Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2025-36612
SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker wit…
Supportassist For Business Pcs
4.9.0+
HIGH 7.8
CVE-2025-36613
SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect Privilege As…
Supportassist For Business Pcs
4.8.2.38851 / 4.9.0+
HIGH 7.8
CVE-2025-38738
SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in the Installe…
Supportassist For Home Pcs
4.8.2.38851+
HIGH 7.2
CVE-2025-54697
Incorrect Privilege Assignment vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Privilege Esca…
Mitigation only
MEDIUM 5.5
CVE-2024-12303
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under ce…
GitLab
18.0.6 / 18.1.4+
HIGH 7.2
CVE-2025-53744
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versio…
Fortios
7.4.8 / 7.6.3+
MEDIUM 5.4
CVE-2025-42936
The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this …
Sap Basis
Patch available
MEDIUM 5.4
CVE-2025-8840
A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoi…
Jsherp
No fix yet
HIGH 8.8
CVE-2025-8839
A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endp…
Jsherp
No fix yet
HIGH 8.8
CVE-2025-8797
A vulnerability was found in LitmusChaos Litmus up to 3.19.0 and classified as critical. This issue affects some unknown processing of the component …
Litmus
after 3.19.0
CRITICAL 9.9
CVE-2025-8795
A vulnerability, which was classified as critical, was found in LitmusChaos Litmus up to 3.19.0. This affects an unknown part of the file /auth/login…
Litmus
after 3.19.0
MEDIUM 6.3
CVE-2025-8791
A vulnerability was found in LitmusChaos Litmus up to 3.19.0. It has been rated as critical. This issue affects some unknown processing of the file /…
Litmus
after 3.19.0
HIGH 7.0
CVE-2025-8758
A vulnerability was found in TRENDnet TEW-822DRE FW103B02. It has been classified as problematic. This affects an unknown part of the component vsftp…
No fix yet
HIGH 8.8
CVE-2025-8756
A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preH…
Tduck Platform
after 5.1
HIGH 7.0
CVE-2025-8757
A vulnerability was found in TRENDnet TV-IP110WN 1.2.2 and classified as problematic. Affected by this issue is some unknown functionality of the fil…
No fix yet
MEDIUM 5.3
CVE-2025-8547
A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email …
Pybbs
after 6.0.0
HIGH 7.2
CVE-2025-5999
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privile…
Vault
1.16.22 / 1.18.11+
MEDIUM 5.1
CVE-2025-43260
This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack …
macOS
14.7.7 / 15.6+
MEDIUM 6.8
CVE-2025-2179
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a locally authenticated non adm…
Mitigation only
CRITICAL 9.8
CVE-2025-8261
A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the componen…
Vaelsys
Mitigation only
HIGH 7.2
CVE-2025-8181
A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.co…
N600r Firmware
No fix yet
MEDIUM 6.5
CVE-2025-31513
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the IsAdminApprover parameter in a …
Mitigation only
HIGH 8.1
CVE-2025-7947
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component …
Jsherp
after 3.5
CRITICAL 9.8
CVE-2025-44655
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized acce…
A7100ru Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-52836
Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Privilege Escalation.This issue…
Mitigation only
CRITICAL 10.0
CVE-2025-34112
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances…
Mitigation only
HIGH 7.3
CVE-2025-7576
A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16 and classified as critical. Affected by this issue is some unkn…
No fix yet
MEDIUM 6.3
CVE-2025-7552
A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the fi…
Mitigation only
MEDIUM 6.3
CVE-2025-0139
An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privil…
Mitigation only
MEDIUM 6.8
CVE-2025-0140
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non adm…
Mitigation only