Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-23918
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Perm…
Node.js
14.21.3 / 16.19.1+
CRITICAL 9.8
CVE-2023-23064
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
A720r Firmware
No fix yet
CRITICAL 9.8
CVE-2021-32163
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.
Modular Open Smart Network
0.23.0+
HIGH 7.8
CVE-2023-24485
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix…
Workspace
2212+
HIGH 8.5
CVE-2023-23947
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2…
Argo Cd
2.3.17 / 2.4.23+
HIGH 7.8
CVE-2023-25173
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not …
Containerd
1.5.18 / 1.6.18+
HIGH 7.3
CVE-2023-21715 KEVEPSS 12%
Microsoft Publisher Security Feature Bypass Vulnerability
365 Apps
Patch available
MEDIUM 6.5
CVE-2023-0814
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_met…
Profile Builder
after 3.9.0
MEDIUM 5.7
CVE-2022-34397
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerabi…
Evasa Provider Virtual Appliance
9.2.3.6 / 9.2.3.22+
HIGH 8.1
CVE-2023-25559
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata…
Datahub
0.8.45+
MEDIUM 5.5
CVE-2023-21423
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission…
Android
Mitigation only
MEDIUM 5.5
CVE-2023-21422
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server w…
Android
Mitigation only
HIGH 8.8
CVE-2022-45544
Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the t…
Cms
No fix yet
HIGH 7.8
CVE-2023-23696
Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious user…
Command \| Intel Vpro Out Of Band
4.4.0+
HIGH 7.2
CVE-2023-24029
In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to ins…
Ws Ftp Server
8.8+
CRITICAL 9.8
CVE-2022-47002EPSS 6%
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.
Masacms
7.2.5 / 7.3.10+
CRITICAL 9.8
CVE-2023-23924
Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letter…
Dompdf
Patch available
CRITICAL 9.8
CVE-2022-45172
An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endp…
Vdesk
018+
HIGH 7.5
CVE-2023-22610
A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of
Service against the Geo SCADA server when specific messages are se…
Ecostruxure Geo Scada Expert 2019
Patch available
MEDIUM 6.5
CVE-2022-45435
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…
Identityiq
8.0+
HIGH 8.8
CVE-2023-24829
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 bef…
Iotdb
0.13.3+
HIGH 8.8
CVE-2023-22482
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6…
Argo Cd
2.3.14 / 2.4.20+
HIGH 7.5
CVE-2023-22500
GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Authorization. This v…
Glpi
10.0.6+
MEDIUM 6.5
CVE-2023-21719
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Edge Chromium
109.0.1518.70+
MEDIUM 6.5
CVE-2023-20018
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker t…
Ip Phone 7800 Firmware
14.1+
CRITICAL 9.8
CVE-2022-23739
An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests fr…
Enterprise Server
3.3.16 / 3.4.11+
HIGH 8.1
CVE-2022-45353
Broken Access Control in Betheme theme <= 26.6.1 on WordPress.
Betheme
after 26.6.1
MEDIUM 6.5
CVE-2023-0298
Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
Firefly Iii
5.8.0+
CRITICAL 9.8
CVE-2023-22480EPSS 67%
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In Kube…
Kubeoperator
3.16.4+
HIGH 7.1
CVE-2022-2155
A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature
due to a flaw in access control mechanism implementation on …
Lumada Asset Performance Management
6.4.0.1+