Top technology
Linux 13324
Google 12772
Microsoft 12406
Oracle 7480
Apple 6702
Ibm 6484
Adobe 6427
Cisco 5768
Debian 3920
Mozilla 2944
Apache 2925
Redhat 2627
CRITICAL 9.8
CVE-2025-40343
In the Linux kernel, the following vulnerability has been resolved:
nvmet-fc: avoid scheduling association deletion twice
When forcefully shutting …
No fix yet
CRITICAL 9.8
CVE-2025-14330
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun…
Firefox
140.6.0 / 146.0+
CRITICAL 9.8
CVE-2025-14326
Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.
Firefox
146.0+
CRITICAL 9.8
CVE-2025-14324
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund…
Firefox
115.31.0 / 140.6.0+
CRITICAL 9.8
CVE-2025-14321
Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 1…
Firefox
140.6.0 / 146.0+
CRITICAL 9.3
CVE-2025-14310
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb.This issue affects rethinkdb: before 2.4.4.
Patch available
CRITICAL 9.8
CVE-2025-14308
An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate t…
Robocode
Patch available
CRITICAL 9.1
CVE-2025-14306
A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly …
Robocode
Patch available
CRITICAL 9.8
CVE-2025-12504
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UNIS allows SQL Injection.
Thi…
Mitigation only
CRITICAL 9.6
CVE-2025-11022
Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.
This
CSRF vulnerability resulting …
Mitigation only
CRITICAL 9.8
CVE-2022-50666
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Fix QP destroy to wait for all references dropped.
Delay QP destroy c…
No fix yet
CRITICAL 9.6
CVE-2025-66481
DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through impro…
Deepchat
after 0.5.1
CRITICAL 9.8
CVE-2025-14285
A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_personnel.php. Th…
Employee Profile Management System
Mitigation only
CRITICAL 9.8
CVE-2023-53794
In the Linux kernel, the following vulnerability has been resolved:
cifs: fix session state check in reconnect to avoid use-after-free issue
Don't …
No fix yet
CRITICAL 9.1
CVE-2025-65849
A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to recover the Proof-of-Work nonce …
Mitigation only
CRITICAL 9.1
CVE-2025-65548
NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not validate the size of preimage w…
Nutshell
0.18.0+
CRITICAL 9.8
CVE-2025-64081
SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to e…
Patients Waiting Area Queue Management System
Mitigation only
CRITICAL 9.8
CVE-2025-14258
A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …
Student Management System
Mitigation only
CRITICAL 9.8
CVE-2025-48626
In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to r…
Android
Patch available
CRITICAL 9.8
CVE-2025-14257
A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /newrecord.php. Executing manipulati…
Student Management System
Mitigation only
CRITICAL 9.8
CVE-2025-14256
A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performin…
Student Management System
Mitigation only
CRITICAL 9.1
CVE-2025-61318
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.ph…
Emlog
No fix yet
CRITICAL 9.8
CVE-2025-14251
A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the c…
Online Ordering System
Mitigation only
CRITICAL 9.8
CVE-2025-14250
A weakness has been identified in code-projects Online Ordering System 1.0. The impacted element is an unknown function of the file /user_contact.php…
Online Ordering System
Mitigation only
CRITICAL 9.8
CVE-2025-14249
A security flaw has been discovered in code-projects Online Ordering System 1.0. The affected element is an unknown function of the file /user_school…
Online Ordering System
Mitigation only
CRITICAL 9.8
CVE-2025-14248
A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /adminlogin.php. The manipulati…
Simple Shopping Cart
Mitigation only
CRITICAL 9.8
CVE-2025-14247
A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php.…
Simple Shopping Cart
Mitigation only
CRITICAL 9.8
CVE-2025-14246
A vulnerability was found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown code of the file /Customers/settings.php. Per…
Simple Shopping Cart
Mitigation only
CRITICAL 9.8
CVE-2025-14245
A vulnerability has been found in IdeaCMS up to 1.8. This affects the function whereRaw of the file app/common/logic/index/Coupon.php. Such manipulat…
Ideacms
after 1.8
CRITICAL 9.8
CVE-2025-27020
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file …
Infinera Mtc 9 Firmware
23.0+