Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2025-5199
In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by mo…
Multipass
1.16.0+
MEDIUM 6.5
CVE-2025-6549
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attack…
Junos
21.4+
HIGH 7.3
CVE-2025-49536
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security fea…
Coldfusion
Mitigation only
CRITICAL 9.1
CVE-2025-21450
Cryptographic issue occurs due to use of insecure connection method while downloading.
Ar8035 Firmware
No fix yet
CRITICAL 9.3
CVE-2025-26850
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on manage…
Mitigation only
HIGH 8.8
CVE-2025-32462
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute co…
Sudo
1.9.17+
MEDIUM 5.4
CVE-2025-46702
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member…
Mattermost Server
9.11.16 / 10.5.6+
MEDIUM 5.4
CVE-2025-47871
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membe…
Mattermost Server
9.11.16 / 10.5.6+
CRITICAL 9.3
CVE-2025-53391
The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_a…
Patch available
MEDIUM 5.3
CVE-2025-6702
A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment…
Litemall
No fix yet
MEDIUM 5.4
CVE-2025-6707
Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administra…
MongoDB
5.0.31 / 6.0.24+
HIGH 8.8
CVE-2025-5822
Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote a…
Maxicharger Ac Elite Business C50 Firmware
1.39.51 / 1.56.51+
HIGH 8.1
CVE-2025-52890
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates n…
Patch available
HIGH 8.1
CVE-2025-48466
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs…
Wise 4060lan Firmware
No fix yet
MEDIUM 5.0
CVE-2025-52918
Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.
Mitigation only
HIGH 7.5
CVE-2025-52487
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN…
Dotnetnuke
10.0.1+
HIGH 8.8
CVE-2025-5071
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow…
Ai Engine
2.8.4+
CRITICAL 9.8
CVE-2025-49825EPSS 8%
Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 …
Mitigation only
HIGH 8.8
CVE-2025-49586
XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all us…
Xwiki
16.4.7 / 16.10.3+
MEDIUM 5.3
CVE-2025-6003
The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in…
Mitigation only
HIGH 8.8
CVE-2025-48445
Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redire…
Commerce Eurobank \(redirect\)
2.1.1+
HIGH 8.8
CVE-2025-48446
Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirec…
Commerce Alphabank Redirect
1.0.3+
HIGH 7.8
CVE-2024-7457
The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the…
Mitigation only
MEDIUM 5.5
CVE-2024-8270
The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling t…
Mitigation only
MEDIUM 6.8
CVE-2025-36578
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access…
Wyse Management Suite
5.2+
MEDIUM 6.5
CVE-2025-40567
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions <…
Mitigation only
MEDIUM 6.5
CVE-2025-40668
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of …
Gim
Mitigation only
MEDIUM 6.5
CVE-2025-40669
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each o…
Gim
Mitigation only
HIGH 8.8
CVE-2025-40670
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many priv…
Gim
Mitigation only
CRITICAL 9.1
CVE-2025-48935
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's per…
Deno
2.2.5+