Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2025-62474
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8688 / 10.0.17763.8146+
MEDIUM 6.5
CVE-2025-59810
An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all v…
Fortisoar
7.5.2 / 7.6.3+
HIGH 7.8
CVE-2025-59517
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8688 / 10.0.17763.8146+
HIGH 7.5
CVE-2025-14286
A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/Downlo…
Ac9 Firmware
No fix yet
HIGH 7.5
CVE-2025-65795
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a craf…
Memos
Patch available
MEDIUM 6.5
CVE-2025-65797
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify …
Memos
Patch available
MEDIUM 5.4
CVE-2025-65798
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by oth…
Memos
Patch available
HIGH 7.2
CVE-2025-14219
A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/a…
Retro Basketball Shoes Online Store
No fix yet
MEDIUM 5.3
CVE-2025-14198
A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientreport/download?key=dummyt…
Verysync
after 2.21.3
CRITICAL 9.8
CVE-2025-14199
A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text…
Verysync
after 2.21.3
MEDIUM 5.3
CVE-2025-14197
A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/res…
Mitigation only
HIGH 8.8
CVE-2025-14195
A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/a…
Employee Profile Management System
No fix yet
HIGH 8.8
CVE-2025-14086
A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipul…
Youlai Mall
No fix yet
MEDIUM 6.5
CVE-2025-14052
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-…
Youlai Mall
No fix yet
CRITICAL 9.8
CVE-2025-66509
LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowin…
Lara Dashboard
after 2.3.0
HIGH 7.5
CVE-2025-63363
A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage …
Rs232\/485 To Wifi Eth \(b\) Firmware
No fix yet
HIGH 7.5
CVE-2025-57210
Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspecified v…
Platform
Mitigation only
HIGH 7.5
CVE-2025-57212
Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a crafted requ…
Platform
Mitigation only
HIGH 7.5
CVE-2025-57213
Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via a crafted …
Platform
Mitigation only
MEDIUM 6.5
CVE-2025-65097
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4…
Romm
4.4.1+
MEDIUM 6.2
CVE-2025-65841
Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings …
Aquarius
No fix yet
MEDIUM 6.3
CVE-2025-13949
A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.…
Mitigation only
CRITICAL 9.1
CVE-2025-59703
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal compo…
Nshield 5c Firmware
13.6.12 / 13.9.0+
HIGH 7.2
CVE-2025-59697
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by ed…
Nshield 5c Firmware
13.6.12 / 13.9.0+
HIGH 7.2
CVE-2025-59702
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with elevated privileges to …
Nshield 5c Firmware
13.6.12 / 13.9.0+
HIGH 7.5
CVE-2025-55749
XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJ…
Xwiki
16.10.11 / 17.4.4+
HIGH 7.8
CVE-2025-61229
An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight …
Superduper\!
after 3.10
HIGH 8.1
CVE-2025-57489
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improp…
Superduper\!
Mitigation only
HIGH 8.8
CVE-2025-63525
An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted…
Blood Bank Management System
No fix yet
CRITICAL 9.8
CVE-2025-13815
A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This man…
Mogublog
after 5.2