Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-68941
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
Gitea
1.22.3+
MEDIUM 5.3
CVE-2025-68938
Gitea before 1.25.2 mishandles authorization for deletion of releases.
Gitea
1.25.2+
HIGH 8.1
CVE-2025-15085
A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/…
Youlai Mall
Mitigation only
HIGH 7.5
CVE-2025-66378
Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams …
Pexip Infinity
39.0+
CRITICAL 9.1
CVE-2025-59683
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Lega…
Pexip Infinity
38.1+
CRITICAL 9.8
CVE-2019-25237
V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulati…
Mitigation only
HIGH 8.1
CVE-2018-25146
Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system proces…
Ipn4g Firmware
No fix yet
HIGH 7.2
CVE-2025-2515
A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a manag…
Patch available
HIGH 8.2
CVE-2025-68476
KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been ide…
Patch available
HIGH 8.1
CVE-2025-58052
Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with…
Galette
1.2.0+
HIGH 7.8
CVE-2025-47382
Memory corruption while loading an invalid firmware in boot loader.
Fastconnect 6200 Firmware
Patch available
HIGH 7.5
CVE-2025-68129
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access …
Laravel Auth0
5.5.0 / 5.6.0+
HIGH 7.8
CVE-2025-14305
ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malici…
Mitigation only
MEDIUM 5.3
CVE-2025-67740
In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
Teamcity
2025.11+
MEDIUM 5.4
CVE-2025-67490
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0…
Nextjs Auth0
Patch available
CRITICAL 9.8
CVE-2025-13184EPSS 11%
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V…
X5000r Firmware
Mitigation only
MEDIUM 5.3
CVE-2025-9056
Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation.
Audiolink
Mitigation only
MEDIUM 6.5
CVE-2025-54838
An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGat…
Fortiportal
after 7.4.5
MEDIUM 6.5
CVE-2025-66581
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side aut…
Learning
2.41.0+
HIGH 7.4
CVE-2025-66623
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.…
Strimzi
0.49.1+
MEDIUM 6.5
CVE-2025-65900
Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission v…
Kalmia
No fix yet
HIGH 8.1
CVE-2025-14016
A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/dele…
Mall Swarm
after 1.0.3
MEDIUM 5.0
CVE-2025-66406
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorizati…
Mitigation only
MEDIUM 5.4
CVE-2025-20381
In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL co…
Mitigation only
HIGH 7.5
CVE-2024-32643
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a…
Masacms
7.2.8 / 7.3.13+
HIGH 8.6
CVE-2025-13829
Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other use…
Mitigation only
HIGH 8.1
CVE-2025-13813
A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the componen…
Mogublog
after 5.2
CRITICAL 9.8
CVE-2025-13806
A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzbo…
Nutzboot
after 2.6.0
HIGH 7.1
CVE-2025-66423
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Trytond
6.0.70 / 7.0.40+
MEDIUM 6.5
CVE-2025-66424
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Trytond
6.0.70 / 7.0.40+