Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2024-34434
Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This…
Wordpress Meta Data And Taxonomies Filter
1.3.3.3+
CRITICAL 9.1
CVE-2024-35187
Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user…
Mitigation only
HIGH 7.5
CVE-2024-31409
Certain MQTT wildcards are not blocked on the
CyberPower PowerPanel
system, which might result in an attacker obtaining data from throughout the sy…
Powerpanel
after 4.9.0
MEDIUM 5.4
CVE-2024-3722
The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function…
Mitigation only
MEDIUM 5.9
CVE-2024-34701
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered as the requester of a specifi…
Patch available
HIGH 7.5
CVE-2024-31441
DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data sou…
Dataease
1.18.19+
HIGH 7.8
CVE-2024-27798
An authorization issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 1…
macOS
12.7.5 / 13.6.7+
CRITICAL 9.0
CVE-2024-34346
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/w…
Deno
1.43.1+
HIGH 7.8
CVE-2024-0043
In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. This c…
Android
Patch available
HIGH 7.8
CVE-2023-42124
Avast Premium Security Sandbox Protection Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to es…
Premium Security
Mitigation only
HIGH 7.3
CVE-2024-3957
The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allow…
Booster For Woocommerce
7.1.9+
HIGH 8.8
CVE-2024-1677
The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized ac…
Print Labels With Barcodes
3.4.7+
MEDIUM 6.5
CVE-2024-34146
Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing a…
Git Server
after 114.v068a_c7cc2574
HIGH 8.0
CVE-2024-2378
A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privileges on af-fected installatio…
No fix yet
HIGH 8.1
CVE-2023-50363
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…
Qts
Mitigation only
CRITICAL 9.8
CVE-2023-51405
Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…
Bookingpress
1.0.75+
HIGH 7.5
CVE-2024-28627
An issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file.
Mitigation only
MEDIUM 6.5
CVE-2024-32470
Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was in…
Tolgee
3.57.4+
CRITICAL 9.8
CVE-2024-31452
OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization…
Openfga
1.5.3+
MEDIUM 5.3
CVE-2024-21120
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affe…
Outside In Technology
Mitigation only
HIGH 7.2
CVE-2024-21083
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Supported versions that are affected are 7.0.0.0.0 …
Bi Publisher
Mitigation only
CRITICAL 9.9
CVE-2024-21010
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported…
Hospitality Simphony
after 19.5.4
HIGH 7.5
CVE-2024-1738
An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations …
Lunary
1.2.4+
MEDIUM 6.3
CVE-2024-31990
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attac…
Argo Cd
2.8.16 / 2.9.12+
MEDIUM 6.5
CVE-2024-1307
The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a s…
Smart Forms
2.6.94+
HIGH 7.4
CVE-2024-27309
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.
Two preconditi…
Kafka
after 3.6.1
MEDIUM 5.0
CVE-2024-3388
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and …
Pan Os
8.1.26 / 9.0.17+
CRITICAL 9.1
CVE-2024-1740
In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs b…
Lunary
1.2.7+
CRITICAL 9.1
CVE-2024-1741
lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates…
Lunary
1.2.8+
CRITICAL 9.1
CVE-2023-52538
Vulnerability of package name verification being bypassed in the HwIms module.
Impact: Successful exploitation of this vulnerability will affect avai…
Emui
No fix yet