Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2025-40746
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a ba…
Simatic Rtls Locating Manager
3.2+
MEDIUM 5.5
CVE-2025-25212
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input.
Openharmony
after 5.0.3
HIGH 8.8
CVE-2025-55006
Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not a…
Learning
2.34.0+
CRITICAL 9.8
CVE-2025-48913
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…
Cxf
3.6.8 / 4.0.9+
HIGH 7.5
CVE-2025-8708
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeMan…
White Jotter
No fix yet
MEDIUM 6.8
CVE-2025-54368
uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, …
Patch available
MEDIUM 6.6
CVE-2025-44779
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.
Ollama
Mitigation only
HIGH 8.8
CVE-2025-54785
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplie…
Suitecrm
Mitigation only
MEDIUM 6.5
CVE-2025-50233
A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name"…
Qcms
No fix yet
HIGH 7.5
CVE-2025-21477
Transient DOS while processing CCCH data when NW sends data with invalid length.
315 5g Iot Modem Firmware
Mitigation only
MEDIUM 5.5
CVE-2025-54642
Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module.
Impact: Successful exploitation of this vulnerabili…
Emui
Mitigation only
MEDIUM 5.5
CVE-2025-54641
Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module.
Impact: Successful exploitation of this vulnerab…
Emui
No fix yet
MEDIUM 5.5
CVE-2025-54636
Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module.
Impact: Successful exploitation of this vulner…
Emui
No fix yet
MEDIUM 5.5
CVE-2025-54614
Input verification vulnerability in the home screen module.
Impact: Successful exploitation of this vulnerability may affect availability.
Harmonyos
No fix yet
HIGH 7.1
CVE-2025-7674
Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denia…
Mitigation only
HIGH 7.5
CVE-2025-27211
An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with access to E…
Mitigation only
CRITICAL 9.8
CVE-2025-27212
An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access managem…
Mitigation only
MEDIUM 5.3
CVE-2024-52279
Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input.
…
Zeppelin
0.12.0+
HIGH 7.8
CVE-2025-54564
uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the no…
Mitigation only
HIGH 8.6
CVE-2011-10008
A stack-based buffer overflow vulnerability exists in MPlayer Lite r33064 due to improper bounds checking when handling M3U playlist files containing…
No fix yet
MEDIUM 6.5
CVE-2025-30480
Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerProtect Data Manager. A low pr…
Powerprotect Data Manager
19.20+
CRITICAL 9.8
CVE-2025-50578
LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Refer…
Docker Heimdall
Mitigation only
MEDIUM 6.0
CVE-2025-4424
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" w…
No fix yet
CRITICAL 9.8
CVE-2025-43253
This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able …
macOS
14.7.7 / 15.6+
CRITICAL 9.8
CVE-2025-43234
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6,…
Ipados
2.6 / 11.6+
HIGH 7.5
CVE-2025-43223
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia…
Ipados
2.6 / 11.6+
MEDIUM 5.5
CVE-2025-43195
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15…
macOS
13.7.7 / 14.7.7+
CRITICAL 9.1
CVE-2025-31281
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6…
Ipados
2.6 / 15.6+
HIGH 7.5
CVE-2025-50492
Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a ses…
E Diary Management System
Mitigation only
HIGH 7.5
CVE-2025-50489
Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to exec…
Student Result Management System
No fix yet