Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-10535
Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143.
Firefox
143.0+
MEDIUM 6.2
CVE-2025-10536
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thund…
Firefox
140.3.0 / 143.0+
MEDIUM 5.7
CVE-2025-26711
There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker …
Mitigation only
MEDIUM 5.3
CVE-2025-9808
The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint…
Mitigation only
CRITICAL 9.8
CVE-2025-43362
The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may be able to monitor ke…
Ipados
18.7+
MEDIUM 5.5
CVE-2025-43367
A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protec…
macOS
14.8 / 26.0+
MEDIUM 6.5
CVE-2025-43356
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tah…
Safari
18.7 / 26.0+
MEDIUM 5.3
CVE-2025-10321
A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead t…
Wl Wn578w2 Firmware
No fix yet
MEDIUM 6.5
CVE-2025-56467
An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as acc…
Mitigation only
HIGH 7.5
CVE-2025-54376
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by…
Hoverfly
1.12.0+
HIGH 8.4
CVE-2025-55976
Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can d…
Iwr 3000n Firmware
after 1.9.8
HIGH 7.5
CVE-2025-56406
An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE…
Mitigation only
HIGH 8.7
CVE-2025-36759
Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addre…
Mitigation only
HIGH 7.5
CVE-2025-29089
An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information
Mitigation only
HIGH 7.5
CVE-2025-55243
Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a networ…
Officeplus
3.10.0.26585+
MEDIUM 5.5
CVE-2025-53804
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
MEDIUM 5.3
CVE-2025-47997
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose i…
Sql Server 2016
13.0.6470.1 / 13.0.7065.1+
MEDIUM 6.7
CVE-2025-33045
APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to …
Aptio V
5.040+
MEDIUM 6.5
CVE-2025-59018
Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑1…
TYPO3
9.5.55 / 10.4.54+
MEDIUM 5.3
CVE-2025-40757
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BA…
Mitigation only
MEDIUM 5.3
CVE-2025-58751
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the pu…
Vite
5.4.20 / 6.3.6+
MEDIUM 5.3
CVE-2025-58752
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served reg…
Vite
5.4.20 / 6.3.6+
CRITICAL 9.8
CVE-2025-22956
OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if an…
Mitigation only
HIGH 7.5
CVE-2025-10093
A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php…
Dir 852 Firmware
No fix yet
HIGH 7.5
CVE-2025-58445
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose de…
Atlantis
after 0.35.1
MEDIUM 5.3
CVE-2025-7368
The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information Exposure in all versions up t…
Mitigation only
HIGH 7.5
CVE-2025-55242
Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.
Xbox Gaming Services
No fix yet
CRITICAL 9.9
CVE-2025-55190EPSS 5%
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.…
Argo Cd
2.13.9 / 2.14.16+
MEDIUM 6.2
CVE-2025-48527
In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead to local i…
Android
Patch available
MEDIUM 5.5
CVE-2025-26453
In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. This could l…
Android
Patch available