Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2023-44752
An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin…
Student Study Center Desk Management System
No fix yet
HIGH 8.1
CVE-2025-27086
A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.
Performance Cluster Manager
1.13+
HIGH 8.2
CVE-2025-31478
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticat…
Zulip Server
10.2+
CRITICAL 9.6
CVE-2025-30215
NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.2…
Mitigation only
MEDIUM 6.5
CVE-2025-30733
Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-2…
Rdbms Listener
after 23.7
MEDIUM 5.9
CVE-2024-44843
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying …
Steve
No fix yet
MEDIUM 6.5
CVE-2025-24949
In JotUrl 2.0, is possible to bypass security requirements during the password change process.
Joturl
No fix yet
MEDIUM 5.3
CVE-2025-2572
In WhatsUp Gold versions released before 2024.0.3, a
database manipulation
vulnerability allows an unauthenticated attacker to modify the content…
Whatsup Gold
24.0.3+
MEDIUM 5.3
CVE-2025-22232
Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to Vault.
Your application may …
Mitigation only
CRITICAL 9.3
CVE-2025-22375
An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a vali…
Mitigation only
HIGH 8.2
CVE-2025-30287
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code…
Coldfusion
Mitigation only
CRITICAL 9.1
CVE-2025-30282
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code…
Coldfusion
Mitigation only
HIGH 7.5
CVE-2025-25227
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Joomla\!
4.4.13 / 5.2.6+
CRITICAL 9.8
CVE-2025-3268
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file ht…
Tinywebserver
after 1.0
MEDIUM 6.6
CVE-2025-3061
Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.
Material Admin
No fix yet
MEDIUM 6.6
CVE-2025-3062
Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.
Admin Lte Theme
No fix yet
CRITICAL 9.8
CVE-2025-30430
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchO…
Ipados
2.4 / 15.4+
MEDIUM 6.4
CVE-2025-30432
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macO…
Ipados
2.4 / 13.7.5+
CRITICAL 9.0
CVE-2025-31122
scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to login to any account by changing …
Mitigation only
CRITICAL 9.8
CVE-2024-13804
Unauthenticated RCE in HPE Insight Cluster Management Utility
No fix yet
CRITICAL 9.8
CVE-2025-2859
An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make chang…
Satech Bcu Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-30361
WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to chang…
Wegia
3.2.6+
HIGH 7.5
CVE-2025-30214
Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure…
Frappe
14.89.0 / 15.51.0+
MEDIUM 6.9
CVE-2025-30168
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd party authe…
Patch available
HIGH 7.7
CVE-2024-57490
Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including the system …
Ioffice20
Mitigation only
HIGH 7.4
CVE-2025-22228
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 chara…
Mitigation only
MEDIUM 5.5
CVE-2025-26475
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping containers ru…
Secure Connect Gateway
Patch available
CRITICAL 9.1
CVE-2025-30114
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely…
Dr 820 Firmware
Mitigation only
HIGH 7.5
CVE-2025-30116
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. It …
Dr 820 Firmware
Mitigation only
HIGH 7.3
CVE-2025-2388
A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by this vulnerability is an unknown functional…
Mitigation only