Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-45613
Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.
Shiro Action
after 0.6
HIGH 7.5
CVE-2025-45614
Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.
One
No fix yet
CRITICAL 9.8
CVE-2025-45615
Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request.
Yaoqishan
No fix yet
CRITICAL 9.8
CVE-2025-45616
Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.
Brcc
after 1.2.0
HIGH 7.5
CVE-2025-45617
Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted…
Production Ssm
No fix yet
HIGH 7.5
CVE-2025-45608
Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a craft…
Xinguan
after 0.0.1-snapshot
MEDIUM 6.3
CVE-2025-4051
Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific…
Chrome
136.0.7103.59+
HIGH 7.5
CVE-2025-45237
Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account i…
Dbsyncer
No fix yet
HIGH 7.5
CVE-2025-4270EPSS 13%
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/…
A720r Firmware
No fix yet
MEDIUM 5.3
CVE-2025-4271
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functional…
A720r Firmware
No fix yet
MEDIUM 5.3
CVE-2025-4269
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/c…
A720r Firmware
No fix yet
CRITICAL 9.8
CVE-2025-4259
A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/n…
Newbee Mall
No fix yet
HIGH 8.8
CVE-2025-4258
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youk…
Youkefu
after 4.2.0
CRITICAL 9.1
CVE-2024-48905
Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
Replyone
No fix yet
HIGH 7.1
CVE-2025-46635
An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces…
Rx2 Pro Firmware
No fix yet
HIGH 7.3
CVE-2025-46628
Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.5
CVE-2025-46629
Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthor…
Rx2 Pro Firmware
No fix yet
CRITICAL 9.8
CVE-2025-46566
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC lin…
Dataease
2.10.9+
MEDIUM 6.3
CVE-2025-24887
OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed,…
Opencti
after 6.4.10
CRITICAL 9.8
CVE-2025-46331
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v…
Helm Charts
0.2.29 / 1.8.11+
HIGH 7.6
CVE-2025-46619
A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized acce…
Couchbase Server
7.2.7 / 7.6.4+
HIGH 8.8
CVE-2025-27134
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version …
Joplin
3.3.3+
HIGH 7.5
CVE-2025-4119
A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the compon…
Mall
Mitigation only
CRITICAL 9.1
CVE-2025-4118
A vulnerability classified as critical has been found in Weitong Mall 1.0.0. This affects an unknown part of the file /historyList of the component P…
Mall
Mitigation only
MEDIUM 6.3
CVE-2025-46552
KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some comm…
Patch available
CRITICAL 9.8
CVE-2025-25962
An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function
Mitigation only
HIGH 7.5
CVE-2025-4065
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerability affects unknown code of …
Online Traveling System
Mitigation only
CRITICAL 9.8
CVE-2025-4066
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of …
Online Traveling System
Mitigation only
MEDIUM 5.3
CVE-2025-4067
A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admi…
Online Traveling System
Mitigation only
MEDIUM 5.3
CVE-2025-4064
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file …
Online Traveling System
Mitigation only