Top technology
Linux 13159
Google 12756
Microsoft 12402
Oracle 7453
Apple 6698
Ibm 6481
Adobe 6427
Cisco 5768
Debian 3920
Apache 2925
Mozilla 2920
Redhat 2626
CRITICAL 9.9
CVE-2025-30996
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Fol…
Mitigation only
CRITICAL 9.8
CVE-2025-14942
wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or tr…
Wolfssh
1.4.22+
CRITICAL 9.8
CVE-2025-60534
Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order t…
Cobalt X1
Mitigation only
CRITICAL 9.8
CVE-2025-39477
Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…
Mitigation only
CRITICAL 9.8
CVE-2026-0640
A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation…
Ac23 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-65212
An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie ver…
Hy511 Firmware
2.1+
CRITICAL 9.8
CVE-2025-60262
An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability …
Mc102 G Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-36925
Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass a…
Mitigation only
CRITICAL 9.8
CVE-2020-36923
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. …
Bravia Signage
after 1.7.8
CRITICAL 9.8
CVE-2020-36912
Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manip…
Mitigation only
CRITICAL 9.8
CVE-2025-15001
The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.…
Mitigation only
CRITICAL 9.8
CVE-2025-14996
The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up…
Mitigation only
CRITICAL 9.8
CVE-2026-21675
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free vulner…
Iccdev
2.3.1.1+
CRITICAL 9.8
CVE-2025-15385
Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects co…
Boomplay
after 7.4.63
CRITICAL 9.8
CVE-2025-15444
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium
libsodium <= 1.0.20 or a version of libsodi…
Crypt\
0.000042+
CRITICAL 9.8
CVE-2026-0607
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executi…
Online Music Site
Mitigation only
CRITICAL 9.8
CVE-2026-0606
A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Album…
Online Music Site
Mitigation only
CRITICAL 9.3
CVE-2026-0625
Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows…
Mitigation only
CRITICAL 9.1
CVE-2025-68456
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trig…
Craft Cms
4.16.17 / 5.8.21+
CRITICAL 9.3
CVE-2025-65110
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 an…
Vega
5.6.3 / 6.1.2+
CRITICAL 9.8
CVE-2026-0605
A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the …
Online Music Site
Mitigation only
CRITICAL 9.1
CVE-2025-67397
An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific payload in…
Passy
Mitigation only
CRITICAL 9.1
CVE-2025-27807
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24…
Exynos 990 Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-61781
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "Wo…
Opencti
6.8.1+
CRITICAL 9.6
CVE-2025-55204
muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in.…
Muffon
2.3.0+
CRITICAL 9.6
CVE-2025-59467
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Adm…
Argentina Afip Invoices
1.3.0+
CRITICAL 9.3
CVE-2025-39484
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue …
Mitigation only
CRITICAL 9.8
CVE-2025-14346EPSS 6%
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pa…
Mitigation only
CRITICAL 9.8
CVE-2026-0597
A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality of the file /retailer/edit_pr…
Supplier Management System
Mitigation only
CRITICAL 9.8
CVE-2025-15029EPSS 12%
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules)…
Awie
24.04.3 / 24.10.3+