Top technology
Linux 13324
Google 12772
Microsoft 12406
Oracle 7480
Apple 6702
Ibm 6484
Adobe 6427
Cisco 5768
Debian 3920
Mozilla 2944
Apache 2925
Redhat 2627
CRITICAL 9.8
CVE-2025-66039
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a…
Freepbx
16.0.44 / 17.0.23+
CRITICAL 9.8
CVE-2025-67489
@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution…
Patch available
CRITICAL 9.8
CVE-2023-53774
MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV …
Minidvblinux
after 5.4
CRITICAL 9.8
CVE-2023-53771
MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Att…
Minidvblinux
after 5.4
CRITICAL 9.9
CVE-2023-53739
Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration back…
Mitigation only
CRITICAL 9.8
CVE-2021-47731
Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocu…
Izero Box Full Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-47728
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbit…
Izero Box Full Firmware
Mitigation only
CRITICAL 9.3
CVE-2021-47708
COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL …
No fix yet
CRITICAL 9.3
CVE-2021-47707
COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can …
No fix yet
CRITICAL 9.8
CVE-2025-66456
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 throug…
Elysia
1.4.17+
CRITICAL 9.8
CVE-2025-65741
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of thi…
Sublime Text 3
3.2.2+
CRITICAL 9.8
CVE-2025-64113
Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (…
Emby
4.9.1.90+
CRITICAL 9.8
CVE-2025-14337
A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /new_grade.php. This manipulat…
Student Management System
Mitigation only
CRITICAL 9.8
CVE-2025-65882
An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ip…
Openmptcprouter
after 0.64
CRITICAL 9.8
CVE-2025-14336
A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown functionality of the file /promote.ph…
Student Management System
Mitigation only
CRITICAL 9.8
CVE-2025-14335
A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …
Student Management System
Mitigation only
CRITICAL 9.8
CVE-2025-14334
A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_adviser.php. Executing manipula…
Student Management System
Mitigation only
CRITICAL 9.0
CVE-2025-64672
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19127.20378+
CRITICAL 9.8
CVE-2025-59719EPSS 30%
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.…
Fortiweb
after 7.6.4
CRITICAL 9.8
CVE-2025-59718 KEVEPSS 69%
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 …
Fortiproxy
7.0.6 / 7.0.18+
CRITICAL 9.3
CVE-2025-34414
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 …
Mitigation only
CRITICAL 9.8
CVE-2025-63742
SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain…
Rockoa
Mitigation only
CRITICAL 9.8
CVE-2025-67504
WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand(…
Wbce Cms
1.6.5+
CRITICAL 9.8
CVE-2025-66631
CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow t…
Csla .net
6.0.0+
CRITICAL 9.1
CVE-2025-66568
The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypa…
Ruby Saml
1.18.0+
CRITICAL 9.1
CVE-2025-66567
The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentic…
Ruby Saml
1.18.0+
CRITICAL 9.8
CVE-2025-66565
Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number ge…
Utils
after 1.2.0
CRITICAL 9.1
CVE-2025-42928EPSS 9%
Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The s…
Mitigation only
CRITICAL 9.9
CVE-2025-42880
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled functio…
Mitigation only
CRITICAL 9.8
CVE-2025-40938
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. Thi…
Simatic Cn 4100 Firmware
4.0.1+