Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 10.0
CVE-2025-32432 KEVEPSS 100%
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.1…
Craft Cms
3.9.15 / 4.14.15+
CRITICAL 9.8
CVE-2025-31324 KEVEPSS 100%
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma…
Netweaver
Mitigation only
MEDIUM 6.7
CVE-2025-1976 KEV
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary…
Fabric Operating System
9.1.1d7+
CRITICAL 10.0
CVE-2025-34028 KEVEPSS 98%
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand…
Commvault
11.38.20+
CRITICAL 9.8
CVE-2025-42599 KEV
Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request creat…
Active\! Mail
6.60.05008562+
CRITICAL 10.0
CVE-2025-32433 KEVEPSS 99%
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server ma…
Confd Basic
5.7.19.1 / 6.1.16.2+
CRITICAL 9.8
CVE-2025-31201 KEVEPSS 15%
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, vis…
macOS
2.4.1 / 15.4.1+
CRITICAL 9.8
CVE-2025-31200 KEVEPSS 20%
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvO…
macOS
2.4.1 / 11.5+
CRITICAL 9.8
CVE-2024-58136 KEVEPSS 85%
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wil…
Yii
2.0.52+
HIGH 7.8
CVE-2025-29824 KEVEPSS 14%
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
CRITICAL 9.8
CVE-2025-3248 KEVEPSS 100%
Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can …
Langflow
1.3.0+
CRITICAL 9.8
CVE-2025-31161 KEVEPSS 100%
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is us…
Crushftp
10.8.4 / 11.3.1+
CRITICAL 9.8
CVE-2025-30406 KEVEPSS 94%
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcod…
Centrestack
16.4.10315.56368+
CRITICAL 9.8
CVE-2025-22457 KEVEPSS 100%
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways…
Connect Secure
22.7 / 22.8+
HIGH 7.5
CVE-2025-31125 KEVEPSS 59%
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explici…
Vite
4.5.11 / 5.4.16+
HIGH 8.3
CVE-2025-2783 KEVEPSS 8%
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perfo…
Chrome
134.0.6998.177+
HIGH 7.2
CVE-2025-29635 KEVEPSS 90%
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices …
Dir 823x Firmware
Mitigation only
HIGH 7.2
CVE-2025-2749 KEV
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative …
Xperience
after 13.0.178
CRITICAL 9.8
CVE-2025-2747 KEVEPSS 92%
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for …
Xperience
after 13.0.178
CRITICAL 9.8
CVE-2025-2746 KEVEPSS 58%
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 …
Xperience
after 13.0.172
HIGH 8.6
CVE-2025-30154 KEV
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 …
Action Ast Grep
0.20.2 / 1.17.2+
HIGH 8.6
CVE-2025-30066 KEVEPSS 70%
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on…
Changed Files
after 45.0.7
MEDIUM 5.4
CVE-2025-27915 KEV
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic …
Zimbra Collaboration Suite
10.0.13 / 10.1.5+
CRITICAL 10.0
CVE-2025-24201 KEV
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and…
Safari
2.3.2 / 11.4+
HIGH 7.0
CVE-2025-26633 KEVEPSS 30%
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24993 KEV
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
MEDIUM 5.5
CVE-2025-24991 KEV
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24985 KEV
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.0
CVE-2025-24983 KEV
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
MEDIUM 5.4
CVE-2025-24054 KEVEPSS 59%
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+