Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2025-23349
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code inje…
Megatron Lm
0.12.3+
HIGH 7.2
CVE-2025-5717
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor a…
Api Control Plane
Mitigation only
CRITICAL 9.8
CVE-2025-9321
The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input valida…
Mitigation only
MEDIUM 5.4
CVE-2025-10837
A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerability is an unknown functionali…
Simple Food Ordering System
Mitigation only
MEDIUM 6.1
CVE-2025-10827
A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /previ…
Restaurant Menu Maker
No fix yet
CRITICAL 10.0
CVE-2025-59528EPSS 91%
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execu…
Flowise
Mitigation only
MEDIUM 5.4
CVE-2025-58673
Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue …
Mitigation only
HIGH 8.8
CVE-2025-57439
Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An authenticated attacke…
Creabox Manager
No fix yet
MEDIUM 6.1
CVE-2025-10794
A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the file /carrental/search.php. E…
Car Rental Project
No fix yet
HIGH 8.8
CVE-2025-54815
Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.
Ppress
No fix yet
CRITICAL 9.1
CVE-2025-57644
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can exe…
Automation Platform
Mitigation only
MEDIUM 5.4
CVE-2025-10632
A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file ava…
Online Petshop Management System
No fix yet
MEDIUM 5.4
CVE-2025-10631
A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the co…
Online Petshop Management System
No fix yet
MEDIUM 6.1
CVE-2025-10614
A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of…
E Logbook With Health Monitoring System For Covid 19
No fix yet
CRITICAL 9.0
CVE-2025-58766
Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows att…
Patch available
MEDIUM 6.1
CVE-2025-10605
A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. …
I Educar
after 2.10.0
MEDIUM 6.1
CVE-2025-10606
A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/Configu…
I Educar
after 2.10.0
MEDIUM 6.1
CVE-2025-10590
A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuar…
I Educar
after 2.10.0
MEDIUM 5.4
CVE-2025-10591
A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_funcao_cad.php of the…
I Educar
after 2.10.0
HIGH 8.8
CVE-2025-10057
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includ…
Mitigation only
MEDIUM 5.4
CVE-2025-10584
A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_calendario_anotacao_ca…
I Educar
after 2.10.0
MEDIUM 6.1
CVE-2025-10566
A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file …
Grocery Sales And Inventory System
No fix yet
CRITICAL 10.0
CVE-2025-41243
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification.
An application should be considered vulnerable wh…
Mitigation only
MEDIUM 6.1
CVE-2025-10411
A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of …
E Logbook With Health Monitoring System For Covid 19
No fix yet
HIGH 7.2
CVE-2025-10394
A vulnerability has been found in fcba_zzm ics-park Smart Park Management System 2.0. Affected is an unknown function of the file ruoyi-quartz/src/ma…
Smart Park Management System
No fix yet
MEDIUM 6.1
CVE-2025-10373
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /intranet/educa…
I Educar
after 2.10.0
MEDIUM 5.4
CVE-2025-10372
A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_modulo_cad.php. This m…
I Educar
after 2.10.0
MEDIUM 6.1
CVE-2025-10369
A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdocs/cardRegisterNew.php. Execut…
Rpi Jukebox Rfid
after 2.8.0
MEDIUM 5.4
CVE-2025-10370
A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php.…
Rpi Jukebox Rfid
after 2.8.0
MEDIUM 6.1
CVE-2025-10368
A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/manageFi…
Rpi Jukebox Rfid
after 2.8.0