Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-4523
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized access of data due to a missing …
Idonate
2.1.10+
MEDIUM 6.5
CVE-2025-54586
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commi…
Gitproxy
1.19.2+
HIGH 8.1
CVE-2025-45620
An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request
Ptc310uv2 Firmware
No fix yet
MEDIUM 5.3
CVE-2025-43018
Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book.
W1a75a Firmware
002.2508a+
MEDIUM 5.3
CVE-2025-54425
Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the content delivery API can be restri…
Umbraco Cms
13.9.3 / 15.4.4+
MEDIUM 6.0
CVE-2025-4426
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" w…
No fix yet
MEDIUM 5.5
CVE-2025-43246
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to access sensitive…
macOS
14.7.7 / 15.6+
MEDIUM 5.5
CVE-2025-43215
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may result in disclos…
macOS
15.6+
CRITICAL 9.8
CVE-2025-31279
A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS …
Ipados
13.7.7 / 14.7.7+
CRITICAL 9.8
CVE-2025-43189
This issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able t…
macOS
14.7.7 / 15.6+
CRITICAL 9.8
CVE-2025-50738
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing su…
Memos
after 0.24.3
CRITICAL 9.8
CVE-2025-8226
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sy…
Chancms
3.1.3+
MEDIUM 6.5
CVE-2025-54380
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would inco…
Opencast
17.6+
CRITICAL 9.4
CVE-2025-29628
A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobil…
Mitigation only
CRITICAL 9.1
CVE-2025-29629
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default crede…
Mitigation only
MEDIUM 6.5
CVE-2025-3508
Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauthenticated users to view sensi…
W3z72e Firmware
Mitigation only
HIGH 8.7
CVE-2020-36850
An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one u…
Mitigation only
MEDIUM 6.5
CVE-2025-31955
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the s…
Dryice Iautomate
No fix yet
MEDIUM 6.5
CVE-2025-7780
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeA…
Mitigation only
HIGH 8.1
CVE-2025-8039
In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Fir…
Firefox
140.1 / 141.0+
MEDIUM 5.3
CVE-2025-6082
The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to in…
Mitigation only
MEDIUM 5.1
CVE-2025-52372
An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss…
Hmailserver
No fix yet
MEDIUM 6.5
CVE-2025-7919
WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitra…
Mitigation only
MEDIUM 5.3
CVE-2025-46382
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
No fix yet
CRITICAL 9.1
CVE-2025-7874
A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue is some unknown function…
Metacrm
after 6.4.2
CRITICAL 9.8
CVE-2025-7394
In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable…
Wolfssl
after 5.8.0
HIGH 7.5
CVE-2025-50708
An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chat URL
Mitigation only
HIGH 8.7
CVE-2025-34130
An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin…
Mitigation only
MEDIUM 6.1
CVE-2025-22227
In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must hav…
Mitigation only
MEDIUM 5.3
CVE-2025-30758
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface). Supported versions that are affected are 25.0-25.…
Siebel Crm Deployment
after 25.5