Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.7
CVE-2025-11060
A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthor…
Patch available
MEDIUM 5.4
CVE-2025-59824
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escap…
Omni
0.48.0+
HIGH 7.5
CVE-2025-59420
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that dec…
Authlib
1.6.4+
HIGH 8.8
CVE-2025-10016
The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can reque…
Mitigation only
MEDIUM 5.4
CVE-2025-31254
This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web con…
Safari
26.0+
MEDIUM 5.3
CVE-2025-59376
feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g.,…
Mcp Kubernetes Server
after 0.1.11
MEDIUM 5.3
CVE-2025-43789
JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi …
Digital Experience Platform
7.4.3.120 / 2024.Q1.10+
MEDIUM 6.5
CVE-2025-43784
Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024…
Digital Experience Platform
7.4.3.125 / 2024.Q1.13+
MEDIUM 6.5
CVE-2025-54246
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security featu…
Experience Manager
after 2025.8.0
HIGH 7.1
CVE-2025-48042
Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability …
Patch available
HIGH 7.8
CVE-2025-48523
In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could le…
Android
Patch available
HIGH 7.8
CVE-2025-32333
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to lo…
Android
Patch available
MEDIUM 5.5
CVE-2025-26442
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic…
Android
Patch available
HIGH 7.8
CVE-2025-26436
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due t…
Android
Patch available
MEDIUM 6.3
CVE-2025-23262
NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modi…
Mitigation only
HIGH 8.7
CVE-2025-23256
NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to mod…
Mitigation only
HIGH 7.8
CVE-2025-22428
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the pr…
Android
Mitigation only
HIGH 7.5
CVE-2025-7974
rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio…
Rocket.chat
7.4.4 / 7.5.3+
MEDIUM 6.9
CVE-2025-41030
Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain information from other users via GET …
Mitigation only
MEDIUM 6.9
CVE-2025-41031
Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other users' profile pictures via a P…
Mitigation only
HIGH 7.2
CVE-2025-3586
In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10…
Digital Experience Platform
7.4.3.43+
MEDIUM 5.3
CVE-2025-54877
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions befor…
Tuleap
16.9-8 / 16.10-5+
MEDIUM 5.4
CVE-2025-55177 KEV
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, a…
Whatsapp
2.25.21.73 / 2.25.21.78+
MEDIUM 6.5
CVE-2025-9602
A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation result…
Rockoa
after 2.6.9
MEDIUM 6.5
CVE-2025-25010
Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access a…
Kibana
9.0.6 / 9.1.3+
MEDIUM 6.5
CVE-2025-9376
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data …
Mitigation only
MEDIUM 6.7
CVE-2025-5187
A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object…
Mitigation only
CRITICAL 9.1
CVE-2025-36157
IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to upda…
Jazz Foundation
Patch available
MEDIUM 6.5
CVE-2025-57728
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
Intellij Idea
2025.2+
CRITICAL 9.8
CVE-2025-55213
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1…
Helm Charts
0.2.42 / 1.9.5+