Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-66225
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the u…
Orangehrm
5.8+
HIGH 8.8
CVE-2025-53939
Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to une…
Kiteworks
9.1.0+
HIGH 8.1
CVE-2025-66201
LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by …
Librechat
0.8.1+
HIGH 8.7
CVE-2025-0658
A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol
causes the device to crash. The device enters a fault state; aft…
Mitigation only
CRITICAL 9.8
CVE-2025-66259
Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions …
Mozart Next 100 Firmware
Mitigation only
MEDIUM 5.5
CVE-2025-33191
NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this…
Dgx Os
Mitigation only
HIGH 8.1
CVE-2025-0248
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, una…
Mitigation only
HIGH 7.7
CVE-2025-12740
A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a ma…
Mitigation only
HIGH 7.7
CVE-2025-12741
A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malic…
Mitigation only
MEDIUM 5.4
CVE-2025-12889
With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.
Wolfssl
Patch available
HIGH 8.1
CVE-2025-65946
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possibl…
Roo Code
3.26.7+
MEDIUM 6.5
CVE-2025-11933
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated att…
Wolfssl
5.8.4+
MEDIUM 5.3
CVE-2025-11936
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to ca…
Wolfssl
5.8.4+
HIGH 8.8
CVE-2025-62164
vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability co…
Vllm
0.11.1+
HIGH 7.1
CVE-2025-11676
Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated adjacent attackers to perfor…
Mitigation only
CRITICAL 9.8
CVE-2025-63213
The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the…
Opera11 Firmware
Mitigation only
MEDIUM 6.1
CVE-2025-64759
Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a use…
Homarr
1.43.3+
MEDIUM 5.3
CVE-2025-12842
The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and inc…
Mitigation only
CRITICAL 9.8
CVE-2025-55058
CWE-20 Improper Input Validation
Rumpus
No fix yet
HIGH 8.8
CVE-2025-13319
An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL v…
Mitigation only
CRITICAL 9.4
CVE-2025-10460
A SQL Injection vulnerability on an endpoint in BEIMS Contractor Web, a legacy product that is no longer maintained or patched by the vendor, allows …
Mitigation only
MEDIUM 5.5
CVE-2025-64747
Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions…
Directus
11.13.0+
MEDIUM 5.3
CVE-2024-45301
Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to ac…
Mitigation only
HIGH 7.5
CVE-2024-47866
Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put…
Ceph
after 19.2.3
HIGH 8.8
CVE-2025-62222
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz…
Github Copilot Chat
0.32.5+
HIGH 8.8
CVE-2025-33000
Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of priv…
Quickassist Technology
2.6.0-0018+
MEDIUM 5.6
CVE-2025-24512
Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a…
Mitigation only
HIGH 8.8
CVE-2025-24299
Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation …
Computing Improvement Program
2.4.11001+
HIGH 7.5
CVE-2025-12942
Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform …
R6260 Firmware
1.1.0.86+
HIGH 8.8
CVE-2025-12944
Improper input validation
in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with
direct network access to the device to poten…
Dgn2200 Firmware
1.0.0.132+