Top technology
Linux 13324
Google 12772
Microsoft 12406
Oracle 7480
Apple 6702
Ibm 6484
Adobe 6427
Cisco 5768
Debian 3920
Mozilla 2944
Apache 2925
Redhat 2627
CRITICAL 9.8
CVE-2025-13390
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect impleme…
Wp Directory Kit
after 1.4.4
CRITICAL 9.8
CVE-2025-13342
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to…
Mitigation only
CRITICAL 9.8
CVE-2025-13486EPSS 68%
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_…
Mitigation only
CRITICAL 9.3
CVE-2025-13658
A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence o…
Mitigation only
CRITICAL 9.8
CVE-2025-13542
The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlm…
Mitigation only
CRITICAL 9.3
CVE-2025-13510
The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated u…
Mitigation only
CRITICAL 9.1
CVE-2025-66409
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on …
Esp Idf
after 5.5.1
CRITICAL 9.8
CVE-2025-65896
SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.
Asyncmy
after 0.2.10
CRITICAL 9.8
CVE-2025-60736
code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.
Online Medicine Guide
Mitigation only
CRITICAL 9.8
CVE-2025-60854
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in…
R15 Firmware
after 1.20.01
CRITICAL 9.8
CVE-2025-58386
In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks.…
Terminalfour
8.4.1.2+
CRITICAL 9.8
CVE-2025-65656
dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.
Dcat Admin
after 2.2.3
CRITICAL 9.8
CVE-2025-65358
Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.
Edoc Doctor Appointment System
Mitigation only
CRITICAL 9.0
CVE-2025-13828
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settin…
Mitigation only
CRITICAL 9.1
CVE-2025-59703
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Pro…
Nshield 5c Firmware
13.6.12 / 13.9.0+
CRITICAL 9.8
CVE-2025-59695
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS r…
Nshield 5c Firmware
13.6.12 / 13.9.0+
CRITICAL 9.8
CVE-2025-59693
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.…
Nshield 5c Firmware
13.6.12 / 13.9.0+
CRITICAL 9.8
CVE-2025-41013
SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete datab…
Gim
2025-04-01+
CRITICAL 9.8
CVE-2025-11788
Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimite…
Sge Plc1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-11786
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter …
Sge Plc1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-11785
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited use…
Sge Plc1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-11784
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user…
Sge Plc1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-11783
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copy…
Sge Plc1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-11782
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string…
Sge Plc1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-11780
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user i…
Sge Plc1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-11779
Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is appli…
Sge Plc1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-11778
Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption thr…
Sge Plc1000 Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-41744
Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communicatio…
Sprecon E C Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-41742
Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic key…
Sprecon E C Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-13872
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an atta…
Opinio
Mitigation only