Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-49240
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
Emui
No fix yet
HIGH 7.5
CVE-2023-49246
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
Emui
Mitigation only
MEDIUM 6.8
CVE-2023-42575
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid fl…
Pass
4.3.00.17+
HIGH 7.8
CVE-2023-33071
Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.
Qca6574 Firmware
Patch available
MEDIUM 6.8
CVE-2023-24047
An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of w…
Ac21000 G6 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-24051
A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style…
Ac21000 G6 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-24052
An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as i…
Ac21000 G6 Firmware
Mitigation only
HIGH 7.5
CVE-2023-49947
Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.
Forgejo
1.20.5-1+
MEDIUM 5.5
CVE-2023-42006
IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority …
I
Mitigation only
HIGH 7.5
CVE-2023-5995
An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all…
GitLab
16.4.3 / 16.5.3+
HIGH 7.5
CVE-2023-47827
Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This …
Events Addon For Elementor
2.1.4+
HIGH 8.8
CVE-2023-40610
Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database conn…
Superset
2.1.2+
HIGH 8.8
CVE-2023-48712
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. In affected versions there is a privilege escalation vulnerability through a …
Warpgate
after 0.8.1
MEDIUM 6.8
CVE-2023-5553
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as S…
Axis Os
10.12.213 / 11.7.57+
MEDIUM 5.4
CVE-2023-5799
The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles t…
Wp Hotel Booking
2.0.8+
MEDIUM 5.3
CVE-2023-48309
NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization a…
Next Auth
4.24.5+
MEDIUM 5.4
CVE-2023-5509
The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions.
Mystickymenu
2.6.5+
MEDIUM 5.3
CVE-2023-48218
The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.4, users were able to bypass …
Protected Populate
1.3.4+
MEDIUM 5.3
CVE-2023-3379
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non…
Compact Controller 100 Firmware
22+
HIGH 7.2
CVE-2023-45626
An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code executio…
Arubaos
8.6.0.23 / 8.10.0.9+
HIGH 7.1
CVE-2022-40681
A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to caus…
Forticlient
after 7.0.7
HIGH 8.0
CVE-2023-31403
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any…
Business One
Mitigation only
HIGH 7.5
CVE-2023-4379
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. …
GitLab
16.2.8 / 16.3.5+
HIGH 8.8
CVE-2023-46244
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a use…
Xwiki
14.10.7 / 15.2+
MEDIUM 5.3
CVE-2023-42553
Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.
Email
6.1.90.4+
MEDIUM 5.3
CVE-2023-42541
Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.
Push Service
3.4.10+
CRITICAL 9.9
CVE-2023-20048EPSS 16%
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to ex…
Secure Firewall Management Center
after 7.3.1.1
HIGH 7.5
CVE-2023-46992
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without au…
A3300r Firmware
No fix yet
CRITICAL 9.8
CVE-2023-22518 KEVEPSS 100%
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an…
Confluence Data Center
7.19.16 / 8.3.4+
HIGH 7.5
CVE-2023-45899
An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication …
Superuser
2.4.2+