Top technology
Linux 13324
Google 12772
Microsoft 12406
Oracle 7480
Apple 6702
Ibm 6484
Adobe 6427
Cisco 5768
Debian 3920
Mozilla 2944
Apache 2925
Redhat 2627
CRITICAL 9.8
CVE-2025-13313
The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is …
Mitigation only
CRITICAL 9.8
CVE-2025-66509
LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowin…
Lara Dashboard
after 2.3.0
CRITICAL 9.8
CVE-2025-66576
Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthentic…
Remote Keyboard Desktop
Mitigation only
CRITICAL 9.3
CVE-2025-66571
UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter…
No fix yet
CRITICAL 9.8
CVE-2025-29269
ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.
All Rut22gw Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-29268EPSS 8%
ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
All Rut22gw Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-12995
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determi…
Carelink Network
2025-12-04+
CRITICAL 9.8
CVE-2025-63362
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to…
Rs232\/485 To Wifi Eth \(b\) Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-14015
A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulatio…
Magic B0 Firmware
after 100R002
CRITICAL 9.8
CVE-2025-66516EPSS 80%
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a…
Tika
3.2.2+
CRITICAL 9.8
CVE-2025-40261
In the Linux kernel, the following vulnerability has been resolved:
nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
nvme_f…
Mitigation only
CRITICAL 9.8
CVE-2025-40258
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix race condition in mptcp_schedule_work()
syzbot reported use-after-fr…
No fix yet
CRITICAL 9.8
CVE-2025-40257
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix a race in mptcp_pm_del_add_timer()
mptcp_pm_del_add_timer() can call…
No fix yet
CRITICAL 9.8
CVE-2025-40252
In the Linux kernel, the following vulnerability has been resolved:
net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_t…
Mitigation only
CRITICAL 9.1
CVE-2025-65346
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive con…
Laravel File Manager
after 3.3.1
CRITICAL 9.8
CVE-2025-54304
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The d…
Ion Torrent Onetouch 2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-54303
The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The iona…
Torrent Suite Software
Mitigation only
CRITICAL 9.8
CVE-2025-53963
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The r…
Ion Torrent Onetouch 2 Firmware
Mitigation only
CRITICAL 9.6
CVE-2024-45538
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Sy…
Diskstation Manager
3.1.4-23079 / 7.2.1-69057-2+
CRITICAL 9.8
CVE-2025-14004
A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add…
Xunruicms
after 4.7.1
CRITICAL 9.8
CVE-2025-64055
An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the d…
X210 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-66489
Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verificati…
Cal.com
5.9.8+
CRITICAL 9.6
CVE-2025-66222
DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the M…
Deepchat
after 0.5.0
CRITICAL 9.8
CVE-2025-66208
Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online.…
Online
25.04.702+
CRITICAL 9.8
CVE-2025-66032
Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible …
Claude Code
1.0.93+
CRITICAL 9.6
CVE-2025-64443
MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming t…
Mcp Gateway
0.28.0+
CRITICAL 9.3
CVE-2025-34319
TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vul…
Mitigation only
CRITICAL 9.8
CVE-2024-32641EPSS 12%
Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code …
Masacms
7.2.8 / 7.3.13+
CRITICAL 10.0
CVE-2025-55182 KEVEPSS 100%
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the …
React
15.0.5 / 15.1.9+
CRITICAL 9.0
CVE-2025-65267
In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. …
Erpnext
Mitigation only