Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-8992
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site…
Mblog
after 3.5.0
MEDIUM 6.5
CVE-2025-55712
Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Exp…
Mitigation only
MEDIUM 5.3
CVE-2025-54739
Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorrectly Configured Access Contro…
Mitigation only
MEDIUM 5.3
CVE-2025-54730
Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews embedder-for-google-reviews allows Accessing Functionality Not Prop…
Mitigation only
MEDIUM 5.4
CVE-2025-54717
Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.…
Mitigation only
MEDIUM 6.5
CVE-2025-20301
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to a…
Secure Firewall Management Center
Mitigation only
MEDIUM 5.4
CVE-2025-54695
Missing Authorization vulnerability in DevItems HT Mega ht-mega-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels…
Mitigation only
HIGH 7.5
CVE-2025-54692
Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Co…
Mitigation only
HIGH 7.5
CVE-2025-54679
Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free allows Exploiting Incorrectly…
Mitigation only
HIGH 7.3
CVE-2025-52801
Missing Authorization vulnerability in VonStroheim TheBooking thebooking allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…
Mitigation only
HIGH 7.1
CVE-2025-52775
Missing Authorization vulnerability in Ronik@UnlimitedWP Project Cost Calculator project-cost-calculator allows Exploiting Incorrectly Configured Acc…
Mitigation only
HIGH 7.1
CVE-2025-52785
Missing Authorization vulnerability in softnwords SMM API smm-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …
Mitigation only
HIGH 7.3
CVE-2025-52800
Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Accessing Functionality Not Properly Con…
Mitigation only
MEDIUM 6.5
CVE-2025-52721
Missing Authorization vulnerability in LCweb Global Gallery allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affec…
Mitigation only
HIGH 7.5
CVE-2025-52731
Missing Authorization vulnerability in themefunction WordPress Event Manager, Event Calendar and Booking Plugin eventin-pro allows Exploiting Incorre…
Mitigation only
MEDIUM 6.5
CVE-2025-50029
Missing Authorization vulnerability in Ashish AI Tools artificial-intelligence-auto-content-generator allows Exploiting Incorrectly Configured Access…
Mitigation only
MEDIUM 6.5
CVE-2025-50031
Missing Authorization vulnerability in syedamirhussain91 DB Backup db-backup allows Exploiting Incorrectly Configured Access Control Security Levels.…
Mitigation only
HIGH 7.5
CVE-2025-31425
Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Exploiting Incorrectly Configured Access Control Secur…
Mitigation only
HIGH 7.5
CVE-2025-30639
Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.Th…
Mitigation only
MEDIUM 6.5
CVE-2025-30993
Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Exploiting Incorrect…
Mitigation only
MEDIUM 6.5
CVE-2025-28962
Missing Authorization vulnerability in stefanoai Advanced Google Universal Analytics advanced-google-universal-analytics allows Exploiting Incorrectl…
Mitigation only
CRITICAL 9.8
CVE-2025-8943EPSS 72%
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inh…
Flowise
3.0.1+
CRITICAL 9.1
CVE-2025-50171
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
Windows Server 2022
10.0.20348.3989 / 10.0.25398.1791+
HIGH 8.8
CVE-2025-8310
Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attack…
Virtual Application Delivery Controller
22.9+
HIGH 8.8
CVE-2025-8418
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all versions up to, and including,…
Mitigation only
MEDIUM 5.3
CVE-2025-47444
Missing Authorization vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Exploiting Incorrectly Configured Access Control Sec…
Mitigation only
HIGH 7.5
CVE-2025-6253
The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inclu…
Mitigation only
CRITICAL 9.8
CVE-2025-8059
The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_re…
Mitigation only
MEDIUM 5.3
CVE-2025-8285
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscriptio…
Confluence
1.5.0+
MEDIUM 5.0
CVE-2025-54458
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscrip…
Confluence
1.5.0+