Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-34159
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platf…
Coolify
4.0.0+
CRITICAL 9.8
CVE-2025-52122
Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code…
Freeform
5.10.16+
CRITICAL 9.4
CVE-2025-30056
The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on …
Mitigation only
CRITICAL 9.4
CVE-2025-30057
In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF func…
Mitigation only
CRITICAL 9.0
CVE-2025-30055
The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code pr…
Mitigation only
CRITICAL 9.4
CVE-2025-2313
In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter.
Mitigation only
HIGH 7.8
CVE-2025-23315
NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious data created by an attacker coul…
Nemo
2.4.0+
HIGH 7.8
CVE-2025-23307
NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow code injection. A successful…
Nemo Curator
25.07+
HIGH 7.8
CVE-2025-23312
NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker cou…
Nemo
2.4.0+
HIGH 7.8
CVE-2025-23313
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code…
Nemo
2.4.0+
HIGH 7.8
CVE-2025-23314
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code…
Nemo
2.4.0+
HIGH 7.5
CVE-2025-52218
SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sanitization of unspecified param…
Selectzero
2025.5.2+
HIGH 7.8
CVE-2025-53419
Delta Electronics COMMGR has Code Injection vulnerability.
No fix yet
MEDIUM 6.1
CVE-2025-9439
A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this vulnerability is an unkno…
Online Student Project Report Submission And Evaluation System
No fix yet
MEDIUM 6.1
CVE-2025-9440
A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some…
Online Student Project Report Submission And Evaluation System
No fix yet
MEDIUM 6.1
CVE-2025-9433
A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin…
Mblog
after 3.5.0
MEDIUM 6.1
CVE-2025-9434
A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects an unknown function of the fi…
Online Student Project Report Submission And Evaluation System
No fix yet
MEDIUM 6.1
CVE-2025-9438
A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected is an unknown function of th…
Online Student Project Report Submission And Evaluation System
No fix yet
MEDIUM 6.1
CVE-2025-9431
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cr…
Mblog
after 3.5.0
MEDIUM 6.1
CVE-2025-9432
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component …
Mblog
after 3.5.0
MEDIUM 5.4
CVE-2025-9429
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the compon…
Mblog
after 3.5.0
MEDIUM 5.4
CVE-2025-9422
A vulnerability was found in oitcode samarium up to 0.9.6. This impacts an unknown function of the file /dashboard/team of the component Team Image H…
Samarium
after 0.9.6
CRITICAL 9.8
CVE-2025-57772EPSS 9%
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If…
Dataease
2.10.12+
CRITICAL 9.8
CVE-2025-57773EPSS 8%
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JN…
Dataease
2.10.12+
MEDIUM 5.4
CVE-2025-9407
A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing…
Mblog
after 3.5.0
MEDIUM 5.4
CVE-2025-9404
A vulnerability was identified in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file /pointHierarchySLTS of the compone…
Scada Lts
after 2.7.8.1
MEDIUM 5.4
CVE-2025-9388
A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm. Executing manipulation of th…
Scada Lts
after 2.7.8.1
CRITICAL 10.0
CVE-2022-31491
Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to…
Mitigation only
CRITICAL 9.8
CVE-2024-52786
An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted U…
Mitigation only
HIGH 8.4
CVE-2010-20120
Maple versions up to and including 13's Maplet framework allows embedded commands to be executed automatically when a .maplet file is opened. This be…
No fix yet