Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-79668 | 6.9 (v4.0) 5.3 (v3.1) | Ech0 before 4.7.3 Unauthenticated Like Endpoint Metric… |
lin-snow |
Ech0 |
2026-08-25T11:33:30.130Z | 2026-08-26T16:11:48.745Z |
| cve-2026-79667 | 7.2 (v4.0) 7.6 (v3.1) | Ech0 before 4.4.3 Authentication Bypass via Scope Enfo… |
lin-snow |
Ech0 |
2026-08-25T11:33:29.421Z | 2026-08-25T13:28:12.131Z |
| cve-2026-79666 | 7.1 (v4.0) 6.5 (v3.1) | Ech0 before 4.4.3 Missing Authorization via dashboard … |
lin-snow |
Ech0 |
2026-08-25T11:33:28.747Z | 2026-08-27T15:11:56.193Z |
| cve-2026-79665 | 8.7 (v4.0) 8.8 (v3.1) | Ech0 before 4.5.1 Authorization Bypass via Session Tokens |
lin-snow |
Ech0 |
2026-08-25T11:33:28.065Z | 2026-08-25T15:31:13.613Z |
| cve-2026-79664 | 9.1 (v4.0) 7.4 (v3.1) | Ech0 before 4.7.3 Access Token Revocation Bypass |
lin-snow |
Ech0 |
2026-08-25T11:33:27.375Z | 2026-08-25T13:01:48.306Z |
| cve-2026-79663 | 4.8 (v4.0) 4.8 (v3.1) | Ech0 before 4.7.3 Stored XSS via RSS feed tag names |
lin-snow |
Ech0 |
2026-08-25T11:33:26.721Z | 2026-08-26T16:11:59.399Z |
| cve-2026-79662 | 8.8 (v4.0) 8 (v3.1) | Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass |
lin-snow |
Ech0 |
2026-08-25T11:33:26.056Z | 2026-08-25T14:51:03.397Z |
| cve-2026-79661 | 6.9 (v4.0) 6.5 (v3.1) | Ech0 before 4.7.3 Unauthenticated fav_count Modification |
lin-snow |
Ech0 |
2026-08-25T11:33:25.369Z | 2026-08-27T15:10:35.322Z |
| cve-2026-79660 | 6.9 (v4.0) 5.3 (v3.1) | Ech0 before 4.7.3 Email Disclosure via Public API |
lin-snow |
Ech0 |
2026-08-25T11:33:24.692Z | 2026-08-25T15:32:51.102Z |
| cve-2026-79659 | 8.3 (v4.0) 7.7 (v3.1) | Ech0 before 4.7.3 Server-Side Request Forgery via fetc… |
lin-snow |
Ech0 |
2026-08-25T11:33:23.996Z | 2026-08-25T13:03:53.372Z |
| cve-2026-79658 | 8.7 (v4.0) 7.5 (v3.1) | Ech0 before 5.0.1 Denial of Service via Accept-Language |
lin-snow |
Ech0 |
2026-08-25T11:33:23.319Z | 2026-08-29T13:38:26.568Z |
| cve-2026-79657 | 9.3 (v4.0) 9.8 (v3.1) | NLTK before 3.10.3 Remote Code Execution via Unsafe Pi… |
nltk |
nltk |
2026-08-25T11:33:22.645Z | 2026-08-25T15:58:38.403Z |
| cve-2026-78684 | 6.9 (v4.0) 5.3 (v3.1) | vLLM before 0.27.0 Denial of Service via DeepStream Backend |
vllm-project |
vllm |
2026-08-25T11:33:22.005Z | 2026-08-31T17:22:39.856Z |
| cve-2026-78864 | liketrek TREK Journey Entry Update journey.controller.… |
liketrek |
TREK |
2026-08-25T11:30:09.324Z | 2026-08-25T13:07:48.384Z | |
| cve-2026-77824 | Media Sweep <= 1.1.3 - Authenticated (Administrator+) … |
wpcreatix |
Media Sweep – WordPress Media Cleaner |
2026-08-25T11:27:12.470Z | 2026-08-25T19:21:34.704Z | |
| cve-2026-18547 | Ultimate Member <= 2.12.1 - Authenticated (Subscriber+… |
ultimatemember |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin |
2026-08-25T11:27:12.131Z | 2026-08-25T16:02:11.847Z | |
| cve-2026-17587 | My Agile Privacy® <= 3.3.6 - Missing Authorization to … |
formulaagile |
My Agile Privacy® – CMP, Cookie Consent & Privacy Tools |
2026-08-25T11:27:11.761Z | 2026-08-25T19:21:42.990Z | |
| cve-2026-75971 | ShopEngine Elementor WooCommerce Builder Addon <= 4.9.… |
roxnor |
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets |
2026-08-25T11:27:11.397Z | 2026-08-25T13:08:29.780Z | |
| cve-2026-19949 | All-in-One WP Migration and Backup <= 7.109 - Unauthen… |
servmask |
All-in-One WP Migration and Backup |
2026-08-25T11:27:11.038Z | 2026-08-27T15:06:46.926Z | |
| cve-2026-75908 | Newsletters <= 4.17 - Missing Authorization to Authent… |
contrid |
Newsletters |
