Top technology
Linux 13249
Google 12771
Microsoft 12402
Oracle 7468
Apple 6700
Ibm 6482
Adobe 6427
Cisco 5768
Debian 3920
Mozilla 2944
Apache 2925
Redhat 2626
CRITICAL 9.8
CVE-2025-53433
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes EasyEat easyeat…
Mitigation only
CRITICAL 9.1
CVE-2025-68435
Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication…
Zerobyte
0.18.5+
CRITICAL 9.1
CVE-2025-68145EPSS 7%
In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository…
Model Context Protocol Servers
2025.12.18+
CRITICAL 9.8
CVE-2025-14833
A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /…
Online Appointment Booking System
Mitigation only
CRITICAL 9.8
CVE-2023-53926
PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database querie…
Simple Cms
Mitigation only
CRITICAL 9.8
CVE-2023-53923
UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserC…
Ulicms
Mitigation only
CRITICAL 9.8
CVE-2023-53922
TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload …
Tinywebgallery
Mitigation only
CRITICAL 9.8
CVE-2023-53921
SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. …
Sitemagic Cms
Mitigation only
CRITICAL 9.8
CVE-2023-53914
UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in …
Ulicms
Mitigation only
CRITICAL 9.1
CVE-2025-68118
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling co…
Freerdp
3.20.0+
CRITICAL 9.8
CVE-2025-68114
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.…
Capstone
6.0.0+
CRITICAL 9.8
CVE-2025-67791
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentica…
Drivelock
after 25.1.6
CRITICAL 9.8
CVE-2025-14832
A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduc…
Online Cake Ordering System
Mitigation only
CRITICAL 9.8
CVE-2025-67793
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" …
Drivelock
25.1.6+
CRITICAL 9.0
CVE-2025-67493
Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access …
Homarr
1.45.3+
CRITICAL 9.8
CVE-2025-66647
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de…
Riot
2025.10+
CRITICAL 9.8
CVE-2025-43526
This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web…
Safari
26.2+
CRITICAL 9.8
CVE-2025-43428
A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. P…
Ipados
26.2+
CRITICAL 9.6
CVE-2025-67787
An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a…
Drivelock
Mitigation only
CRITICAL 9.9
CVE-2025-67781
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileg…
Drivelock
24.1.6 / 24.2.7+
CRITICAL 9.8
CVE-2025-67073
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial o…
Ac10 Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-34434
AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints respon…
Avideo
20.0+
CRITICAL 9.8
CVE-2025-62521
ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM'…
Churchcrm
5.21.0+
CRITICAL 9.8
CVE-2025-67165
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
Pagekit
Mitigation only
CRITICAL 9.9
CVE-2025-67164
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c…
Pagekit
Mitigation only
CRITICAL 10.0
CVE-2025-20393 KEVEPSS 30%
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could …
Asyncos
15.0.2-007 / 15.0.5-016+
CRITICAL 10.0
CVE-2025-44005EPSS 9%
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol a…
Mitigation only
CRITICAL 9.8
CVE-2022-23851
Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).
Api Orchestrator
0.19.3+
CRITICAL 9.8
CVE-2025-67895
Edge3 Worker RPC RCE on Airflow 2.
This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on …
Apache Airflow Providers Edge3
2.0.0+
CRITICAL 9.8
CVE-2025-59374 KEV
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a sup…
Live Update
3.6.8+