Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-25276
An unauthenticated attacker can hijack other users' devices and potentially control them.
Cloud Portal
after 3.6.0
MEDIUM 5.3
CVE-2025-31933
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
Cloud Portal
after 3.6.0
MEDIUM 5.3
CVE-2025-31941
An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
Cloud Portal
after 3.6.0
MEDIUM 5.3
CVE-2025-31949
An authenticated attacker can obtain any plant name by knowing the plant ID.
Cloud Portal
after 3.6.0
MEDIUM 5.3
CVE-2025-31357
An unauthenticated attacker can obtain a user's plant list by knowing the username.
Cloud Portal
after 3.6.0
MEDIUM 5.3
CVE-2025-30514
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
Cloud Portal
after 3.6.0
MEDIUM 5.3
CVE-2025-30254
An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
Cloud Portal
after 3.6.0
MEDIUM 5.3
CVE-2025-27568
An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request.
Cloud Portal
after 3.6.0
MEDIUM 5.3
CVE-2025-27938
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
Cloud Portal
after 3.6.0
HIGH 7.5
CVE-2025-27939
An attacker can change registered email addresses of other users and take over arbitrary accounts.
Cloud Portal
after 3.6.0
MEDIUM 5.3
CVE-2025-24487
An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
Cloud Portal
after 3.6.0
HIGH 8.7
CVE-2025-3574
Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via …
Mitigation only
HIGH 8.7
CVE-2025-3575
Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via …
Mitigation only
MEDIUM 6.5
CVE-2025-3536
A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown func…
Employee Management System
No fix yet
MEDIUM 5.3
CVE-2025-3537
A vulnerability was found in Tutorials-Website Employee Management System 1.0. It has been classified as critical. This affects an unknown part of th…
Employee Management System
No fix yet
MEDIUM 5.3
CVE-2025-3282
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Obj…
User Registration \& Membership
4.1.4+
MEDIUM 6.5
CVE-2025-32373
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered u…
Dotnetnuke
9.13.8+
HIGH 8.8
CVE-2025-2526
The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.2. This is due …
Mitigation only
HIGH 7.5
CVE-2025-22931
An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to acce…
Opensis
after 9.1
MEDIUM 5.4
CVE-2025-31867
Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager js-jobs allows Exploiting Incorrectly Configured Access Cont…
Js Job Manager
after 2.0.2
MEDIUM 5.3
CVE-2024-13558
The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9…
Np Quote Request For Woocommerce
1.9.180+
MEDIUM 6.5
CVE-2024-9617
An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the…
Mitigation only
HIGH 8.8
CVE-2024-8613
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue a…
Chuanhuchatgpt
Patch available
MEDIUM 6.5
CVE-2024-12880
A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from th…
Ragflow
No fix yet
HIGH 8.8
CVE-2024-12048
An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly che…
Superagi
No fix yet
MEDIUM 5.3
CVE-2024-11167
An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts v…
Librechat
0.7.6+
MEDIUM 6.5
CVE-2024-11300
In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This i…
Lunary
1.6.3+
HIGH 7.5
CVE-2024-11137
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vu…
Lunary
1.6.1+
MEDIUM 6.5
CVE-2024-10366
An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpo…
Librechat
Patch available
MEDIUM 6.5
CVE-2024-13407
The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via the megamenu block due to in…
Omnipress
1.5.5+