2026-08-25T11:27:10.516Z | 2026-08-25T18:03:51.392Z | |
| cve-2026-79652 | 5.9 (v3.1) | Keycloak-services: keycloak-services: jwt bearer autho… |
Red Hat |
Red Hat Build of Keycloak |
2026-08-25T11:07:48.988Z | 2026-08-25T13:26:20.259Z |
| cve-2026-59335 | 8.7 (v3.1) | Case-Sensitive Authorization Check Bypass via Identity… |
Cloud Foundry |
UAA |
2026-08-25T11:05:11.166Z | 2026-08-25T13:09:07.719Z |
| cve-2026-78863 | liketrek TREK Pre-2FA mfa_token authService.ts loginUs… |
liketrek |
TREK |
2026-08-25T11:00:10.236Z | 2026-08-27T15:06:04.339Z | |
| cve-2026-12600 | 8.7 (v4.0) | Uncontrolled memory usage in Innodata Labs’ Poppler JP… |
Poppler |
Innodata Labs |
2026-08-25T10:57:57.486Z | 2026-08-26T12:22:48.941Z |
| cve-2026-21754 | 5.4 (v3.1) | HCL Hive is affected by multiple security vulnerabilities. |
HCL Software |
Hive |
2026-08-25T10:51:48.749Z | 2026-08-25T13:12:18.697Z |
| cve-2026-21753 | 4.2 (v3.1) | HCL Hive is affected by multiple security vulnerabilities. |
HCL Software |
Hive |
2026-08-25T10:50:27.071Z | 2026-08-25T13:12:40.952Z |
| cve-2026-21758 | 3.7 (v3.1) | HCL Hive is affected by multiple security vulnerabilities. |
HCL Software |
Hive |
2026-08-25T10:49:13.333Z | 2026-08-25T13:27:58.160Z |
| cve-2026-49845 | Apache Hive: SQL Injection vulnerability in HiveMetaSt… |
Apache Software Foundation |
Apache Hive |
2026-08-25T10:13:49.998Z | 2026-08-26T03:56:13.485Z | |
| cve-2026-55976 | Apache Hive: SSRF vulnerability in Hive Avro Serde due… |
Apache Software Foundation |
Apache Hive |
2026-08-25T10:13:27.529Z | 2026-08-26T18:50:58.145Z | |
| cve-2026-53561 | Apache Hive: Unauthenticated authentication bypass in … |
Apache Software Foundation |
Apache Hive |
2026-08-25T10:12:53.804Z | 2026-08-26T18:49:03.614Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2007-000476 | Hiki arbitrary file deletion vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000471 | RaidenHTTPD cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000457 | Apache Tomcat cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-07-11T13:48+09:00 |
| jvndb-2007-000456 | Apache Tomcat sample web application cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-07-11T13:48+09:00 |
| jvndb-2007-000454 | dotProject cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000447 | Internet Explorer vulnerable in handling MHTML protocol | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000446 | Internet Explorer vulnerable in MHTML handling | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000434 | ADPLAN cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000429 | Meneame cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000420 | HP System Management Homepage cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000400 | Advance-Flow cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000395 | Homepage Builder sample CGI programs vulnerable to OS command injection | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000329 | Java Web Start vulnerable to execution of unauthorized system classes | 2008-05-21T00:00+09:00 | 2008-06-06T16:22+09:00 |
| jvndb-2007-000322 | Lunascape RSS reader arbitrary script execution vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000301 | Canon Network Camera Server VB100 Series vulnerable to cross-site scripting | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000297 | Apache Tomcat Accept-Language Header Cross-Site Scripting Vulnerability | 2008-05-21T00:00+09:00 | 2008-07-11T13:47+09:00 |
