Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2025-48731
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscripti…
Confluence
1.5.0+
HIGH 8.8
CVE-2025-8807
A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tia…
Tianti
after 2.3
MEDIUM 5.4
CVE-2025-8796
A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file …
Litmus
after 3.19.0
MEDIUM 5.3
CVE-2025-51308
In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only end…
Gatling
1.25.0+
HIGH 7.8
CVE-2025-41698
A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.
No fix yet
CRITICAL 9.1
CVE-2025-6205 KEVEPSS 71%
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged acces…
Delmia Apriso
2025+
HIGH 8.8
CVE-2025-6754
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect…
Mitigation only
MEDIUM 5.3
CVE-2025-8152
The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missi…
Mitigation only
HIGH 7.3
CVE-2025-8435
A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown…
Online Movie Streaming
No fix yet
HIGH 7.3
CVE-2025-8434
A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the fil…
Online Movie Streaming
No fix yet
MEDIUM 6.5
CVE-2025-53111
GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized acc…
Glpi
10.0.19+
CRITICAL 9.8
CVE-2025-46811EPSS 10%
A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any …
Mitigation only
HIGH 8.8
CVE-2025-8322
The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator function…
Mitigation only
HIGH 8.8
CVE-2025-7689
The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() …
Mitigation only
MEDIUM 5.3
CVE-2025-4370
The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls funct…
Brizy
2.6.21+
HIGH 8.3
CVE-2025-54378
HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 …
Haxcms Nodejs
11.0.9 / 11.0.14+
HIGH 7.5
CVE-2023-7306
The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete…
Mitigation only
HIGH 8.8
CVE-2025-5835
The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis…
Droip
after 2.2.0
CRITICAL 9.8
CVE-2015-10143
The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability…
Platform Theme
1.4.4+
HIGH 8.8
CVE-2025-7695
The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_li…
Mitigation only
CRITICAL 9.8
CVE-2025-6441
The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable t…
Mitigation only
CRITICAL 9.8
CVE-2025-6380
The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in v…
Mitigation only
MEDIUM 5.3
CVE-2025-6215
The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/regist…
Mitigation only
HIGH 8.8
CVE-2025-6190
The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the rp_user_profile() AJAX h…
Mitigation only
HIGH 8.8
CVE-2015-10140
The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscribe…
Ajax Load More
2.8.1.2+
CRITICAL 9.8
CVE-2025-6187
The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint in versions 1…
Mitigation only
HIGH 7.5
CVE-2025-7717
Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: from 0.0.0 before 1.9.0, from …
File Download
8.x-1.9+
MEDIUM 6.5
CVE-2025-43720
Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user ro…
Headwind Mdm
5.33.1+
MEDIUM 5.5
CVE-2025-43976
The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone ca…
2ndline
No fix yet
MEDIUM 5.5
CVE-2025-43977
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without u…
Com.skt.prod.dialer
Mitigation only