Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-45584
Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authe…
Universal Traffic Recorder Firmware
No fix yet
MEDIUM 5.3
CVE-2025-10321
A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead t…
Wl Wn578w2 Firmware
No fix yet
HIGH 7.5
CVE-2024-45432
OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue res…
Blue Sdk
after 6.0.1
MEDIUM 6.3
CVE-2025-10247
A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of the component Filter Handler.…
Mitigation only
HIGH 8.8
CVE-2025-10201
Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site is…
Chrome
140.0.7339.127+
MEDIUM 5.3
CVE-2025-20159
A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, rem…
Mitigation only
HIGH 7.5
CVE-2025-56405
An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through …
Mcp Server
No fix yet
HIGH 7.5
CVE-2025-56406
An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE…
Mitigation only
HIGH 7.3
CVE-2025-54116
Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
HIGH 7.8
CVE-2025-54098
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
HIGH 7.8
CVE-2025-49692
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.49+
HIGH 7.3
CVE-2025-10116
A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manip…
Mitigation only
MEDIUM 5.3
CVE-2025-58751
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the pu…
Vite
5.4.20 / 6.3.6+
MEDIUM 5.3
CVE-2025-58752
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served reg…
Vite
5.4.20 / 6.3.6+
HIGH 7.5
CVE-2025-10093
A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php…
Dir 852 Firmware
No fix yet
HIGH 8.8
CVE-2025-10085
A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file manag…
Pet Grooming Management Software
No fix yet
HIGH 8.8
CVE-2025-10083
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the fi…
Pet Grooming Management Software
No fix yet
HIGH 7.2
CVE-2025-10081
A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation…
Pet Grooming Management Software
No fix yet
MEDIUM 6.3
CVE-2025-10071
A vulnerability has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /cancelar-enturmacao-em-lote/. …
I Educar
after 2.10.0
MEDIUM 6.3
CVE-2025-10072
A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/…
I Educar
after 2.10.0
MEDIUM 6.3
CVE-2025-10070
A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /enturmacao-em-lote/. This manipulation causes impr…
I Educar
after 2.10.0
MEDIUM 6.3
CVE-2025-10013
A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao-para-o-seb. Performing manip…
I Educar
after 2.10.0
CRITICAL 9.0
CVE-2025-55244
Azure Bot Service Elevation of Privilege Vulnerability
Azure Ai Bot Service
No fix yet
CRITICAL 9.8
CVE-2025-54914
Azure Networking Elevation of Privilege Vulnerability
Azure Networking
No fix yet
HIGH 7.5
CVE-2025-55238
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
Dynamics 365
No fix yet
HIGH 8.8
CVE-2025-9942
A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The m…
Real Estate Management System
No fix yet
HIGH 8.8
CVE-2025-9941
A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulat…
Real Estate Management System
No fix yet
MEDIUM 5.3
CVE-2025-36909
Information disclosure
Android
No fix yet
MEDIUM 5.3
CVE-2025-20335
A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could a…
Desk Phone 9841 Firmware
3.3 / 14.3+
MEDIUM 6.8
CVE-2025-21031
Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.
Android
Mitigation only