Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-36710
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page ma…
Wps Hide Login
after 1.5.4.2
HIGH 7.5
CVE-2023-33651
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release…
Experience Commerce
after 10.3
MEDIUM 5.4
CVE-2023-32683
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_ur…
Synapse
1.85.0+
MEDIUM 6.5
CVE-2023-22833
Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Found…
Foundry
after 2.531.0
HIGH 7.8
CVE-2023-21670
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
315 5g Iot Modem Firmware
Patch available
HIGH 7.8
CVE-2022-40529
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
Aqt1000 Firmware
Mitigation only
HIGH 7.8
CVE-2023-3027
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value…
Advanced Cluster Management For Kubernetes
Mitigation only
HIGH 8.1
CVE-2023-3066
Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including admi…
Amxgt 100
after 1.3.20
HIGH 8.8
CVE-2023-25729
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them wi…
Firefox
102.8 / 110.0+
MEDIUM 6.5
CVE-2023-23604
A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have l…
Firefox
109.0+
HIGH 8.8
CVE-2023-3033
Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Secur…
Mobatime Web Application
after 06.7.22
CRITICAL 9.8
CVE-2023-28698
Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can exploit this vulnerability by …
Fantsy
Mitigation only
HIGH 8.8
CVE-2022-46307
SGUDA U-Lock central lock control service’s lock management function has incorrect authorization. A remote attacker with general privilege can exploi…
U Lock Firmware
Mitigation only
HIGH 8.8
CVE-2022-46308
SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can e…
U Lock Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-34218
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
Teamcity
2023.05+
HIGH 7.4
CVE-2023-28352
An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled arti…
Insight
No fix yet
HIGH 8.8
CVE-2023-33779
A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POS…
Xxl Job
Mitigation only
HIGH 7.5
CVE-2023-31226
The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vulnerability may affect confide…
Emui
No fix yet
MEDIUM 6.8
CVE-2023-2002
A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This f…
Linux Kernel
6.4+
HIGH 7.5
CVE-2023-31726
AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.
Alist
No fix yet
HIGH 7.5
CVE-2023-23299
The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malic…
Connect Iq
after 4.1.7
CRITICAL 9.1
CVE-2023-23304
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.Sensor…
Connect Iq
after 4.1.7
HIGH 8.8
CVE-2023-25946
Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent attacker to analyze the product…
Q Sl2 Firmware
after 2.0.9
CRITICAL 9.8
CVE-2023-27388
Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login t…
Tr 71w Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-33254
There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a high…
Kace Systems Deployment Appliance
No fix yet
MEDIUM 5.5
CVE-2023-26818
Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.
Telegram
No fix yet
MEDIUM 6.5
CVE-2023-31597
An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. At…
Zammad
5.4.1+
MEDIUM 5.5
CVE-2023-2782
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build …
Cyber Infrastructure
5.3.1-38+
MEDIUM 6.7
CVE-2023-21116
In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logi…
Android
Patch available
HIGH 7.8
CVE-2023-21117
In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to…
Android
Patch available