Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2025-55169
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vul…
Wegia
3.4.8+
HIGH 7.5
CVE-2025-53793
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
Azure Stack Hub
1.2406.1.23 / 1.2408.1.50+
HIGH 8.8
CVE-2025-53778EPSS 38%
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.21100 / 10.0.14393.8330+
CRITICAL 9.8
CVE-2025-8838
A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHand…
My Site
Mitigation only
HIGH 8.7
CVE-2025-54888
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5…
Patch available
MEDIUM 5.3
CVE-2025-54786
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken au…
Suitecrm
Mitigation only
HIGH 8.0
CVE-2025-53786EPSS 7%
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made…
Exchange Server
15.02.2562.017+
MEDIUM 5.3
CVE-2025-8546
A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the compone…
Pybbs
after 6.0.0
HIGH 7.5
CVE-2025-8348
A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability affects unknown code of the f…
Charging Pile Cloud Platform
No fix yet
MEDIUM 6.5
CVE-2025-54573
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not …
Computer Vision Annotation Tool
2.42.0+
HIGH 8.1
CVE-2025-6505
Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vu…
Hybrid Data Pipeline
4.6.2.3275+
CRITICAL 10.0
CVE-2025-54419
A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original respon…
Patch available
CRITICAL 9.8
CVE-2025-45777
An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a …
Chavara Matrimony
Mitigation only
MEDIUM 5.9
CVE-2025-0249
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to acces…
Intelliops Event Management
Mitigation only
HIGH 7.0
CVE-2024-12310
A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstat…
Mitigation only
CRITICAL 9.8
CVE-2025-54452
Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: l…
Magicinfo 9 Server
21.1080.0+
HIGH 7.8
CVE-2025-41459
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS all…
Mitigation only
CRITICAL 9.8
CVE-2024-6107
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has…
Metal As A Service
3.1.4 / 3.2.11+
MEDIUM 6.5
CVE-2025-53771EPSS 100%
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.18526.20508+
CRITICAL 9.8
CVE-2025-7897
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token …
Moneyprinterturbo
after 1.2.6
HIGH 7.5
CVE-2025-7875
A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This affects an unknown part of the file /debug.jsp. …
Metacrm
after 6.4.2
CRITICAL 9.8
CVE-2025-7862
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTel…
T6 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-37106
An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
Autopass License Server
9.18+
CRITICAL 9.8
CVE-2025-37107
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
Autopass License Server
9.18+
HIGH 7.1
CVE-2025-7699
An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to copy arbitrary files from the …
Mitigation only
CRITICAL 9.8
CVE-2025-49831
An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can r…
Conjur
1.22.1 / 13.5.1+
CRITICAL 9.8
CVE-2025-52376EPSS 10%
An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, a…
Mitigation only
CRITICAL 9.6
CVE-2025-3621
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.
* vulnerabilit…
Mitigation only
MEDIUM 6.5
CVE-2025-53889
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flo…
Directus
11.9.0+
HIGH 7.3
CVE-2024-51767
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
Autopass License Server
9.17+