Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-39204
A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returni…
Microscada X Sys600
10.7+
CRITICAL 9.8
CVE-2023-47029
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST reque…
Terminal Handler
Mitigation only
HIGH 7.4
CVE-2025-27387
OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.
Mitigation only
HIGH 8.6
CVE-2025-52488EPSS 33%
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN…
Dotnetnuke
10.0.1+
CRITICAL 9.3
CVE-2025-25037
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp…
No fix yet
CRITICAL 9.1
CVE-2025-52467
pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to commit 8eb3567, the pgai repos…
Patch available
HIGH 7.5
CVE-2025-23173
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the …
Mitigation only
MEDIUM 6.8
CVE-2025-49593
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…
Patch available
MEDIUM 6.1
CVE-2025-49177
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read u…
Mitigation only
HIGH 7.5
CVE-2025-49200
The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the …
Field Analytics
Mitigation only
HIGH 7.5
CVE-2025-49184
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the pro…
Baggage Analytics
Mitigation only
MEDIUM 5.9
CVE-2025-49150
Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enable was set to True. This mean…
Mitigation only
HIGH 8.1
CVE-2025-26521
When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of…
Cloudstack
4.19.3.0 / 4.20.1.0+
MEDIUM 5.5
CVE-2025-43579
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result …
Acrobat Dc
20.005.30774 / 24.001.30254+
MEDIUM 5.9
CVE-2025-49143
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROO…
Nautobot
1.6.32 / 2.4.10+
HIGH 8.2
CVE-2024-34711
GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables …
Geoserver
2.25.0+
HIGH 7.5
CVE-2024-38524
GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpSer…
Geoserver
2.25.6 / 2.26.2+
HIGH 7.5
CVE-2025-40662
Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigati…
Dm Corporative Cms
2025.01+
HIGH 8.0
CVE-2025-49653
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform.
Mitigation only
MEDIUM 5.7
CVE-2025-25209
The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the k…
Mitigation only
CRITICAL 9.8
CVE-2025-47966
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.
Power Automate For Desktop
No fix yet
MEDIUM 6.5
CVE-2025-5690
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the ori…
Mitigation only
MEDIUM 5.4
CVE-2025-20129
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenti…
Socialminer
Mitigation only
MEDIUM 5.3
CVE-2025-5436
A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic. This issue affects some unknown processing of the file…
Mitigation only
MEDIUM 5.3
CVE-2025-4659
The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclo…
No fix yet
MEDIUM 5.5
CVE-2025-31231
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read sensitive locat…
macOS
15.4+
HIGH 7.5
CVE-2025-5334
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager
allows an authen…
Remote Desktop Manager
2025.1.37.0 / 2025.2.0.0+
MEDIUM 5.4
CVE-2025-5281
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via …
Chrome
137.0.7151.55+
MEDIUM 5.4
CVE-2025-5064
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via …
Chrome
137.0.7151.55+
MEDIUM 5.1
CVE-2024-56193
There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no addi…
Android
Mitigation only