Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2025-2623
A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …
Cicadascms
No fix yet
HIGH 8.8
CVE-2025-2303
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi…
Mitigation only
MEDIUM 5.4
CVE-2025-2590
A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic. Affected is the function Up…
Human Resource Management
No fix yet
MEDIUM 6.1
CVE-2025-2583
A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php…
Simple Machines Forum
No fix yet
MEDIUM 5.4
CVE-2025-2582
A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file…
Simple Machines Forum
No fix yet
HIGH 8.8
CVE-2025-29807
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Dataverse
Mitigation only
HIGH 8.8
CVE-2025-0185
A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vuln…
Dify
No fix yet
HIGH 8.8
CVE-2024-9439
SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters…
Superagi
No fix yet
HIGH 8.4
CVE-2024-6982
A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Pytho…
Patch available
HIGH 8.8
CVE-2024-6825
BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules'…
Litellm
1.65.4+
HIGH 8.8
CVE-2024-12215
In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, …
Mitigation only
HIGH 8.8
CVE-2024-10950
In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause…
Gpt Academic
after 3.83
HIGH 8.8
CVE-2024-10954
In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided promp…
Gpt Academic
No fix yet
HIGH 7.5
CVE-2024-10572
In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGB…
H2o
No fix yet
HIGH 7.2
CVE-2024-10252
A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerabi…
Dify
after 0.9.1
CRITICAL 9.8
CVE-2024-57061
An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses c…
Mitigation only
CRITICAL 9.8
CVE-2025-29401
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploadin…
Emlog
No fix yet
MEDIUM 5.4
CVE-2025-2491
A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cm…
Ujcms
No fix yet
MEDIUM 5.4
CVE-2025-2490
A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the fi…
Ujcms
No fix yet
HIGH 8.4
CVE-2024-21760
An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versio…
Fortisoar
after 7.4.5
MEDIUM 5.4
CVE-2025-2377
A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown funct…
Vehicle Management System
No fix yet
MEDIUM 5.4
CVE-2025-2375
A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unk…
Human Metapneumovirus Testing Management System
No fix yet
MEDIUM 5.4
CVE-2025-2371
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as problematic. Affected by this issue…
Human Metapneumovirus Testing Management System
No fix yet
MEDIUM 5.4
CVE-2025-2364
A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the f…
Vblog
Mitigation only
MEDIUM 5.4
CVE-2025-2352
A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the…
Starsea Mall
Mitigation only
MEDIUM 6.5
CVE-2025-26924
Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code Injection.This issue affects Oh…
Mitigation only
HIGH 7.2
CVE-2024-54448
The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account …
Logicaldoc
9.1+
MEDIUM 5.5
CVE-2024-29409
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
Nest
No fix yet
HIGH 7.3
CVE-2025-1119
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in…
Mitigation only
CRITICAL 9.0
CVE-2025-27407
graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, …
Patch available