Top technology
Linux 13249
Google 12771
Microsoft 12402
Oracle 7468
Apple 6700
Ibm 6482
Adobe 6427
Cisco 5768
Debian 3920
Mozilla 2944
Apache 2925
Redhat 2626
CRITICAL 9.8
CVE-2025-56157
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE:…
Dify
after 1.5.1
CRITICAL 9.8
CVE-2025-64236
Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: fr…
No fix yet
CRITICAL 9.8
CVE-2025-14879EPSS 7%
A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Reques…
Wh450 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-63389
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exp…
Ollama
after 0.12.3
CRITICAL 9.1
CVE-2025-63388
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoin…
Dify
Mitigation only
CRITICAL 9.1
CVE-2025-63386
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implemen…
Dify
Patch available
CRITICAL 9.8
CVE-2025-14878
A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirelessRestart of the component HT…
Wh450 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-14877
A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The…
Supplier Management System
Mitigation only
CRITICAL 9.8
CVE-2025-7358
Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse.
This issue affects SoliClub: b…
Soliclub
5.3.7+
CRITICAL 9.4
CVE-2025-65008
In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in the adm.cgi endpoint, the mal…
Mitigation only
CRITICAL 9.8
CVE-2025-14860
Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.
Firefox
146.0.1+
CRITICAL 9.3
CVE-2025-10910
A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker…
Mitigation only
CRITICAL 9.1
CVE-2025-66078
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote …
Mitigation only
CRITICAL 9.0
CVE-2025-66074
Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webho…
Mitigation only
CRITICAL 9.9
CVE-2025-64374
Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors:…
Mitigation only
CRITICAL 9.8
CVE-2025-64233
Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2…
Mitigation only
CRITICAL 9.9
CVE-2025-64231
Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordp…
Mitigation only
CRITICAL 9.8
CVE-2025-64227
Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue af…
Mitigation only
CRITICAL 9.8
CVE-2025-64206
Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0.
Mitigation only
CRITICAL 9.8
CVE-2025-64188
Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through …
Mitigation only
CRITICAL 9.8
CVE-2025-60180
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue af…
Wp Gravity Forms Salesforce
1.5.2+
CRITICAL 9.8
CVE-2025-60178
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravit…
Wp Gravity Forms Hubspot
1.2.7+
CRITICAL 9.8
CVE-2025-60174
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.Thi…
Wp Gravity Forms Constant Contact Plugin
after 1.1.2
CRITICAL 9.8
CVE-2025-60091
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects W…
Wp Gravity Forms Zoho Crm And Bigin
1.3.0+
CRITICAL 9.8
CVE-2025-60090
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gr…
Wp Gravity Forms Insightly
1.1.7+
CRITICAL 9.8
CVE-2025-60089
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affect…
Wp Gravity Forms Freshdesk Plugin
1.3.6+
CRITICAL 9.3
CVE-2025-60062
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-wit…
Mitigation only
CRITICAL 9.3
CVE-2025-58951
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management fo…
Mitigation only
CRITICAL 9.8
CVE-2025-58935
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Lunna lunna allo…
Lunna
after 1.15
CRITICAL 9.8
CVE-2025-54723
Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue affects DentiCare: from n/a thro…
Mitigation only