Top technology
Linux 13324
Google 12772
Microsoft 12406
Oracle 7480
Apple 6702
Ibm 6484
Adobe 6427
Cisco 5768
Debian 3920
Mozilla 2944
Apache 2925
Redhat 2627
CRITICAL 9.8
CVE-2025-27019
Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows
an attacker to utilize password-less user accounts and obtain
system acces…
Infinera Mtc 9 Firmware
23.0+
CRITICAL 9.8
CVE-2025-14227
A security flaw has been discovered in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. This issue affects some unknown pro…
Simple Php Blog
after 2025-01-22
CRITICAL 9.8
CVE-2025-14226
A vulnerability was identified in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The…
Student Management System
Mitigation only
CRITICAL 9.8
CVE-2025-14224
A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the componen…
Dm2 Firmware
after 1.9.12
CRITICAL 9.8
CVE-2025-14223
A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /req…
Simple Leave Manager
Mitigation only
CRITICAL 9.8
CVE-2025-14218
A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editother…
Currency Exchange System
Mitigation only
CRITICAL 9.8
CVE-2025-14217
A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the file /edittrns.php. Such manipul…
Currency Exchange System
Mitigation only
CRITICAL 9.8
CVE-2025-14216
A vulnerability was determined in code-projects Currency Exchange System 1.0. This issue affects some unknown processing of the file /viewserial.php.…
Currency Exchange System
Mitigation only
CRITICAL 9.8
CVE-2025-14215
A vulnerability was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the file /edit.php. The manipulat…
Currency Exchange System
Mitigation only
CRITICAL 9.8
CVE-2025-14212
A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /memb…
Advanced Library Management System
Mitigation only
CRITICAL 9.8
CVE-2025-14211
A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of t…
Advanced Library Management System
Mitigation only
CRITICAL 9.8
CVE-2025-14210
A security vulnerability has been detected in projectworlds Advanced Library Management System 1.0. Affected is an unknown function of the file /dele…
Advanced Library Management System
Mitigation only
CRITICAL 9.8
CVE-2025-14209
A weakness has been identified in Campcodes School File Management System 1.0. This impacts an unknown function of the file /update_query.php. This m…
School File Management System
Mitigation only
CRITICAL 9.3
CVE-2023-53769
In the Linux kernel, the following vulnerability has been resolved:
virt/coco/sev-guest: Double-buffer messages
The encryption algorithms read and …
No fix yet
CRITICAL 9.8
CVE-2023-53751
In the Linux kernel, the following vulnerability has been resolved:
cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname
TCP_Server…
No fix yet
CRITICAL 9.8
CVE-2025-40320
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential cfid UAF in smb2_query_info_compound
When smb2_query…
No fix yet
CRITICAL 9.8
CVE-2025-14199
A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text…
Verysync
after 2.21.3
CRITICAL 9.8
CVE-2025-14191
A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. Affected by this issue is the function strcpy of the file /goform/formP2PLimitCon…
512w Firmware
after 1.7.7-171114
CRITICAL 9.8
CVE-2025-14182
A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability affects unknown code of the file /sobey-mchEditor/waterm…
Media Convergence System
Mitigation only
CRITICAL 9.8
CVE-2025-14141
A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formArpBindConfig. Executing man…
520w Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-12673
The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() f…
Mitigation only
CRITICAL 9.8
CVE-2025-66644 KEV
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Arrayos Ag
9.4.5.9+
CRITICAL 9.8
CVE-2025-66570
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP he…
Cpp Httplib
0.27.0+
CRITICAL 9.6
CVE-2025-66562
TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exi…
Tuui
1.3.4+
CRITICAL 9.8
CVE-2025-34256
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secre…
Wise Deviceon Server
5.4+
CRITICAL 9.3
CVE-2020-36877
ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary…
No fix yet
CRITICAL 9.8
CVE-2025-14094EPSS 20%
A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulatio…
Br 6478ac V3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-14093EPSS 20%
A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The …
Br 6478ac V3 Firmware
Mitigation only
CRITICAL 9.6
CVE-2025-64054
A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially exec…
X210 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-12374
The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerab…
Mitigation only