Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.7
CVE-2025-61679
Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained access to localhost, even wi…
Patch available
CRITICAL 9.8
CVE-2025-9209
The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due t…
Mitigation only
MEDIUM 5.9
CVE-2025-61589
Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows embedding images which then g…
Cursor
1.7+
HIGH 7.5
CVE-2025-61665
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability,…
Wegia
3.5.0+
HIGH 7.5
CVE-2025-59405
The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers …
Flock Safety
No fix yet
HIGH 7.5
CVE-2025-56161
YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the rela…
Firefly Mall
No fix yet
MEDIUM 5.3
CVE-2025-54290
Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence wi…
Lxd
5.21.4 / 6.5+
MEDIUM 5.4
CVE-2025-40646
Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by interceptin…
Energy Crm
Mitigation only
HIGH 8.7
CVE-2025-40645
Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensitive information about customer…
Mitigation only
MEDIUM 5.9
CVE-2025-10744
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and…
Mitigation only
MEDIUM 5.3
CVE-2025-34220
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments…
Virtual Appliance Application
25.1.102 / 25.1.1413+
HIGH 8.8
CVE-2025-8868EPSS 23%
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restrict…
Automate
4.13.295+
CRITICAL 9.8
CVE-2025-11079
A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation r…
Farm Management System
Mitigation only
HIGH 7.5
CVE-2025-45994
An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /use…
Passrecovery
No fix yet
HIGH 7.5
CVE-2025-11028
A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image Handler. Performing manipulati…
Vvveb
after 1.0.7.2
MEDIUM 6.8
CVE-2025-56463
Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.
Mw305r Firmware
after 3.30
HIGH 7.5
CVE-2025-11026
A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality of the component Configurati…
Vvveb
after 1.0.7.2
MEDIUM 5.3
CVE-2025-10952
A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream…
Mitigation only
HIGH 7.5
CVE-2025-36601
Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An un…
Powerscale Onefs
9.5.1.4 / 9.7.1.10+
HIGH 7.5
CVE-2025-59833
Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hin…
Flagforge
2.3+
MEDIUM 6.5
CVE-2025-59535
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary them…
Dotnetnuke
10.1.0+
CRITICAL 9.6
CVE-2025-59434
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated …
Mitigation only
CRITICAL 9.8
CVE-2025-57437
The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected…
Web Presenter Hd Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-57441
The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Up…
Atem Mini Pro Firmware
Mitigation only
HIGH 7.5
CVE-2025-57430
Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns int…
Creabox Manager
No fix yet
MEDIUM 6.5
CVE-2025-57433
The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a specific endpo…
Ip 4c Firmware
No fix yet
HIGH 8.8
CVE-2023-49367
An issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent packages by…
Mitigation only
MEDIUM 5.3
CVE-2024-25011
Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remed…
Mitigation only
MEDIUM 6.5
CVE-2025-10607
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi…
I Educar
after 2.10.0
HIGH 7.5
CVE-2025-34185
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote atta…
Eve X1 Server Firmware
after 4.7.18.0