Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-49234
Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Ac…
Mitigation only
HIGH 8.8
CVE-2025-6105
A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.ja…
Jfinal Cms
No fix yet
MEDIUM 6.5
CVE-2025-48916
Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.…
Bookable Calendar
2.2.13+
MEDIUM 5.3
CVE-2025-5815
The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_b…
Mitigation only
HIGH 7.5
CVE-2025-5282
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing …
Wp Travel Engine
6.5.2+
CRITICAL 9.8
CVE-2025-5288
The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a mi…
Mitigation only
HIGH 8.6
CVE-2025-49181
Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET
requests to gather sensitive information. An attacker could als…
Media Server
Mitigation only
MEDIUM 5.3
CVE-2025-48444
Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.
Quick Node Block
Mitigation only
MEDIUM 5.3
CVE-2025-48013
Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.
Quick Node Block
Mitigation only
HIGH 8.3
CVE-2025-29756
SunGrow's back end users system iSolarCloud https://isolarcloud.com uses an MQTT service to transport data from the user's connected devices to the…
Mitigation only
MEDIUM 5.6
CVE-2025-1055
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL reque…
Mitigation only
MEDIUM 5.3
CVE-2025-27505
GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security and ac…
Geoserver
2.25.6 / 2.26.3+
MEDIUM 5.3
CVE-2025-49509
Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting Incorrectly Configured Access…
Mitigation only
CRITICAL 9.6
CVE-2025-42989
RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successfu…
Mitigation only
MEDIUM 6.7
CVE-2025-42993
Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Confi…
Mitigation only
HIGH 8.8
CVE-2025-42982
SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system creden…
Mitigation only
HIGH 8.5
CVE-2025-42983
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss …
Mitigation only
MEDIUM 5.4
CVE-2025-42984
SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker coul…
Mitigation only
HIGH 7.1
CVE-2025-5900
A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cro…
Ac9 Firmware
No fix yet
MEDIUM 6.5
CVE-2025-5888
A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionalit…
Webstack Guns
No fix yet
HIGH 8.1
CVE-2025-49651
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in…
Mitigation only
HIGH 7.5
CVE-2025-49265
Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Co…
Mitigation only
MEDIUM 6.5
CVE-2025-48147
Missing Authorization vulnerability in Crypto Cloud CryptoCloud - Crypto Payment Gateway cryptocloud-crypto-payment-gateway allows Exploiting Incorre…
Mitigation only
MEDIUM 6.5
CVE-2025-48139
Missing Authorization vulnerability in relentlo StyleAI relentlosoftware allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…
Mitigation only
HIGH 7.1
CVE-2025-47527
Missing Authorization vulnerability in Icegram Icegram Collect icegram-rainmaker allows Exploiting Incorrectly Configured Access Control Security Lev…
Mitigation only
HIGH 7.1
CVE-2025-47463
Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Co…
Mitigation only
HIGH 7.6
CVE-2025-32308
Missing Authorization vulnerability in looks_awesome Team Builder a-team-showcase allows Exploiting Incorrectly Configured Access Control Security Le…
Mitigation only
HIGH 8.8
CVE-2025-5894
Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges …
Mitigation only
HIGH 8.8
CVE-2025-47601
Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a…
Mitigation only
MEDIUM 5.3
CVE-2025-5814
The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on…
Mitigation only