Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-25951
An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information Syste…
Academia Student Information System
Mitigation only
HIGH 7.5
CVE-2024-13611
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Informa…
Better Messages
2.7.0+
HIGH 7.2
CVE-2024-13911
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio…
Mitigation only
HIGH 7.5
CVE-2024-13568
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u…
Fluent Support
1.8.6+
MEDIUM 5.1
CVE-2025-26263
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to imp…
Mitigation only
HIGH 7.5
CVE-2024-13638
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.…
Order Attachments For Woocommerce
after 2.5.1
HIGH 7.5
CVE-2024-13796
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl…
Post Grid
2.3.7+
HIGH 7.5
CVE-2025-25729
An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attacker…
Mitigation only
MEDIUM 5.3
CVE-2024-38290
In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.
Xiq Se
24.2.11+
MEDIUM 5.3
CVE-2025-27399
Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/re…
Mastodon
4.1.23 / 4.2.16+
HIGH 7.5
CVE-2025-25333
An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.
No fix yet
MEDIUM 5.3
CVE-2024-12434
The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. T…
Mitigation only
MEDIUM 6.5
CVE-2025-25192
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive i…
Glpi
10.0.18+
MEDIUM 6.5
CVE-2025-21626
GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive…
Glpi
10.0.18+
MEDIUM 5.3
CVE-2025-1063
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi…
Classified Listing
4.0.5+
HIGH 7.5
CVE-2025-1606
A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of…
Best Employee Management System
No fix yet
MEDIUM 5.3
CVE-2025-1595
A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects un…
No fix yet
HIGH 7.5
CVE-2025-22973
An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. …
Qibocms X1
Mitigation only
MEDIUM 6.5
CVE-2024-54961
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the username…
Nagios Xi
Mitigation only
MEDIUM 6.5
CVE-2025-26309
A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackers to caus…
Libming
No fix yet
MEDIUM 6.5
CVE-2025-26310
Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c of libming …
Libming
No fix yet
HIGH 7.5
CVE-2024-57716
An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.
Mitigation only
MEDIUM 6.5
CVE-2025-25942
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specific…
Bento4
No fix yet
MEDIUM 6.5
CVE-2025-25945
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDesc…
Bento4
No fix yet
MEDIUM 5.5
CVE-2025-25946
An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncrypt…
Bento4
No fix yet
MEDIUM 6.1
CVE-2020-13481
Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other sensitive information.
Mitigation only
MEDIUM 6.5
CVE-2025-25468
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.
Ffmpeg
2025-01-13+
HIGH 8.3
CVE-2025-26604
Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Beca…
Patch available
MEDIUM 5.9
CVE-2024-13609
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver…
1 Click Migration
after 2.1
HIGH 7.5
CVE-2024-13622
The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7…
File Uploads Addon For Woocommerce
after 1.7.1