Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-4018
A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue a…
Novel Plus
5.1.1+
HIGH 7.5
CVE-2025-4015
A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issu…
Novel Plus
5.1.1+
CRITICAL 9.8
CVE-2025-46275
WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could
allow an attacker to create an administrator account without knowing any
exist…
Mitigation only
CRITICAL 10.0
CVE-2025-34028 KEVEPSS 98%
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand…
Commvault
11.38.20+
MEDIUM 6.5
CVE-2025-32377
Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has …
Mitigation only
HIGH 7.5
CVE-2024-42178
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially con…
Dryice Myxalytics
Mitigation only
CRITICAL 10.0
CVE-2025-32433 KEVEPSS 99%
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server ma…
Confd Basic
5.7.19.1 / 6.1.16.2+
CRITICAL 9.6
CVE-2025-30215
NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.2…
Mitigation only
MEDIUM 5.3
CVE-2025-32782
Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered b…
Patch available
CRITICAL 9.8
CVE-2025-30727
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.…
E Business Suite
after 12.2.14
CRITICAL 9.8
CVE-2025-2567
An attacker could modify or disable settings, disrupt fuel monitoring
and supply chain operations, leading to disabling of ATG monitoring.
This wou…
Mitigation only
CRITICAL 9.3
CVE-2025-0129
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying i…
Mitigation only
MEDIUM 6.5
CVE-2025-3474
Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.T…
Panels
4.9+
HIGH 7.5
CVE-2025-29870
Missing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attac…
Mitigation only
HIGH 7.5
CVE-2024-41793
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an endpoint th…
7kt Pac1260 Data Manager Firmware
Mitigation only
MEDIUM 6.5
CVE-2024-41791
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not authenticate r…
7kt Pac1260 Data Manager Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-3248 KEVEPSS 100%
Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can …
Langflow
1.3.0+
HIGH 7.5
CVE-2025-0257
HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authenticatio…
Hcl Devops Deploy
7.1.2.23 / 7.2.3.16+
HIGH 8.2
CVE-2025-25060
Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the p…
Mitigation only
CRITICAL 9.8
CVE-2024-13553
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to…
Sms Alert Order Notifications
3.8.0+
MEDIUM 6.3
CVE-2024-56469
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 throu…
Devops Deploy
7.1.2.23 / 7.2.3.16+
HIGH 7.3
CVE-2024-45356
A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by …
No fix yet
MEDIUM 5.5
CVE-2024-45355
A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by …
Mitigation only
HIGH 7.0
CVE-2024-45483
A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow an unauthenticated physical a…
Mitigation only
MEDIUM 6.5
CVE-2025-0256
HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing autho…
Hcl Devops Deploy
7.0.5.26 / 7.1.2.22+
HIGH 8.8
CVE-2025-25068
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows auth…
Mattermost Server
9.11.9 / 10.3.4+
HIGH 8.4
CVE-2024-9919
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. T…
Lollms Web Ui
No fix yet
CRITICAL 9.8
CVE-2024-8196
In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by defaul…
Anythingllm Desktop
1.6.5+
HIGH 8.2
CVE-2024-8053
In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to a…
Open Webui
No fix yet
HIGH 7.5
CVE-2024-6842EPSS 31%
In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The…
Anythingllm
Patch available