Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-24246
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An a…
macOS
13.7.5 / 14.7.5+
CRITICAL 9.8
CVE-2025-24232
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A m…
macOS
13.7.5 / 14.7.5+
MEDIUM 5.5
CVE-2025-24217
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS …
Ipados
15.4 / 18.4+
MEDIUM 5.5
CVE-2025-24226
The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.
Xcode
16.3+
CRITICAL 9.8
CVE-2025-24204
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
macOS
15.4+
MEDIUM 5.5
CVE-2025-24164
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be…
macOS
13.7.5 / 14.7.5+
MEDIUM 5.3
CVE-2025-31124
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps …
Zitadel
2.63.9 / 2.64.6+
HIGH 7.5
CVE-2025-31125 KEVEPSS 59%
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explici…
Vite
4.5.11 / 5.4.16+
MEDIUM 5.3
CVE-2025-2840
The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.…
Mitigation only
MEDIUM 5.3
CVE-2025-2860
SaTECH BCU in its firmware version 2.1.3, allows an authenticated attacker to access information about the credentials that users have within the web…
Satech Bcu Firmware
Mitigation only
MEDIUM 5.3
CVE-2021-24008
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and b…
Fortimail
5.4.3 / 6.0.4+
MEDIUM 5.3
CVE-2025-2578
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and…
Mitigation only
MEDIUM 6.5
CVE-2025-29497
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.
Libming
No fix yet
MEDIUM 6.5
CVE-2025-29488
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.
Libming
No fix yet
MEDIUM 6.5
CVE-2025-29489
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.
Libming
No fix yet
MEDIUM 6.5
CVE-2025-29486
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.
Libming
No fix yet
MEDIUM 5.7
CVE-2025-20232
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.23…
Splunk
9.1.8 / 9.1.2308.212+
MEDIUM 5.7
CVE-2025-20226
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.111, and 9.1.2308.…
Splunk
9.1.8 / 9.1.2308.214+
HIGH 7.5
CVE-2025-26009
Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.
Tlr 2005ksh Firmware
Mitigation only
HIGH 7.5
CVE-2025-26001
Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.
Tlr 2005ksh Firmware
Mitigation only
MEDIUM 5.3
CVE-2025-30352
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `…
Directus
11.5.0+
HIGH 7.5
CVE-2025-30353
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow …
Directus
11.5.0+
MEDIUM 5.5
CVE-2025-23203
Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4…
Patch available
MEDIUM 5.7
CVE-2025-2228
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Sensitive Informatio…
Responsive Addons For Elementor
1.6.9+
HIGH 7.5
CVE-2025-30214
Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure…
Frappe
14.89.0 / 15.51.0+
MEDIUM 5.3
CVE-2025-2252
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in a…
Easy Digital Downloads
3.3.7+
HIGH 7.5
CVE-2025-30208EPSS 75%
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies acc…
Vite
4.5.10 / 5.4.15+
MEDIUM 5.0
CVE-2025-30474
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS.
The FtpFileObject class can throw an exception when …
Commons Vfs
2.10.0+
MEDIUM 6.5
CVE-2025-2331
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and…
Givewp
3.22.2+
HIGH 7.5
CVE-2025-27784
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This is…
Applio
after 3.2.8-bugfix