Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2025-3565
A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /u…
Studentmanager
No fix yet
CRITICAL 9.8
CVE-2025-3558
A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uplo…
Uzy Ssm Mall
No fix yet
MEDIUM 6.8
CVE-2025-32726
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
Visual Studio Code
1.99.1+
HIGH 8.4
CVE-2025-23389
A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first logi…
Mitigation only
MEDIUM 5.3
CVE-2025-27190
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability th…
Commerce
Mitigation only
MEDIUM 5.3
CVE-2025-27191
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability th…
Commerce
1.3.3 / 2.4.4+
HIGH 8.2
CVE-2025-30288
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security fea…
Coldfusion
Mitigation only
CRITICAL 9.1
CVE-2025-30281EPSS 20%
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code…
Coldfusion
Mitigation only
HIGH 7.3
CVE-2025-29804
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
Visual Studio 2022
17.8.20 / 17.10.13+
HIGH 7.5
CVE-2025-29810
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
HIGH 7.8
CVE-2025-27744
Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.
Office
Mitigation only
MEDIUM 6.5
CVE-2025-27738
Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
HIGH 8.4
CVE-2025-26678
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
Windows 10 1809
10.0.17763.7136 / 10.0.19044.5737+
MEDIUM 6.5
CVE-2025-21197
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't hav…
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
HIGH 8.8
CVE-2025-3410
A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform…
Aias
No fix yet
CRITICAL 9.8
CVE-2025-3398
A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blo…
Vblog
Mitigation only
HIGH 8.8
CVE-2025-28409
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly valida…
Ruoyi
No fix yet
CRITICAL 9.8
CVE-2025-28410
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the req…
Ruoyi
No fix yet
CRITICAL 9.8
CVE-2025-28411
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
Ruoyi
No fix yet
CRITICAL 9.8
CVE-2025-28412
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
Ruoyi
No fix yet
CRITICAL 9.8
CVE-2025-28413
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
Ruoyi
No fix yet
CRITICAL 9.8
CVE-2025-28402
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
Ruoyi
No fix yet
HIGH 7.2
CVE-2025-28403
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting u…
Ruoyi
No fix yet
CRITICAL 9.8
CVE-2025-28405
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
Ruoyi
No fix yet
CRITICAL 9.8
CVE-2025-28406
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
Ruoyi
No fix yet
HIGH 8.8
CVE-2025-28407
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly valida…
Ruoyi
No fix yet
CRITICAL 9.8
CVE-2025-28408
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does…
Ruoyi
No fix yet
HIGH 7.8
CVE-2025-21425
Memory corruption may occur due top improper access control in HAB process.
Qam8255p Firmware
No fix yet
HIGH 8.8
CVE-2025-3324
A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown funct…
Nimrod
No fix yet
HIGH 7.5
CVE-2025-3256
A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file…
Admintwo
No fix yet