Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-53532
giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauthorized user to create discuss…
Patch available
MEDIUM 6.5
CVE-2025-6713
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of th…
MongoDB
6.0.22 / 7.0.19+
HIGH 8.8
CVE-2025-53106
Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain …
Graylog
6.2.4+
HIGH 8.8
CVE-2025-6736
A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-…
Cms
No fix yet
HIGH 8.8
CVE-2025-6735
A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the comp…
Cms
No fix yet
MEDIUM 5.3
CVE-2025-6702
A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment…
Litemall
No fix yet
MEDIUM 6.4
CVE-2025-20264
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass…
Identity Services Engine
Mitigation only
MEDIUM 6.5
CVE-2025-6431
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have b…
Firefox
140.0+
HIGH 8.1
CVE-2025-6329
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown process…
Real Estate Management System
No fix yet
MEDIUM 5.3
CVE-2025-6099
A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared as critical. This vulnerabili…
Mitigation only
HIGH 8.1
CVE-2025-22239
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the …
Mitigation only
HIGH 8.7
CVE-2025-46840
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalatio…
Experience Manager
6.5.23.0 / 2025.5.0+
HIGH 8.8
CVE-2024-43706
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.
Kibana
after 8.12.0
HIGH 8.2
CVE-2025-43585
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that cou…
Commerce
Mitigation only
HIGH 7.3
CVE-2025-5522
A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affe…
Mitigation only
HIGH 7.5
CVE-2025-5511
A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of…
Shiyi Blog
after 1.2.1
MEDIUM 5.0
CVE-2025-3454
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.
…
Mitigation only
CRITICAL 9.8
CVE-2025-4631
The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versio…
Mitigation only
HIGH 8.8
CVE-2025-4672
The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback…
Mitigation only
HIGH 8.8
CVE-2025-4103
The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_ajax_wpgm_start_geojson_import(…
Mitigation only
HIGH 7.5
CVE-2025-5182
A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability a…
Vacation Rental Management Platform
1.0.2+
MEDIUM 5.5
CVE-2025-5175
A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the function Save of the file pypickle/p…
Pypickle
2.0.0+
HIGH 8.8
CVE-2025-48371
OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.…
Helm Charts
0.2.32 / 1.8.13+
HIGH 8.8
CVE-2025-48063
XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part of the s…
Xwiki
16.10.4+
HIGH 8.8
CVE-2025-4473
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in…
Mitigation only
HIGH 8.8
CVE-2025-4474
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_fun…
Mitigation only
HIGH 7.1
CVE-2025-31249
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.
macOS
15.5+
HIGH 8.8
CVE-2025-29827
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
Azure Automation
Mitigation only
CRITICAL 9.8
CVE-2025-4104
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form…
Mitigation only
HIGH 8.2
CVE-2025-3921
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …
Mitigation only