CVE-2024-32983
Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming sign…
Misskey
2024.5.0+
HIGH 7.8
CVE-2024-36963
In the Linux kernel, the following vulnerability has been resolved:
tracefs: Reset permissions on remount if permissions are options
There's an inc…
Linux Kernel
6.6.31 / 6.8.10+
CRITICAL 9.8
CVE-2024-35353
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /cla…
Dino Physics School Assistant
No fix yet
HIGH 8.1
CVE-2024-36376
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
Teamcity
2024.03.2+
HIGH 8.1
CVE-2024-36377
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
Teamcity
2024.03.2+
MEDIUM 6.5
CVE-2024-36364
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build fe…
Teamcity
2022.04.7 / 2022.10.6+
HIGH 8.1
CVE-2024-36365
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
Teamcity
2022.04.7 / 2022.10.6+
MEDIUM 5.5
CVE-2024-36037
Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.
Manageengine Adaudit Plus
7.2+
MEDIUM 5.5
CVE-2024-36055
Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write access via t…
Mitigation only
HIGH 8.1
CVE-2024-27312
Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions.
…
Manageengine Pam360
6.6+
HIGH 7.8
CVE-2024-3745
MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads to triggering vulnerabilitie…
Mitigation only