Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2025-55521
An issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial of Service (DoS) via a crafted…
Akaunting
after 3.1.19
MEDIUM 6.5
CVE-2025-55522
Cross-site scripting (XSS) vulnerability in the component /common/reports of Akaunting v3.1.18 allows attackers to execute arbitrary web scripts or H…
Akaunting
after 3.1.19
CRITICAL 9.8
CVE-2024-22836EPSS 30%
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to…
Akaunting
3.1.4+
MEDIUM 5.4
CVE-2020-20908
Akaunting v1.3.17 was discovered to contain a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts…
Akaunting
after 1.3.17
HIGH 8.1
CVE-2021-36801
Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed i…
Akaunting
after 2.1.12
HIGH 8.1
CVE-2021-36804
Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests thro…
Akaunting
2.1.13+
MEDIUM 6.5
CVE-2021-36802
Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'locale' variable and sending it…
Akaunting
after 2.1.12
MEDIUM 5.4
CVE-2021-36803
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar …
Akaunting
2.1.13+
CRITICAL 9.1
CVE-2021-36800
Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/…
Akaunting
2.1.13+
HIGH 8.8
CVE-2020-22390
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name paramete…
Akaunting
after 2.0.9