Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.0
CVE-2025-26330
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local a…
Powerscale Onefs
after 9.10.1.1
MEDIUM 6.5
CVE-2025-3475
Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoo…
Web T
1.1.0+
HIGH 7.5
CVE-2025-31481
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured secu…
Patch available
CRITICAL 9.1
CVE-2024-38392
Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the ap…
Mitigation only
CRITICAL 9.8
CVE-2025-24233
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.…
macOS
13.7.5 / 14.7.5+
HIGH 7.5
CVE-2025-24221
This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, visionOS 2.4. Sensiti…
Ipados
2.4 / 17.7.6+
MEDIUM 5.3
CVE-2025-30209
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or info…
Tuleap
16.4-10 / 16.5-6+
HIGH 8.1
CVE-2025-30093
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass auth…
Htcondor
23.0.22 / 23.10.22+
HIGH 8.8
CVE-2025-2242
An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 1…
GitLab
17.8.6 / 17.9.3+
MEDIUM 6.5
CVE-2024-55965
An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (spe…
Appsmith
1.51+
CRITICAL 9.1
CVE-2025-29927EPSS 99%
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and …
Next.js
12.3.5 / 13.5.9+
MEDIUM 6.5
CVE-2025-30179
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attac…
Mattermost Server
9.11.9 / 10.3.4+
HIGH 8.8
CVE-2025-25274
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authen…
Mattermost Server
9.11.9 / 10.3.4+
HIGH 7.8
CVE-2024-44305
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges.
macOS
14.6+
CRITICAL 9.8
CVE-2025-26853
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
Infocad
3.5.2.0+
MEDIUM 6.5
CVE-2024-9159
An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the s…
Chuanhuchatgpt
No fix yet
MEDIUM 6.1
CVE-2024-9098
In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, …
Lunary
1.4.30+
MEDIUM 6.7
CVE-2024-7039
In open-webui/open-webui version v0.3.8, there is an improper privilege management vulnerability. The application allows an attacker, acting as an ad…
Open Webui
No fix yet
HIGH 7.3
CVE-2024-10275
In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change…
Lunary
1.5.7+
MEDIUM 6.5
CVE-2024-10273
In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The …
Lunary
1.5.7+
HIGH 8.3
CVE-2024-10109
A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "…
Anythingllm
1.3.1+
HIGH 7.5
CVE-2025-29924
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private informatio…
Xwiki
15.10.14 / 16.4.6+
MEDIUM 6.9
CVE-2025-2202
Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to …
Mitigation only
MEDIUM 6.9
CVE-2025-2201
Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive in…
Mitigation only
HIGH 7.8
CVE-2025-30074
Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation ro…
Mitigation only
CRITICAL 9.8
CVE-2025-27138
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the i…
Dataease
2.10.6+
HIGH 8.2
CVE-2025-29997
This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated remote a…
Mitigation only
MEDIUM 6.5
CVE-2025-0652
An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, …
GitLab
17.7.7 / 17.8.5+
MEDIUM 6.4
CVE-2025-27602
Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1…
Umbraco Cms
10.8.9 / 13.7.1+
HIGH 7.8
CVE-2024-45328
An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated …
Fortisandbox
4.4.7+