Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2025-55278
Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation…
Mitigation only
MEDIUM 5.5
CVE-2025-43468
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 1…
macOS
14.8.2 / 15.7.2+
MEDIUM 5.5
CVE-2025-43390
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 1…
macOS
15.7.2+
MEDIUM 5.9
CVE-2025-54549
Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO
No fix yet
HIGH 8.3
CVE-2025-58356
Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persistent storage. When opening an …
Patch available
HIGH 8.1
CVE-2025-12295
A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler.…
Dap 2695 Firmware
No fix yet
HIGH 7.0
CVE-2025-34503
Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can repl…
Mitigation only
HIGH 7.0
CVE-2025-34500
Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key…
Mitigation only
MEDIUM 6.5
CVE-2025-55039
This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0.
Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure defau…
Spark
3.4.4 / 3.5.2+
MEDIUM 5.3
CVE-2025-59288
Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.
Playwright
1.55.1+
HIGH 7.8
CVE-2025-46774
An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and…
Forticlient
7.2.10 / 7.4.4+
CRITICAL 9.8
CVE-2025-9485
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up t…
Mitigation only
CRITICAL 9.4
CVE-2025-59934EPSS 8%
Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stem…
Patch available
CRITICAL 9.3
CVE-2024-13990
MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without ro…
Mitigation only
HIGH 7.2
CVE-2025-7937
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a…
Mitigation only
HIGH 7.2
CVE-2025-6198
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with…
Mitigation only
HIGH 8.8
CVE-2025-59334
Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not verify the integrity or authen…
Linkr
2.0.1+
MEDIUM 6.0
CVE-2025-20248
A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software ima…
Mitigation only
HIGH 7.2
CVE-2025-52550
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade pack…
E3 Supervisory Controller Firmware
2.31f01+
HIGH 8.8
CVE-2025-30064
An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verif…
Mitigation only
CRITICAL 9.1
CVE-2025-57801
gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a s…
Gnark
0.14.0+
MEDIUM 5.3
CVE-2025-55229
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
MEDIUM 6.8
CVE-2025-4371
A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to wri…
Mitigation only
HIGH 8.7
CVE-2025-40758
A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendix 10.21 compatible) (All vers…
Mitigation only
CRITICAL 9.6
CVE-2025-54982
An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.
Mitigation only
CRITICAL 9.8
CVE-2025-8454
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to …
Devscripts
Mitigation only
MEDIUM 5.5
CVE-2025-43185
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6. An app may be able to access pr…
macOS
15.6+
CRITICAL 10.0
CVE-2025-54419
A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original respon…
Patch available
CRITICAL 9.1
CVE-2025-43023
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is d…
Linux Imaging And Printing
3.25.2+
CRITICAL 9.3
CVE-2025-54369
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (u…
Patch available