Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-7100
A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /appl…
Boyuncms
after 1.4.20
HIGH 8.8
CVE-2025-7076
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionalit…
Blackvue Dr590x Firmware
after 2025-06-24
HIGH 8.8
CVE-2025-7075
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown fun…
Blackvue Dr590x Firmware
after 2025-06-24
MEDIUM 5.3
CVE-2025-6786
The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, 1.1.5. This is due to plugin …
Mitigation only
HIGH 8.8
CVE-2025-53501
Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrain…
Scribunto
Patch available
MEDIUM 5.3
CVE-2025-45424
Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.
Xinference
1.4.0+
CRITICAL 9.8
CVE-2025-52101
linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authenticat…
Mitigation only
MEDIUM 6.5
CVE-2025-27153
Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This…
Mitigation only
HIGH 8.8
CVE-2025-45081
Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.
No fix yet
MEDIUM 6.1
CVE-2025-45083
Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental pin feature via unspecified ve…
No fix yet
MEDIUM 6.5
CVE-2025-50405
Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation functio…
Rx 1500 Firmware
after 2.2.17
HIGH 8.2
CVE-2025-53003
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without s…
Patch available
CRITICAL 9.8
CVE-2025-6900
A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /a…
Library System
Mitigation only
HIGH 8.8
CVE-2025-46014
Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with d…
Pc Manager
after 16.0.0.118
HIGH 7.2
CVE-2025-6873
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown proce…
Simple Company Website
No fix yet
HIGH 7.2
CVE-2025-6872
A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /c…
Simple Company Website
No fix yet
HIGH 8.8
CVE-2025-6848
A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of th…
Simple Forum
No fix yet
CRITICAL 9.8
CVE-2025-6843
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file …
Simple Photo Gallery
Mitigation only
CRITICAL 9.8
CVE-2025-6837
A vulnerability classified as critical was found in code-projects Library System 1.0. Affected by this vulnerability is an unknown functionality of t…
Library System
Mitigation only
MEDIUM 6.3
CVE-2023-29113
The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process comm…
Mitigation only
MEDIUM 6.7
CVE-2023-28907
There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to com…
Mitigation only
MEDIUM 6.3
CVE-2025-45729
D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.
Dir 823 Pro Firmware
No fix yet
CRITICAL 9.1
CVE-2025-49603
Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.
Mitigation only
HIGH 8.3
CVE-2024-52928
Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permission…
Arc
1.26.1+
HIGH 8.8
CVE-2025-6667
A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …
Car Rental System
No fix yet
HIGH 7.2
CVE-2025-6443
Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on …
Routeros
7.20+
CRITICAL 9.8
CVE-2023-47031
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRo…
Terminal Handler
Mitigation only
HIGH 8.1
CVE-2023-47294
An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts…
Terminal Handler
Mitigation only
CRITICAL 9.8
CVE-2023-47297
A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system securit…
Terminal Handler
Mitigation only
CRITICAL 9.8
CVE-2025-6466
A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function speechToTextTranscriptionsV2/u…
Ruoyi Ai
2.0.1+