Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.0
CVE-2025-59469
This vulnerability allows a Backup or Tape Operator to write files as root.
Veeam Backup \& Replication
13.0.1.1071+
MEDIUM 5.3
CVE-2026-21880
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP aut…
Kanboard
1.2.49+
MEDIUM 5.3
CVE-2026-20027
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to…
Mitigation only
MEDIUM 5.5
CVE-2025-47369
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Ar8035 Firmware
Patch available
HIGH 8.6
CVE-2025-13371
The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.9. This is due to the …
Mitigation only
MEDIUM 5.3
CVE-2025-13215
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.…
Mitigation only
MEDIUM 5.3
CVE-2025-69226
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existen…
Aiohttp
3.13.3+
MEDIUM 6.5
CVE-2025-68436
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Cr…
Craft Cms
4.16.17 / 5.8.21+
MEDIUM 6.5
CVE-2025-67732
Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-admin…
Dify
1.11.0+
MEDIUM 5.3
CVE-2025-68273
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions pri…
Signal K Server
2.19.0+
HIGH 7.5
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earl…
Uri
0.12.5 / 0.13.3+
CRITICAL 9.8
CVE-2025-15103
DVP-12SE11T - Authentication Bypass via Partial Password Disclosure
Dvp 12se11t Firmware
2.16+
MEDIUM 5.3
CVE-2025-14280
The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.1.5 through publicly …
Mitigation only
MEDIUM 6.5
CVE-2025-15070
Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse.
Thi…
Web Fax
4.0+
MEDIUM 6.3
CVE-2025-15065
Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties…
Mitigation only
MEDIUM 5.5
CVE-2024-29720
An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the S…
Sciter
No fix yet
HIGH 7.5
CVE-2025-15082
A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Managemen…
Zlt M30s Firmware
after 1.47
HIGH 7.5
CVE-2025-12491
Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio…
Mitigation only
HIGH 7.5
CVE-2025-63662
Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive informatio…
Gt Edge Ai
2.0.12+
MEDIUM 6.5
CVE-2025-15033
A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configurat…
Mitigation only
MEDIUM 6.5
CVE-2025-8305
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being prin…
Mitigation only
MEDIUM 6.5
CVE-2025-8304
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being acce…
Mitigation only
MEDIUM 5.3
CVE-2025-12492
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…
Mitigation only
HIGH 7.5
CVE-2025-14591
In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EO…
Delphix Continuous Compliance
after 2025.6.0.0
MEDIUM 6.5
CVE-2025-68279
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using craf…
Weblate
5.15.1+
MEDIUM 5.3
CVE-2025-68429
Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 an…
Storybook
7.6.21 / 8.6.15+
HIGH 8.8
CVE-2025-68110
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the hos…
Churchcrm
6.5.3+
MEDIUM 5.5
CVE-2025-46278
The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data.
macOS
26.2+
MEDIUM 5.5
CVE-2025-46283
A logic issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access sens…
macOS
26.2+
MEDIUM 5.5
CVE-2025-43514
The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data.
macOS
26.2+