Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-59214
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a networ…
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 5.5
CVE-2025-59209
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information lo…
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 5.5
CVE-2025-59211
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information lo…
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 5.5
CVE-2025-59186
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
Windows Server 2016
10.0.17763.7919 / 10.0.20348.4294+
MEDIUM 5.5
CVE-2025-59188
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.
Windows Server 2012
10.0.14393.8519 / 10.0.17763.7919+
MEDIUM 6.5
CVE-2025-58739
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a networ…
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 5.5
CVE-2025-59184
Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose informatio…
Windows Server 2016
10.0.17763.7919 / 10.0.20348.4294+
MEDIUM 5.5
CVE-2025-55699
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 5.5
CVE-2025-55683
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
Windows Server 2016
10.0.14393.8519 / 10.0.17763.7919+
MEDIUM 5.5
CVE-2025-55336
Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose inform…
Windows 10 1809
10.0.17763.7919 / 10.0.19044.6456+
MEDIUM 6.5
CVE-2025-59921
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, ve…
Fortiadc
7.1.5 / 7.2.4+
CRITICAL 9.1
CVE-2025-11717
When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the las…
Firefox
144.0+
CRITICAL 9.8
CVE-2025-11710
A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the comprom…
Firefox
115.29.0 / 140.4.0+
HIGH 7.5
CVE-2025-61688
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensitive information via an API.
Omni
1.0.2 / 1.1.5+
HIGH 8.7
CVE-2025-8915
Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-in-the-middle attack via the n…
Mitigation only
MEDIUM 6.8
CVE-2025-11647
A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component GATT Service. This manipulatio…
Furbo Mini Firmware
after 074
MEDIUM 5.5
CVE-2025-11639
A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the file collect_logs.sh of the co…
Furbo Mini Firmware
after 074
MEDIUM 5.3
CVE-2025-8484
The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 through publicly exposed log files.…
Mitigation only
MEDIUM 5.3
CVE-2025-9196
The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure…
Mitigation only
MEDIUM 5.5
CVE-2025-58278
Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2025-58277
Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.
Harmonyos
No fix yet
MEDIUM 5.3
CVE-2025-62158
Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments upl…
Learning
Patch available
MEDIUM 5.3
CVE-2025-61780
Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in …
Rack
2.2.20 / 3.1.18+
MEDIUM 6.1
CVE-2025-8887
Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in …
Mitigation only
MEDIUM 6.7
CVE-2025-8886
Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect A…
Mitigation only
HIGH 7.5
CVE-2025-52634
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.
Aion
No fix yet
HIGH 7.5
CVE-2025-52630
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
Aion
No fix yet
MEDIUM 5.9
CVE-2025-11443
A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/password/email of the component Forg…
Opnform
after 1.9.3
CRITICAL 9.1
CVE-2025-61777
Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/a…
Flagforge
2.3.2+
MEDIUM 6.5
CVE-2025-58589
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other inter…
Baggage Analytics
Mitigation only