Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2025-60710 KEV
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges …
Windows 11 24h2
10.0.26100.7392 / 10.0.26200.7392+
CRITICAL 9.1
CVE-2025-12480 KEVEPSS 91%
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after se…
Triofox
16.7.10368.56560+
HIGH 7.2
CVE-2025-64328 KEVEPSS 85%
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestor…
Filestore
17.0.3+
HIGH 8.8
CVE-2023-43000 KEV
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.…
Safari
13.5 / 15.8.7+
CRITICAL 9.8
CVE-2025-11953 KEVEPSS 94%
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpo…
React Native Community Cli
19.1.2+
CRITICAL 9.8
CVE-2025-61757 KEVEPSS 88%
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12…
Identity Manager
Mitigation only
CRITICAL 9.8
CVE-2025-61932 KEV
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing …
Lanscope Endpoint Manager
9.3.2.7 / 9.3.3.9+
CRITICAL 9.8
CVE-2025-53521 KEV
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Note: Softw…
Big Ip Access Policy Manager
15.1.10.8 / 16.1.6.1+
CRITICAL 9.8
CVE-2025-59287 KEVEPSS 100%
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Windows Server 2012
10.0.14393.8524 / 10.0.17763.7922+
HIGH 7.8
CVE-2025-59230 KEV
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-24990 KEVEPSS 6%
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an…
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.5
CVE-2025-61884 KEVEPSS 98%
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3…
Configurator
after 12.2.14
HIGH 7.5
CVE-2025-11371 KEVEPSS 92%
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows …
Centrestack
16.10.10408.56683+
CRITICAL 9.8
CVE-2025-61882 KEVEPSS 100%
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that …
Concurrent Processing
after 12.2.14
HIGH 7.8
CVE-2025-41244 KEVEPSS 8%
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privilege…
Aria Operations
5.0.1 / 8.18.5+
HIGH 8.6
CVE-2025-20362 KEVEPSS 87%
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Softwar…
Adaptive Security Appliance Software
7.0.8.1 / 7.2.10.2+
CRITICAL 9.9
CVE-2025-20333 KEVEPSS 40%
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (F…
Adaptive Security Appliance Software
7.0.8.1 / 7.2.9+
HIGH 7.7
CVE-2025-20352 KEVEPSS 39%
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:…
Ios Xe Sd Wan
Mitigation only
CRITICAL 9.8
CVE-2025-10585 KEVEPSS 5%
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…
Chrome
140.0.7339.185+
CRITICAL 9.8
CVE-2025-26399 KEVEPSS 88%
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exp…
Web Help Desk
after 12.8.6
MEDIUM 6.1
CVE-2025-59689 KEV
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.…
Email Security Gateway
5.0.31 / 5.1.20+
CRITICAL 9.0
CVE-2025-48703 KEVEPSS 100%
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_tota…
Webpanel
0.9.8.1205+
CRITICAL 9.8
CVE-2025-10035 KEVEPSS 100%
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…
Goanywhere Managed File Transfer
7.6.3 / 7.8.4+
CRITICAL 9.8
CVE-2025-9242 KEVEPSS 91%
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code…
Fireware
12.5.13 / 12.11.4+
CRITICAL 9.8
CVE-2025-21043 KEV
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
Android
Mitigation only
CRITICAL 9.8
CVE-2025-21042 KEVEPSS 33%
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
Android
Mitigation only
CRITICAL 9.1
CVE-2025-54236 KEVEPSS 95%
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vu…
Commerce
Mitigation only
HIGH 8.8
CVE-2025-48543 KEV
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to l…
Android
Patch available
CRITICAL 9.0
CVE-2025-53690 KEVEPSS 31%
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This iss…
Experience Commerce
after 9.0
HIGH 7.2
CVE-2025-9377 KEVEPSS 12%
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) …
Tl Wr841n Firmware
241108+