Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-14005
A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionality of the file /admind45f74ad…
Xunruicms
after 4.7.1
CRITICAL 9.6
CVE-2025-66222
DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the M…
Deepchat
after 0.5.0
CRITICAL 9.8
CVE-2024-32641EPSS 12%
Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code …
Masacms
7.2.8 / 7.3.13+
CRITICAL 9.8
CVE-2025-13486EPSS 74%
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_…
Mitigation only
CRITICAL 9.3
CVE-2025-13658
A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence o…
Mitigation only
HIGH 8.8
CVE-2025-66448
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a conf…
Vllm
0.11.1+
HIGH 8.8
CVE-2025-66299
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenti…
Grav
1.8.0+
HIGH 8.8
CVE-2025-66294
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authentic…
Grav
1.8.0+
HIGH 8.1
CVE-2024-39148
The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute ar…
Keros
5.12+
HIGH 7.3
CVE-2025-13792
A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stde…
Mitigation only
CRITICAL 9.8
CVE-2025-13786
A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. P…
Wtcms
after 2019-12-20
HIGH 8.8
CVE-2025-66224
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw i…
Orangehrm
5.8+
HIGH 8.8
CVE-2025-62593 KEV
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabi…
Ray
2.52.0+
HIGH 7.8
CVE-2025-33204
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cau…
Nemo
2.5.1+
HIGH 7.2
CVE-2025-64050
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to e…
Redaxo
No fix yet
CRITICAL 9.8
CVE-2025-6389EPSS 73%
The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pa…
Mitigation only
MEDIUM 5.4
CVE-2025-13577
A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Ex…
Hostel Management System
Mitigation only
CRITICAL 10.0
CVE-2025-65108
md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block…
Patch available
MEDIUM 6.1
CVE-2025-13484
A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file …
Online Beauty Parlor Management System
No fix yet
HIGH 7.3
CVE-2025-12120
Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for co…
Lite Xl
after 2.1.8
MEDIUM 5.4
CVE-2025-13450
A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipu…
Online Shop Project
No fix yet
MEDIUM 5.4
CVE-2025-13415
A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image H…
Easyimages2.0
after 2.8.6
MEDIUM 6.1
CVE-2025-13412
A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file…
Retro Basketball Shoes Online Store
No fix yet
CRITICAL 9.8
CVE-2025-65099
Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked…
Claude Code
1.0.39+
CRITICAL 9.6
CVE-2025-65026
esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Litera…
Esm.sh
136+
HIGH 8.6
CVE-2025-10702
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Acc…
Mitigation only
HIGH 8.6
CVE-2025-10703
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Acc…
Mitigation only
HIGH 8.0
CVE-2025-13035
The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's u…
Mitigation only
MEDIUM 5.4
CVE-2025-63693
The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in m…
Dzzoffice
after 2.3.7
HIGH 8.8
CVE-2025-37157
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to cond…
Arubaos Cx
10.10.1170 / 10.13.1101+