Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2022-37326
Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by co…
Desktop
4.6.0+
HIGH 7.8
CVE-2023-26244
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is …
Gen5w L Firmware
No fix yet
HIGH 7.8
CVE-2023-26245
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is u…
Gen5w L Firmware
No fix yet
HIGH 7.8
CVE-2023-26246
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is u…
Gen5w L Firmware
No fix yet
HIGH 8.8
CVE-2023-27107
Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows use…
Central Server
8.2+
MEDIUM 6.5
CVE-2023-31250
The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files t…
Drupal
7.96 / 9.4.14+
MEDIUM 5.4
CVE-2022-25274
Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, r…
Drupal
9.3.12+
HIGH 7.8
CVE-2023-20871
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate …
Fusion
13.0.2+
MEDIUM 6.5
CVE-2023-24512
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to updat…
Eos
4.26.10m / 4.27.9m+
HIGH 7.5
CVE-2021-23203
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to do…
Odoo
Patch available
HIGH 7.8
CVE-2023-2257
Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker wit…
Workspace
2023.1.1.4+
MEDIUM 5.5
CVE-2023-26097
An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behaviour may not be blocked.
Apsal
No fix yet
HIGH 7.8
CVE-2023-20950
In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. …
Android
Patch available
HIGH 8.8
CVE-2023-25547
A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution
on upload and install packages when a hacker is using …
Struxureware Data Center Expert
after 7.9.2
MEDIUM 6.5
CVE-2023-25548
A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device
credentials on specific DCE endpoints not being properly se…
Struxureware Data Center Expert
after 7.9.2
CRITICAL 9.8
CVE-2023-30771
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd…
Iotdb Web Workbench
Mitigation only
HIGH 8.6
CVE-2020-17354
LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangero…
Lilypond
2.24.0+
HIGH 7.5
CVE-2023-22620
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an inva…
Unified Threat Management
12.2.5.1+
MEDIUM 6.8
CVE-2023-28270
Windows Lock Screen Security Feature Bypass Vulnerability
Windows 10 1809
10.0.17763.4252 / 10.0.19042.2846+
MEDIUM 6.8
CVE-2023-28249
Windows Boot Manager Security Feature Bypass Vulnerability
Windows 10 1507
10.0.10240.19869 / 10.0.14393.5850+
MEDIUM 5.3
CVE-2023-25415
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.
Pe8108 Firmware
No fix yet
HIGH 7.8
CVE-2022-40682
A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to exec…
Forticlient
7.0.8+
HIGH 8.1
CVE-2022-43770
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in …
Pentaho Business Analytics
8.3.0.27 / 9.2.0.4+
MEDIUM 5.3
CVE-2023-0319
An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all ve…
GitLab
15.8.5 / 15.9.4+
HIGH 8.8
CVE-2023-28634
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technic…
Glpi
9.5.13 / 10.0.7+
HIGH 8.8
CVE-2022-43940
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization chec…
Vantara Pentaho Business Analytics Server
9.3.0.2+
MEDIUM 6.5
CVE-2023-1202
Permission bypass when importing or synchronizing entries in User vault
in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows us…
Remote Desktop Manager
2023.1.10+
MEDIUM 6.5
CVE-2023-1603
Permission bypass when importing or synchronizing entries in User vault
in Devolutions Server 2022.3.13 and prior versions allows users with restri…
Devolutions Server
2023.1.3.0+
CRITICAL 9.8
CVE-2023-23594
An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unaut…
Cl4nx Plus Firmware
1.13.3-u724_r2+
CRITICAL 9.8
CVE-2023-26829
An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new …
Centrestack
13.5.9808+