Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2023-28911
A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied dat…
Mitigation only
HIGH 8.7
CVE-2025-34047
A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attackers to read arbitrary files o…
Mitigation only
CRITICAL 10.0
CVE-2025-34043EPSS 8%
A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.c…
Mitigation only
HIGH 7.5
CVE-2025-6709
The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC…
MongoDB
6.0.21 / 7.0.17+
MEDIUM 6.5
CVE-2025-6703
Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2.
Neqo
after 0.13.2
MEDIUM 5.9
CVE-2025-6444
ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This vulnerability allows remote attackers to relay NTLM credential…
Servicestack
8.6+
HIGH 7.5
CVE-2025-52894
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao befo…
Openbao
2.3.0+
MEDIUM 6.6
CVE-2025-52569
GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-prov…
Patch available
MEDIUM 6.6
CVE-2025-50178
GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for user provided values in certa…
Patch available
HIGH 8.8
CVE-2025-52568
NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory cor…
Patch available
CRITICAL 9.1
CVE-2025-6545
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program fil…
Patch available
CRITICAL 9.1
CVE-2025-6547
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2.
Patch available
HIGH 7.8
CVE-2025-34021
A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, T…
No fix yet
HIGH 8.0
CVE-2025-6279
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the f…
Upsonic
after 0.55.6
HIGH 7.1
CVE-2025-29646
An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest pac…
Open5gs
after 2.7.2
MEDIUM 6.7
CVE-2024-55567
Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and …
Insydeh2o
5.4.05.47.01 / 5.5.05.55.01+
HIGH 8.8
CVE-2025-4613
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b…
Web Designer
16.3.0.0407+
CRITICAL 9.5
CVE-2024-1244
Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or in p…
Mitigation only
HIGH 7.2
CVE-2024-1243
Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key to…
Wazuh
4.8.0+
HIGH 8.7
CVE-2025-0051
Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service.
Mitigation only
HIGH 8.3
CVE-2025-0052
Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service.
Mitigation only
HIGH 7.8
CVE-2025-47968
Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Autoupdate
4.79+
MEDIUM 6.7
CVE-2025-47171
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
365 Apps
Mitigation only
MEDIUM 6.5
CVE-2025-3898
CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an
authenticated malicious user sends HTTPS request co…
Mitigation only
HIGH 8.6
CVE-2025-4680
Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorrectly Configured Access Contr…
Mitigation only
MEDIUM 6.5
CVE-2025-3116
CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an
authenticated malicious user sends special malforme…
No fix yet
CRITICAL 9.8
CVE-2025-1041
An improper input validation discovered in
Avaya Call Management System
could allow an unauthorized
remote command via a specially crafted web re…
Call Management System
19.2.0.7 / 20.0.1.0+
MEDIUM 6.6
CVE-2025-0037
In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to i…
No fix yet
MEDIUM 5.5
CVE-2025-27131
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
Openharmony
after 5.0.3
MEDIUM 5.5
CVE-2025-27242
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
Openharmony
after 5.0.3