Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2025-6218 KEVEPSS 89%
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…
Winrar
7.12+
HIGH 7.5
CVE-2025-5777 KEVEPSS 100%
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Prox…
Netscaler Application Delivery Controller
12.1-55.328 / 13.1-37.235+
HIGH 8.8
CVE-2025-33073 KEVEPSS 80%
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 8.8
CVE-2025-33053 KEVEPSS 85%
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 8.6
CVE-2025-21479 KEV
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Aqt1000 Firmware
No fix yet
HIGH 7.5
CVE-2025-27038 KEV
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
Ar8031 Firmware
Mitigation only
HIGH 8.6
CVE-2025-21480 KEV
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Aqt1000 Firmware
Mitigation only
HIGH 8.8
CVE-2025-5419 KEVEPSS 8%
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a cra…
Chrome
137.0.3296.62 / 137.0.7151.68+
CRITICAL 9.0
CVE-2025-5086 KEVEPSS 90%
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code executio…
Delmia Apriso
after 2025
HIGH 8.8
CVE-2025-49113 KEVEPSS 98%
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n…
Debian Linux
1.5.10 / 1.6.11+
MEDIUM 5.3
CVE-2025-48927 KEVEPSS 9%
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the…
Telemessage
Mitigation only
HIGH 7.5
CVE-2025-34026 KEVEPSS 83%
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at at…
Concerto
12.1.2+
HIGH 8.8
CVE-2025-4008 KEVEPSS 94%
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system thro…
Meteobridge Vm
6.2+
HIGH 7.8
CVE-2025-32709 KEV
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-32706 KEV
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-32701 KEV
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-30400 KEV
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7314 / 10.0.19044.5854+
HIGH 7.5
CVE-2025-30397 KEVEPSS 27%
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a ne…
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 8.8
CVE-2025-4428 KEVEPSS 86%
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t…
Endpoint Manager Mobile
11.12.0.5 / 12.3.0.2+
HIGH 7.5
CVE-2025-4427 KEVEPSS 100%
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources wit…
Endpoint Manager Mobile
11.12.0.5 / 12.3.0.2+
CRITICAL 9.8
CVE-2025-32756 KEVEPSS 30%
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiC…
Fortimail
6.4.6 / 6.4.11+
CRITICAL 9.8
CVE-2025-4632 KEVEPSS 24%
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to wr…
Magicinfo 9 Server
21.1052.0+
CRITICAL 9.1
CVE-2025-42999 KEVEPSS 12%
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ…
Netweaver
Mitigation only
MEDIUM 5.3
CVE-2025-35939 KEV
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an…
Craft Cms
4.15.3 / 5.7.5+
CRITICAL 9.8
CVE-2025-2776 KEVEPSS 64%
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing function…
Sysaid
after 23.3.40
HIGH 7.5
CVE-2025-2775 KEVEPSS 43%
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionali…
Sysaid
after 23.3.40
HIGH 8.8
CVE-2025-27920 KEV
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in paramete…
Output Messenger
2.0.63+
HIGH 7.2
CVE-2025-3935 KEV
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preser…
Screenconnect
25.2.4+
HIGH 8.8
CVE-2025-3928 KEV
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory:…
Commvault
11.20.217 / 11.28.141+
CRITICAL 10.0
CVE-2025-32432 KEVEPSS 100%
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.1…
Craft Cms
3.9.15 / 4.14.15+