Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-56396
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the act…
Ruoyi
No fix yet
HIGH 7.5
CVE-2025-46174
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserControll…
Ruoyi
Mitigation only
MEDIUM 5.4
CVE-2025-65963
Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow n…
Patch available
HIGH 8.8
CVE-2025-64064
Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SEC…
Project Contract Management
Mitigation only
HIGH 8.6
CVE-2025-64066
Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any…
Project Contract Management
Mitigation only
HIGH 7.5
CVE-2025-54563
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Inc…
Pingalert Application Server
6.1.1.6+
HIGH 7.5
CVE-2025-54338
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an …
Pingalert Application Server
6.1.1.6+
CRITICAL 9.8
CVE-2025-63958
MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authenticatio…
Vision Tools Workspace
Mitigation only
HIGH 8.8
CVE-2025-13573
A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_…
Advanced Library Management System
No fix yet
HIGH 7.2
CVE-2025-13574
A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/add…
Online Bidding System
No fix yet
CRITICAL 9.8
CVE-2025-13544
A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the f…
Travel Agency
after 2025-07-05
MEDIUM 5.3
CVE-2025-64483
Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configurati…
Patch available
HIGH 8.0
CVE-2025-64660
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
Visual Studio Code
1.106.2+
HIGH 8.8
CVE-2025-48986
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and po…
Revive Adserver
after 6.0.1
MEDIUM 6.1
CVE-2025-60799
phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manip…
Phppgadmin
after 7.13.0
MEDIUM 6.5
CVE-2025-13443
A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Pe…
Mall
after 1.0.3
HIGH 7.2
CVE-2025-13423
A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_prod…
Retro Basketball Shoes Online Store
No fix yet
CRITICAL 9.8
CVE-2025-13411
A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the fil…
Retro Basketball Shoes Online Store
Mitigation only
MEDIUM 6.5
CVE-2025-63214
An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauthorized attackers to delete an…
Vbc Server
No fix yet
CRITICAL 9.1
CVE-2025-63221
The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi…
Puma Firmware
after 1.0.3
CRITICAL 9.8
CVE-2025-63223
The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authenticatio…
Streamermax Mk Ii Firmware
after 1.0.3
CRITICAL 9.8
CVE-2025-63218
The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authenticat…
Wolf1ms Firmware
after 1.0.3
HIGH 7.5
CVE-2025-63219
The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home…
Iso Fm Firmware
No fix yet
CRITICAL 9.8
CVE-2025-63225
The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical admi…
Elts 100 Firmware
Mitigation only
MEDIUM 6.5
CVE-2025-56499
Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges…
Mihomo
No fix yet
HIGH 7.8
CVE-2025-37155
A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only u…
Arubaos Cx
10.10.1170 / 10.13.1101+
HIGH 7.5
CVE-2025-41737
Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.
Ewio2 M Firmware
2.2.0+
HIGH 8.8
CVE-2025-13250
A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job…
Datax Web
after 2.1.2
MEDIUM 6.3
CVE-2025-13249
A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTempl…
Mitigation only
HIGH 8.8
CVE-2025-13238
A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/pro…
Flight Booking Software
No fix yet