Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-20702EPSS 8%
In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege wi…
Mitigation only
HIGH 8.8
CVE-2025-20700EPSS 8%
In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT …
Mitigation only
HIGH 8.5
CVE-2013-10046
A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code…
No fix yet
CRITICAL 9.3
CVE-2025-8286
The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify hardware configurations, m…
Mitigation only
CRITICAL 9.2
CVE-2014-125126
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentic…
No fix yet
CRITICAL 10.0
CVE-2014-125124
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, wh…
Mitigation only
CRITICAL 9.8
CVE-2025-8279
Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution
Language Server
7.30.0+
MEDIUM 5.3
CVE-2025-30126
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a remote attack…
Mitigation only
CRITICAL 9.4
CVE-2025-30135
An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication cont…
Fx2 Firmware
Mitigation only
CRITICAL 9.3
CVE-2014-125116
A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. T…
No fix yet
CRITICAL 9.4
CVE-2014-125118
A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' par…
No fix yet
HIGH 8.6
CVE-2016-15046
A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restri…
Mitigation only
HIGH 8.8
CVE-2013-10032
An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated…
Getsimplecms
No fix yet
CRITICAL 9.8
CVE-2025-6260
The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local ar…
Mitigation only
CRITICAL 9.3
CVE-2022-4978
Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the …
Mitigation only
CRITICAL 9.3
CVE-2015-10141EPSS 5%
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick …
No fix yet
HIGH 8.5
CVE-2016-15045
A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepi…
No fix yet
HIGH 7.5
CVE-2025-48733
DuraComm SPM-500 DP-10iN-100-MU
lacks access controls for a function that should require user authentication. This could allow an attacker to repea…
Mitigation only
CRITICAL 9.8
CVE-2025-7897
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token …
Moneyprinterturbo
after 1.2.6
CRITICAL 9.8
CVE-2025-7862
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTel…
T6 Firmware
Mitigation only
MEDIUM 6.5
CVE-2025-6226
Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts…
Mattermost Server
9.11.17 / 10.5.7+
HIGH 8.7
CVE-2025-34130
An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin…
Mitigation only
CRITICAL 9.3
CVE-2025-34121
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post…
No fix yet
CRITICAL 9.3
CVE-2025-34117EPSS 20%
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the pres…
No fix yet
HIGH 8.8
CVE-2025-34119
A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server…
No fix yet
HIGH 8.7
CVE-2025-34120
An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 151014. The application fails …
Mitigation only
HIGH 7.5
CVE-2025-53938
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was i…
Wegia
3.4.5+
HIGH 7.5
CVE-2025-30762
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…
Weblogic Server
Patch available
HIGH 8.7
CVE-2025-34116
A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated att…
No fix yet
CRITICAL 10.0
CVE-2025-34112
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances…
Mitigation only