Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2025-66376 KEVEPSS 22%
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives…
Zimbra Collaboration Suite
10.0.18 / 10.1.13+
CRITICAL 10.0
CVE-2025-52691 KEVEPSS 85%
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, po…
Smartermail
100.0.9413+
HIGH 8.8
CVE-2025-68645 KEVEPSS 32%
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling …
Zimbra Collaboration Suite
10.0.18 / 10.1.13+
HIGH 8.8
CVE-2025-68613 KEVEPSS 98%
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remo…
N8n
1.120.4+
HIGH 7.5
CVE-2025-14847 KEVEPSS 83%
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue a…
MongoDB
4.4.30 / 5.0.32+
CRITICAL 9.8
CVE-2025-14733 KEVEPSS 27%
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code…
Fireware
12.5.15 / 12.11.6+
MEDIUM 6.6
CVE-2025-40602 KEV
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Sma6200 Firmware
12.4.3-03245 / 12.5.0-02283+
MEDIUM 6.1
CVE-2025-68461 KEVEPSS 21%
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
Webmail
1.5.12 / 1.6.12+
HIGH 8.8
CVE-2025-43529 KEVEPSS 9%
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and …
Safari
18.7.3 / 26.2+
CRITICAL 10.0
CVE-2025-20393 KEVEPSS 30%
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could …
Asyncos
15.0.2-007 / 15.0.5-016+
CRITICAL 9.8
CVE-2025-59374 KEV
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a sup…
Live Update
3.6.8+
CRITICAL 9.8
CVE-2025-37164 KEVEPSS 90%
A remote code execution issue exists in HPE OneView.
Oneview
after 10.20.00
MEDIUM 5.5
CVE-2025-43520 KEV
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1,…
Ipados
14.8.2 / 15.7.2+
HIGH 7.8
CVE-2025-43510 KEV
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 2…
Ipados
14.8.2 / 15.7.2+
CRITICAL 9.8
CVE-2025-14611 KEVEPSS 53%
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degr…
Centrestack
16.12.10420.56791+
HIGH 8.8
CVE-2025-14174 KEVEPSS 23%
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access…
Chrome
18.7.3 / 26.2+
HIGH 8.8
CVE-2025-8110 KEVEPSS 83%
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Gogs
after 0.13.3
HIGH 7.8
CVE-2025-62221 KEV
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8146 / 10.0.19044.6691+
CRITICAL 9.8
CVE-2025-59718 KEVEPSS 63%
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 …
Fortiproxy
7.0.6 / 7.0.18+
MEDIUM 5.5
CVE-2025-48633 KEV
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in …
Android
Patch available
HIGH 7.8
CVE-2025-48572 KEV
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalat…
Android
Mitigation only
HIGH 8.8
CVE-2025-34291 KEVEPSS 84%
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permis…
Langflow
after 1.6.9
CRITICAL 9.8
CVE-2025-66644 KEV
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Arrayos Ag
9.4.5.9+
CRITICAL 10.0
CVE-2025-55182 KEVEPSS 100%
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the …
React
15.0.5 / 15.1.9+
HIGH 8.8
CVE-2025-62593 KEV
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabi…
Ray
Patch available
CRITICAL 9.8
CVE-2025-58360 KEVEPSS 65%
GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XM…
Geoserver
2.25.6 / 2.26.2+
HIGH 7.2
CVE-2025-58034 KEVEPSS 56%
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiW…
Fortiweb
7.0.12 / 7.2.12+
HIGH 8.8
CVE-2025-13223 KEVEPSS 5%
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…
Chrome
142.0.7444.175+
CRITICAL 9.8
CVE-2025-64446 KEVEPSS 92%
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWe…
Fortiweb
7.0.12 / 7.2.12+
HIGH 7.0
CVE-2025-62215 KEVEPSS 6%
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat…
Windows 10 1809
10.0.17763.8027 / 10.0.19044.6575+