Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2025-4324
A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file /admin/link/edit.do of the c…
Mrcms
No fix yet
MEDIUM 5.4
CVE-2025-4323
A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unknown functionality of the comp…
Mrcms
No fix yet
HIGH 7.3
CVE-2025-2802
The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.3.1. This is due to the so…
Mitigation only
MEDIUM 5.4
CVE-2025-4292
A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /…
Mrcms
No fix yet
MEDIUM 5.4
CVE-2025-4293
A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group…
Mrcms
No fix yet
CRITICAL 9.8
CVE-2025-44071
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attacker…
Seacms
No fix yet
CRITICAL 9.8
CVE-2025-43845
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. T…
Retrieval Based Voice Conversion Webui
after 2.2.231006
CRITICAL 9.1
CVE-2025-24977
OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute…
Opencti
6.4.11+
MEDIUM 5.3
CVE-2025-4261
A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as critical. This affects the fu…
Mitigation only
MEDIUM 6.1
CVE-2025-4257
A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pa…
Seacms
No fix yet
MEDIUM 5.4
CVE-2025-4256
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipu…
Seacms
No fix yet
HIGH 7.3
CVE-2024-13738
The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…
Mitigation only
HIGH 7.8
CVE-2025-4218
A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulnerability is the function GPTS…
Browserpilot
after 0.2.51
CRITICAL 9.8
CVE-2025-2421
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection.
This issue affects S…
Sambabox
5.1+
HIGH 7.4
CVE-2025-46569
Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API …
Patch available
CRITICAL 9.8
CVE-2025-45947
An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the …
Online Banquet Booking System
No fix yet
CRITICAL 9.8
CVE-2024-32499
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
Project Center
after 2023.3.0.32259
CRITICAL 9.8
CVE-2023-42404
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
Workspace
Mitigation only
HIGH 8.8
CVE-2015-2079
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argume…
Usermin
1.660+
HIGH 8.8
CVE-2025-4022
A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentE…
Webarena
after 0.2.0
CRITICAL 9.8
CVE-2025-46661
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template ex…
Metazo
after 8.1.13
MEDIUM 5.4
CVE-2025-4000
A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function …
Oa Web Application System
Mitigation only
MEDIUM 5.4
CVE-2025-3999
A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unk…
Oa Web Application System
Mitigation only
HIGH 7.5
CVE-2025-3984
A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\we…
Central Authentication Service
Mitigation only
HIGH 8.8
CVE-2025-3982
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sve…
Sverchok
No fix yet
MEDIUM 5.4
CVE-2025-3970
A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. Th…
Jsite
after 1.0
MEDIUM 5.4
CVE-2025-3965
A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality …
Paicoding
No fix yet
HIGH 7.8
CVE-2025-46579
There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users d…
Zxcloud Goldendb
6.1.03.11+
MEDIUM 6.5
CVE-2024-13812
The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.1.1. This is du…
Mitigation only
HIGH 7.2
CVE-2025-3491
The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and inc…
Mitigation only