Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2025-43561EPSS 21%
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code…
Coldfusion
Mitigation only
HIGH 7.2
CVE-2025-4646
Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.0…
Centreon Web
24.04.10 / 24.10.4+
HIGH 8.8
CVE-2025-27696
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read…
Superset
4.1.2+
MEDIUM 5.5
CVE-2025-30440
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be abl…
macOS
13.7.6 / 14.7.6+
HIGH 8.8
CVE-2025-29827
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
Azure Automation
Mitigation only
HIGH 7.5
CVE-2025-26842
An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to use…
Znuny
after 7.1.3
HIGH 8.8
CVE-2025-46265
On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher priv…
F5os A
after 1.6.2
HIGH 8.1
CVE-2025-36546
On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance …
F5os A
1.5.3+
MEDIUM 6.7
CVE-2025-3272
Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager.
The vulnerability could allow authenticated users to change their pas…
Mitigation only
CRITICAL 9.4
CVE-2025-3476
Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated us…
Mitigation only
MEDIUM 5.3
CVE-2025-3609
The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to t…
Mitigation only
HIGH 8.8
CVE-2025-3879
Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the poten…
Vault
1.16.18 / 1.17.14+
HIGH 7.4
CVE-2025-46569
Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API …
Patch available
HIGH 7.8
CVE-2025-23244
NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an unprivileged attacker to escalate permissions. A successful exploit…
Mitigation only
HIGH 7.5
CVE-2025-40619
Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without…
Bookgy
Mitigation only
CRITICAL 9.8
CVE-2025-3963
A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processin…
Books Management System
No fix yet
CRITICAL 9.8
CVE-2025-3960
A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionali…
Books Management System
No fix yet
MEDIUM 5.4
CVE-2025-3861
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misc…
Mitigation only
MEDIUM 6.5
CVE-2025-46544
In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.
Sherpa Orchestrator
Mitigation only
MEDIUM 5.4
CVE-2024-10306
A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the for…
Patch available
HIGH 8.1
CVE-2025-43922
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.
Mitigation only
MEDIUM 5.5
CVE-2024-12862
Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to r…
Mitigation only
MEDIUM 6.1
CVE-2025-3838
An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the cust…
Mitigation only
MEDIUM 5.3
CVE-2025-43921
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple…
Mailman
after 2.1.39
HIGH 8.2
CVE-2025-43917
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifica…
Mitigation only
MEDIUM 6.5
CVE-2025-32796
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enabl…
Dify
after 0.6.8
MEDIUM 6.5
CVE-2024-49808
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to impro…
Sterling Connect Direct Web Services
6.1.0.28 / 6.2.0.27+
MEDIUM 5.3
CVE-2025-3453
The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and mor…
Mitigation only
MEDIUM 6.1
CVE-2025-21582
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affect…
Crm Technical Foundation
after 12.2.14
MEDIUM 5.4
CVE-2025-32068
Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawi…
Mitigation only