Top technology
Linux 13159
Google 12756
Microsoft 12402
Oracle 7453
Apple 6698
Ibm 6482
Adobe 6427
Cisco 5768
Debian 3920
Apache 2925
Mozilla 2920
Redhat 2626
CRITICAL 9.8
CVE-2025-56333
An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component
Pangolin
1.7.0+
CRITICAL 9.8
CVE-2025-15195
A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file /admin/ad…
Assessment Management
Mitigation only
CRITICAL 9.8
CVE-2025-15194
A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the…
Dir 600 Firmware
Mitigation only
CRITICAL 9.0
CVE-2025-68929
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tri…
Frappe
14.99.6 / 15.88.1+
CRITICAL 9.8
CVE-2025-65570
A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array ele…
Jsish
Mitigation only
CRITICAL 9.8
CVE-2025-57460
File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
Machpanel
Mitigation only
CRITICAL 9.8
CVE-2025-15186
A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file …
Refugee Food Management System
Mitigation only
CRITICAL 9.8
CVE-2025-15185
A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ho…
Refugee Food Management System
Mitigation only
CRITICAL 9.8
CVE-2025-15184
A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the file /home/refugeesreport2.p…
Refugee Food Management System
Mitigation only
CRITICAL 9.8
CVE-2025-15183
A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown function of the file /home/vi…
Refugee Food Management System
Mitigation only
CRITICAL 9.8
CVE-2025-15182
A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of the file /home/served.php. Ex…
Refugee Food Management System
Mitigation only
CRITICAL 9.8
CVE-2025-15181
A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unknown function of the file /hom…
Refugee Food Management System
Mitigation only
CRITICAL 9.8
CVE-2025-15228
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and exe…
Bpmflowwebkit
5.0.5+
CRITICAL 9.8
CVE-2025-15226
WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdo…
Wmpro
after 5.2
CRITICAL 9.8
CVE-2025-15069
Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3.0 before 3.0.1
Web Fax
4.0+
CRITICAL 9.8
CVE-2025-15068
Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification through Manipulation.This issue…
Web Fax
4.0+
CRITICAL 10.0
CVE-2025-52691 KEVEPSS 86%
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, po…
Smartermail
100.0.9413+
CRITICAL 9.8
CVE-2025-15168
A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /statistical.php. Such mani…
Student Management System
Mitigation only
CRITICAL 9.8
CVE-2025-15167
A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the file /detailtransac.php. This…
Online Cake Ordering System
Mitigation only
CRITICAL 9.8
CVE-2025-15166
A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file /updatesupplier.php?action=ed…
Online Cake Ordering System
Mitigation only
CRITICAL 9.8
CVE-2025-15165
A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown function of the file /updatecustom…
Online Cake Ordering System
Mitigation only
CRITICAL 9.8
CVE-2025-15127
A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. Affected by this issue is so…
Hotels Server
after 2019-03-23
CRITICAL 9.8
CVE-2025-54322EPSS 15%
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and…
Sxzos
after 2025-12-26
CRITICAL 9.8
CVE-2025-68952
Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been identified in Eigent. This vulnera…
Eigent
Mitigation only
CRITICAL 9.8
CVE-2025-68932
FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() a…
Freshrss
1.28.0+
CRITICAL 9.1
CVE-2025-66203
StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault…
Streamvault
251126+
CRITICAL 9.9
CVE-2025-68668EPSS 13%
n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node…
N8n
2.0.0+
CRITICAL 9.8
CVE-2024-44065
Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.
Cloudlog
Mitigation only
CRITICAL 9.3
CVE-2025-13158
Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object proto…
Mitigation only
CRITICAL 9.8
CVE-2025-13915EPSS 9%
IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized acce…
Api Connect
after 10.0.8.5