Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-6916
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /…
T6 Firmware
No fix yet
HIGH 7.5
CVE-2024-8419
The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authen…
Mitigation only
CRITICAL 9.8
CVE-2025-5310
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a s…
Mitigation only
HIGH 8.1
CVE-2025-6763
A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. Affected by this issue is som…
T7611 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-3699
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versi…
Mitigation only
MEDIUM 5.3
CVE-2025-1754
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could h…
GitLab
17.11.5 / 18.0.3+
HIGH 7.5
CVE-2025-6678
Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers t…
Maxicharger Ac Elite Business C50 Firmware
1.39.51 / 1.56.51+
HIGH 7.5
CVE-2025-32978
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5)…
Mitigation only
HIGH 8.2
CVE-2025-3090
An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function.
Mitigation only
CRITICAL 9.6
CVE-2025-48469
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially lea…
Wise 4060lan Firmware
No fix yet
CRITICAL 10.0
CVE-2025-34039
A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet)…
Mitigation only
CRITICAL 9.8
CVE-2025-3319
IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result …
Spectrum Protect Server
after 8.1.26
HIGH 8.8
CVE-2025-32879
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attac…
Coros Pace 3 Firmware
after 3.0808.0
MEDIUM 6.8
CVE-2025-32876
An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connectio…
Coros Pace 3 Firmware
after 3.0808.0
MEDIUM 6.5
CVE-2025-32896
# Summary
Unauthorized users can perform Arbitrary File Read and Deserialization
attack by submit job using restful api-v1.
# Details
Unauthorized …
Seatunnel
2.3.11+
CRITICAL 9.4
CVE-2025-49596EPSS 45%
The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code exe…
Patch available
MEDIUM 6.1
CVE-2024-35295
A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 t…
Mitigation only
HIGH 7.8
CVE-2024-9062
The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.…
Mitigation only
CRITICAL 9.8
CVE-2025-5906
A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manip…
Laundry System
Mitigation only
HIGH 7.5
CVE-2025-26468
CyberData
011209
Intercom exposes features that could allow an unauthenticated to gain
access and cause a denial-of-service condition or system …
011209 Sip Emergency Intercom
22.0.1+
CRITICAL 9.8
CVE-2025-49652
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data …
Mitigation only
MEDIUM 5.3
CVE-2025-5876
A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability …
Mitigation only
MEDIUM 5.3
CVE-2025-5871
A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality…
Mitigation only
MEDIUM 5.3
CVE-2025-5872
A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component…
Mitigation only
CRITICAL 9.8
CVE-2025-3461
The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Criti…
Qhs710 Firmware
Mitigation only
CRITICAL 9.0
CVE-2024-55585
In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read …
Mitigation only
HIGH 7.5
CVE-2025-5192
A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through ver…
Hr Portal
after 7.3.2025.0408
MEDIUM 5.1
CVE-2025-5719
The wallet has an authentication bypass vulnerability that allows access to specific pages.
No fix yet
MEDIUM 6.4
CVE-2025-5715
A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the compon…
Signal
No fix yet
HIGH 8.9
CVE-2025-1701
CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by sending a specially crafted …
Mitigation only