Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-14962
A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file /market/chatuser.php. This ma…
Simple Stock System
No fix yet
CRITICAL 9.6
CVE-2025-66580
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS)…
Dive
0.11.1+
CRITICAL 9.8
CVE-2025-63665
An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into…
Gt Edge Ai
2.0.12+
CRITICAL 9.3
CVE-2025-34433
AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installati…
Patch available
CRITICAL 10.0
CVE-2025-65037
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
Azure Container Apps
Mitigation only
HIGH 7.2
CVE-2025-64676
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
Purview
No fix yet
HIGH 7.8
CVE-2023-53940
Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious m…
No fix yet
HIGH 8.8
CVE-2025-68278
Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing att…
Tinacms
2.0.3 / 2.0.4+
CRITICAL 9.1
CVE-2025-66078
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote …
Mitigation only
MEDIUM 6.5
CVE-2025-60070
Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This issue affects Molla: from n/a …
Mitigation only
MEDIUM 6.5
CVE-2025-60068
Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code Injection.This issue affects Ja…
Mitigation only
HIGH 8.8
CVE-2025-14856
A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/get…
Ruoyi
after 4.8.1
HIGH 7.2
CVE-2025-14837
A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Back…
Zzcms
No fix yet
CRITICAL 9.8
CVE-2025-62521
ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM'…
Churchcrm
5.21.0+
HIGH 7.2
CVE-2025-67172
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.
Ritecms
No fix yet
CRITICAL 9.9
CVE-2025-67164
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c…
Pagekit
Mitigation only
CRITICAL 9.8
CVE-2025-46295
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the t…
Filemaker Server
22.0.4+
CRITICAL 9.8
CVE-2025-37164 KEVEPSS 90%
A remote code execution issue exists in HPE OneView.
Oneview
after 10.20.00
CRITICAL 9.6
CVE-2025-67744
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerab…
Deepchat
0.5.3+
HIGH 7.8
CVE-2025-67748
Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of uns…
Fickling
0.1.6+
HIGH 7.2
CVE-2025-14729
A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_A…
Ctcms
after 2.1.2
HIGH 7.2
CVE-2025-14730
A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms…
Ctcms
after 2.1.2
HIGH 7.2
CVE-2023-53883
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page…
Webedition Cms
No fix yet
HIGH 8.8
CVE-2023-53888
Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file …
Zomplog
No fix yet
HIGH 8.8
CVE-2025-66437
An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function rend…
Erpnext
after 15.89.0
HIGH 8.8
CVE-2025-66438
A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, th…
Erpnext
after 15.89.0
HIGH 8.8
CVE-2025-66434
An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function r…
Erpnext
after 15.89.0
MEDIUM 6.1
CVE-2025-14691
A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation r…
Mayan Edms
4.10.2+
MEDIUM 5.4
CVE-2025-14662
A vulnerability was found in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php of the…
Student File Management System
No fix yet
MEDIUM 5.4
CVE-2025-14539
The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to …
Mitigation only