Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.0
CVE-2025-32973
XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to …
Xwiki
15.10.12 / 16.4.3+
MEDIUM 5.4
CVE-2025-3953
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to…
Mitigation only
CRITICAL 9.8
CVE-2025-46348
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authen…
Yeswiki
4.5.4+
MEDIUM 5.3
CVE-2025-4064
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file …
Online Traveling System
Mitigation only
MEDIUM 5.3
CVE-2025-39367
Missing Authorization vulnerability in SeventhQueen Kleo kleo.This issue affects Kleo: from n/a through < 5.4.4.
No fix yet
MEDIUM 5.3
CVE-2025-3981
A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. T…
Internet Doctor Workstation System
No fix yet
MEDIUM 6.5
CVE-2025-3979
A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-aja…
Lecms
No fix yet
MEDIUM 5.3
CVE-2025-3980
A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability…
Internet Doctor Workstation System
No fix yet
CRITICAL 9.8
CVE-2025-3963
A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processin…
Books Management System
No fix yet
CRITICAL 9.8
CVE-2025-3960
A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionali…
Books Management System
No fix yet
HIGH 8.8
CVE-2025-3906
The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on…
Mitigation only
HIGH 7.6
CVE-2025-43862
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even thou…
Dify
0.6.12+
MEDIUM 5.3
CVE-2025-32045
A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to…
Moodle
4.1.17 / 4.3.11+
MEDIUM 5.3
CVE-2025-3912
The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing …
Mitigation only
HIGH 8.8
CVE-2025-1279
The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing…
Mitigation only
MEDIUM 5.4
CVE-2025-46535
Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Secu…
No fix yet
MEDIUM 5.3
CVE-2025-46485
Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Accessing Functionality Not Properly Cons…
Mitigation only
MEDIUM 5.3
CVE-2025-46489
Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Func…
Mitigation only
MEDIUM 5.3
CVE-2025-39390
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Function…
Mitigation only
HIGH 7.5
CVE-2021-47662
Due to missing authorization an unauthenticated remote attacker can cause a DoS attack by connecting via HTTPS and triggering the shutdown button.
Mitigation only
CRITICAL 9.8
CVE-2025-3604
The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This i…
Flynax Bridge
after 2.2.0
HIGH 8.8
CVE-2025-3058
The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing cap…
Mitigation only
MEDIUM 5.3
CVE-2024-13307
The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capabili…
Mitigation only
HIGH 7.5
CVE-2025-1021
Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows re…
Diskstation Manager
7.1.1-42962-8 / 7.2.1-69057-7+
CRITICAL 9.8
CVE-2025-37087
A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the …
Mitigation only
CRITICAL 9.8
CVE-2025-46247
Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Proper…
Appointment Booking Calendar
1.3.93+
CRITICAL 9.8
CVE-2025-46244
Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured …
Advanced Linked Variations For Woocommerce
1.0.4+
HIGH 8.8
CVE-2025-46232
Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Lev…
Alt Text Ai
1.9.94+
MEDIUM 6.5
CVE-2025-3843
A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to…
Ds Java
No fix yet
MEDIUM 6.4
CVE-2025-28103
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
Flaskblog
Mitigation only