Top technology
Linux 13249
Google 12771
Microsoft 12402
Oracle 7468
Apple 6700
Ibm 6482
Adobe 6427
Cisco 5768
Debian 3920
Mozilla 2944
Apache 2925
Redhat 2626
CRITICAL 9.9
CVE-2025-14700EPSS 7%
An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remot…
Crafty Controller
Mitigation only
CRITICAL 9.1
CVE-2025-53619
An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file …
Grassroots Dicom
Mitigation only
CRITICAL 9.1
CVE-2025-53618
An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file …
Grassroots Dicom
Mitigation only
CRITICAL 9.1
CVE-2025-48429
An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file ca…
Grassroots Dicom
No fix yet
CRITICAL 9.8
CVE-2025-65834
Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulated widt…
Shotcut
Mitigation only
CRITICAL 9.9
CVE-2025-68270
The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are a…
Patch available
CRITICAL 9.8
CVE-2025-62864
Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly form…
Ampereone A192 32m Firmware
4.4.5.2 / 5.4.5.1+
CRITICAL 9.8
CVE-2025-62863
Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly form…
Ampereone A192 32m Firmware
4.4.5.2 / 5.4.5.1+
CRITICAL 9.8
CVE-2025-46295
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the t…
Filemaker Server
22.0.4+
CRITICAL 9.0
CVE-2025-33210
NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution.
Isaac Lab
2.3.0+
CRITICAL 10.0
CVE-2025-63414
A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command exec…
Allsky
Mitigation only
CRITICAL 9.8
CVE-2025-50401
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password.
D196g Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-50398
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter fac_password.
D196g Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-37164 KEVEPSS 90%
A remote code execution issue exists in HPE OneView.
Oneview
after 10.20.00
CRITICAL 9.8
CVE-2023-53899
PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Att…
Podcast Generator
Mitigation only
CRITICAL 9.8
CVE-2023-53895
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization throug…
Pimp My Log
Mitigation only
CRITICAL 9.8
CVE-2023-53894
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash vali…
Phpfilemanager
Mitigation only
CRITICAL 9.8
CVE-2025-68315
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to detect potential corrupted nid in free_nid_list
As reported, on-di…
No fix yet
CRITICAL 9.8
CVE-2025-68301
In the Linux kernel, the following vulnerability has been resolved:
net: atlantic: fix fragment overflow handling in RX path
The atlantic driver ca…
Mitigation only
CRITICAL 9.8
CVE-2025-68285
In the Linux kernel, the following vulnerability has been resolved:
libceph: fix potential use-after-free in have_mon_and_osd_map()
The wait loop i…
No fix yet
CRITICAL 9.8
CVE-2025-68284
In the Linux kernel, the following vulnerability has been resolved:
libceph: prevent potential out-of-bounds writes in handle_auth_session_key()
Th…
Mitigation only
CRITICAL 9.1
CVE-2025-65319
When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-Web tag, wh…
Bluemail
after 1.140.103
CRITICAL 9.1
CVE-2025-65318
When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, whi…
Canary Mail
after 5.1.40
CRITICAL 9.8
CVE-2025-68263
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: ipc: fix use-after-free in ipc_msg_send_request
ipc_msg_send_request() w…
Mitigation only
CRITICAL 9.8
CVE-2025-68192
In the Linux kernel, the following vulnerability has been resolved:
net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
Raw IP pack…
No fix yet
CRITICAL 9.8
CVE-2025-40350
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ
XDP …
No fix yet
CRITICAL 9.8
CVE-2025-62849
An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerab…
Qts
Mitigation only
CRITICAL 9.8
CVE-2025-59385
An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then …
Qts
Mitigation only
CRITICAL 9.6
CVE-2025-67744
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerab…
Deepchat
0.5.3+
CRITICAL 9.8
CVE-2025-64725
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15…
Weblate
5.15+