Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2025-53887
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Dir…
Directus
11.9.0+
MEDIUM 6.5
CVE-2025-53640
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to…
Indico
3.3.7+
HIGH 7.5
CVE-2024-51769
An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
Autopass License Server
9.17+
MEDIUM 5.3
CVE-2025-7573
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000…
No fix yet
MEDIUM 5.3
CVE-2025-7572
A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. …
No fix yet
HIGH 7.5
CVE-2025-7565
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi…
Bl Ac3600 Firmware
after 1.0.22
HIGH 7.5
CVE-2020-36848
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in…
Total Upkeep
1.14.10+
MEDIUM 5.3
CVE-2025-6745
The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_que…
Mitigation only
MEDIUM 6.5
CVE-2025-4593
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6…
Mitigation only
HIGH 7.1
CVE-2025-34098
A path traversal vulnerability exists in Riverbed SteelHead VCX appliances (confirmed in VCX255U 9.6.0a) due to improper input validation in the log …
No fix yet
MEDIUM 5.5
CVE-2025-52473
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branche…
Liboqs
0.14.0+
CRITICAL 10.0
CVE-2025-53624
The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists ve…
Patch available
MEDIUM 6.5
CVE-2025-53512
The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contai…
Juju
2.9.52 / 3.6.8+
MEDIUM 6.5
CVE-2025-49671
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis…
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
MEDIUM 5.5
CVE-2025-49664
Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose infor…
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
MEDIUM 5.5
CVE-2025-48808
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
MEDIUM 6.2
CVE-2025-47980
Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information local…
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
MEDIUM 5.3
CVE-2025-20325
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.113, and 9.2.240…
Splunk
9.1.10 / 9.2.7+
CRITICAL 9.3
CVE-2025-34072
A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI…
Mitigation only
HIGH 7.5
CVE-2024-13451
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is v…
Bit Form
2.17.6+
HIGH 7.5
CVE-2025-49741
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Edge Chromium
135.0.3179.98+
CRITICAL 9.0
CVE-2025-34064
A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-productio…
Mitigation only
HIGH 8.7
CVE-2025-34059
An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/…
Mitigation only
MEDIUM 5.7
CVE-2025-34062
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attack…
Mitigation only
MEDIUM 6.9
CVE-2025-34051
A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?ac…
No fix yet
HIGH 8.2
CVE-2025-53003
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without s…
Patch available
HIGH 8.8
CVE-2025-52898
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor …
Frappe
14.94.3 / 15.58.0+
HIGH 7.5
CVE-2025-49845
Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers_allowed_groups` site setting…
Discourse
3.4.6+
HIGH 7.1
CVE-2025-27827
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthenticated attacker to conduct a…
Mitigation only
HIGH 8.6
CVE-2025-6432
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not…
Firefox
140.0+