Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-2638
A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file /user/release.html …
Jizhicms
after 1.7
MEDIUM 5.3
CVE-2025-2637
A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of…
Jizhicms
after 1.7
CRITICAL 9.1
CVE-2025-29927EPSS 99%
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and …
Next.js
12.3.5 / 13.5.9+
CRITICAL 9.8
CVE-2025-2589
A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index o…
Human Resource Management
No fix yet
CRITICAL 9.6
CVE-2025-29922
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vuln…
Patch available
CRITICAL 9.8
CVE-2025-29926
XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki…
Xwiki
15.10.15 / 16.4.6+
HIGH 7.3
CVE-2025-30117
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Batt…
Dr 820 Firmware
Mitigation only
MEDIUM 6.5
CVE-2024-44314
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order st…
Tastyigniter
Mitigation only
CRITICAL 9.8
CVE-2025-2360
A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings…
Dir 823g Firmware
No fix yet
CRITICAL 9.8
CVE-2025-2359EPSS 15%
A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNA…
Dir 823g Firmware
No fix yet
CRITICAL 9.8
CVE-2025-2345
A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. This affects an unknown part. …
Mitigation only
CRITICAL 9.8
CVE-2025-2320
A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this vulnerability is the funct…
Springboot Openai Chatgpt
No fix yet
HIGH 7.2
CVE-2025-24053
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
Dataverse
Mitigation only
MEDIUM 6.4
CVE-2025-27602
Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1…
Umbraco Cms
10.8.9 / 13.7.1+
CRITICAL 9.3
CVE-2025-27509
fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML…
Patch available
MEDIUM 5.5
CVE-2024-43051
Information disclosure while deriving keys for a session for any Widevine use case.
Aqt1000 Firmware
No fix yet
HIGH 8.8
CVE-2025-1847
A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation lead…
Zz
after 2024-8
HIGH 7.3
CVE-2025-1815
A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resou…
Mitigation only
MEDIUM 5.3
CVE-2025-27399
Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/re…
Mastodon
4.1.23 / 4.2.16+
HIGH 7.7
CVE-2024-47053
This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized acces…
Mautic
5.2.3+
MEDIUM 5.3
CVE-2025-1361
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due t…
Country Blocker
2.38.9+
CRITICAL 9.8
CVE-2025-25196
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (He…
Helm Charts
0.2.22 / 1.8.5+
MEDIUM 5.3
CVE-2025-1007
In OpenVSX version v0.9.0 to v0.20.0, the
/user/namespace/{namespace}/details API allows a user to edit all
namespace details, even if the user is …
Open Vsx
0.19.1+
MEDIUM 5.4
CVE-2024-13692
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vul…
Return Refund And Exchange For Woocommerce
4.4.6+
CRITICAL 9.8
CVE-2025-1226
A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/s…
Yimioa
2024-07-04+
MEDIUM 5.3
CVE-2024-13821
The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and inclu…
Booking Calendar
10.10.1+
HIGH 8.1
CVE-2025-24418
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability tha…
Commerce B2b
1.3.3+
HIGH 8.0
CVE-2025-21400EPSS 34%
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Server
16.0.17928.20396+
MEDIUM 5.3
CVE-2025-1078
A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects t…
Mitigation only
HIGH 7.5
CVE-2024-57954
Permission verification vulnerability in the media library module
Impact: Successful exploitation of this vulnerability may affect service confidenti…
Harmonyos
No fix yet