Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-6984
The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML…
Mitigation only
HIGH 7.5
CVE-2025-36895
Information disclosure
Android
No fix yet
HIGH 7.5
CVE-2025-20336
A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could a…
Desk Phone 9841 Firmware
3.3 / 14.3+
MEDIUM 6.5
CVE-2025-20270
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow…
Evolved Programmable Network Manager
8.0.1 / 8.1.2+
HIGH 7.5
CVE-2025-53694EPSS 6%
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (…
Experience Commerce
10.4+
HIGH 7.5
CVE-2025-9843
A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This mani…
Parking Management System
Mitigation only
HIGH 7.5
CVE-2025-9842
A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. Th…
Parking Management System
Mitigation only
MEDIUM 5.5
CVE-2025-22430
In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This could lead…
Android
Mitigation only
MEDIUM 5.5
CVE-2025-58061
OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, p…
Mitigation only
CRITICAL 9.1
CVE-2025-58059
Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to before 13.1.2.RELEASE, any admi…
Patch available
MEDIUM 5.3
CVE-2025-57756
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered …
Contao
4.13.56 / 5.3.38+
MEDIUM 5.3
CVE-2025-57757
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their n…
Contao
5.3.38 / 5.6.1+
HIGH 7.5
CVE-2024-13807
The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.0.5 via the backup funct…
Mitigation only
MEDIUM 5.5
CVE-2025-20290
A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone N…
Mitigation only
CRITICAL 9.1
CVE-2024-39335
Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administra…
Mahara
23.04.6 / 24.04.1+
HIGH 7.5
CVE-2025-29992
Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily…
Mahara
24.04.9+
HIGH 7.5
CVE-2025-9461
A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePacka…
Bbs
after 6.8
HIGH 7.5
CVE-2023-47799
Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration inter…
Mahara
22.10.4 / 23.04.4+
CRITICAL 9.3
CVE-2025-7426
Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated…
Mitigation only
HIGH 7.5
CVE-2025-9398
A security vulnerability has been detected in YiFang CMS up to 2.0.5. Affected by this vulnerability is the function exportInstallTable of the file a…
Yifang
after 2.0.5
HIGH 8.1
CVE-2025-57755
claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper Cross-Origin Resou…
Mitigation only
MEDIUM 6.5
CVE-2025-9139
A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plain…
Scada Lts
No fix yet
HIGH 8.8
CVE-2025-7654
Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated…
Mitigation only
MEDIUM 5.3
CVE-2025-54118
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allo…
Nameless
2.2.4+
MEDIUM 5.3
CVE-2024-12575
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, a…
Mitigation only
MEDIUM 6.2
CVE-2025-43201
This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may be able to unexpectedly leak …
Music Classical
2.3+
MEDIUM 5.7
CVE-2025-26709
There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker ca…
Mitigation only
MEDIUM 5.9
CVE-2025-50862
The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data exfiltration via ADB backup on…
Mitigation only
CRITICAL 9.8
CVE-2025-27845
In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This al…
Mitigation only
HIGH 8.5
CVE-2025-9036
A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a Web…
Mitigation only