Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2025-47563
Missing Authorization vulnerability in villatheme CURCY woocommerce-multi-currency allows Accessing Functionality Not Properly Constrained by ACLs.Th…
Mitigation only
MEDIUM 5.3
CVE-2025-47564
Missing Authorization vulnerability in ashanjay EventON eventon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ev…
Mitigation only
MEDIUM 5.4
CVE-2025-47556
Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Exploiting Incorre…
Mitigation only
HIGH 8.8
CVE-2025-39482
Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…
Eventer
after 3.9.6
HIGH 8.8
CVE-2025-39493
Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Access Control Security Levels.Th…
Rankie
1.8.2+
MEDIUM 5.3
CVE-2025-32296
Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Co…
Mitigation only
MEDIUM 5.4
CVE-2025-31923
Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Exploiting Incorrectly Configured Access Con…
Mitigation only
MEDIUM 5.3
CVE-2025-31071
Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Configured Access Control Securi…
Mitigation only
MEDIUM 5.3
CVE-2025-31630
Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affe…
Mitigation only
MEDIUM 5.3
CVE-2025-31065
Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects R…
No fix yet
MEDIUM 5.3
CVE-2025-31066
Missing Authorization vulnerability in themeton Acerola acerola allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…
Mitigation only
MEDIUM 6.1
CVE-2025-47792
Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed o…
Desktop
3.15.0+
HIGH 7.5
CVE-2024-12812
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDO…
Wp Erp
1.13.4+
MEDIUM 5.3
CVE-2024-56006
Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a before 2.0.1.
Mitigation only
CRITICAL 9.8
CVE-2025-47580
Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Securi…
Front End Users
after 3.2.32
HIGH 8.1
CVE-2024-58101
Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequenc…
Mitigation only
MEDIUM 6.5
CVE-2025-47709
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Dr…
Miniorange 2fa
5.2.0 / 8.x-4.7+
MEDIUM 5.0
CVE-2025-24021
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set valu…
Itop
2.7.12 / 3.1.3+
HIGH 8.6
CVE-2025-4430
Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (publishe…
Mitigation only
HIGH 7.7
CVE-2025-43011
Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated…
Mitigation only
MEDIUM 5.3
CVE-2025-43004
Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enable outside users to access cus…
Mitigation only
MEDIUM 6.3
CVE-2025-43007
SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privil…
Mitigation only
MEDIUM 5.8
CVE-2025-43008
Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of emplo…
Mitigation only
MEDIUM 6.3
CVE-2025-43009
SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privil…
Mitigation only
HIGH 7.9
CVE-2025-43000
Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High…
Mitigation only
CRITICAL 9.1
CVE-2025-30448
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macO…
Ipados
2.5 / 13.7.6+
MEDIUM 6.5
CVE-2025-46745
An authenticated user without user-management permissions could view other users account information.
Mitigation only
CRITICAL 9.8
CVE-2025-26846
An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.
Znuny
after 7.1.3
HIGH 8.8
CVE-2025-3876
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in…
Sms Alert Order Notifications
3.8.2+
HIGH 8.8
CVE-2025-28202
Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.
Rx1800 Firmware
No fix yet