| jvndb-2007-000295 | APOP password recovery vulnerability | 2008-05-21T00:00+09:00 | 2009-08-06T11:39+09:00 |
| jvndb-2007-000290 | InfoBarrier4 self-decrypted file vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000260 | Shihonkanri Plus Ver2 GOOUT directory traversal vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000259 | open-gorotto cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000236 | Overlay Weaver cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000229 | MailDwarf vulnerability allows unauthorized sending of emails | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000228 | MailDwarf cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000227 | CruiseWorks and Minna De Office vulnerable in access restrictions | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000226 | BASP21 vulnerable to mail header injection | 2008-05-21T00:00+09:00 | 2016-10-13T14:45+09:00 |
| jvndb-2007-000225 | NewsGlue and Ikinari Jijyoutsuu arbitrary script execution vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000218 | Interstage Application Server cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000215 | FENCE-Pro and Systemwalker Desktop Encryption self-decoding file vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000200 | Trac cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000199 | CCC Cleaner division-by-zero vulnerability when scanning UPX-packed executables | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-0269 | Multiples vulnérabilités dans Mozilla Firefox | 2024-04-04T00:00:00.000000 | 2024-04-04T00:00:00.000000 |
| certfr-2024-avi-0268 | Multiples vulnérabilités dans VMware SD-WAN | 2024-04-03T00:00:00.000000 | 2024-04-03T00:00:00.000000 |
| certfr-2024-avi-0267 | Vulnérabilité dans les produits Palo Alto Networks | 2024-04-02T00:00:00.000000 | 2024-04-02T00:00:00.000000 |
| certfr-2024-avi-0266 | Multiples vulnérabilités dans Synology Surveillance Station | 2024-04-02T00:00:00.000000 | 2024-04-02T00:00:00.000000 |
| certfr-2024-avi-0265 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-03-29T00:00:00.000000 | 2024-03-29T00:00:00.000000 |
| certfr-2024-avi-0264 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2024-03-29T00:00:00.000000 | 2024-03-29T00:00:00.000000 |
| certfr-2024-avi-0263 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-03-29T00:00:00.000000 | 2024-03-29T00:00:00.000000 |
| certfr-2024-avi-0262 | Multiples vulnérabilités dans les produits IBM | 2024-03-29T00:00:00.000000 | 2024-03-29T00:00:00.000000 |
| certfr-2024-avi-0261 | Multiples vulnérabilités dans Microsoft Edge | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0260 | Multiples vulnérabilités dans les produits Cisco | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0259 | Multiples vulnérabilités dans GitLab | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0258 | Multiples vulnérabilités dans les produits Splunk | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0257 | Multiples vulnérabilités dans Elasticsearch | 2024-03-28T00:00:00.000000 | 2024-03-29T00:00:00.000000 |
| certfr-2024-avi-0256 | Vulnérabilité dans Wireshark | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0255 | Vulnérabilité dans GLPI | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0254 | Multiples vulnérabilités dans Google Chrome | 2024-03-27T00:00:00.000000 | 2024-03-27T00:00:00.000000 |
| certfr-2024-avi-0253 | Vulnérabilité dans Aruba ArubaOS-Switch | 2024-03-27T00:00:00.000000 | 2024-03-27T00:00:00.000000 |
| certfr-2024-avi-0252 | Multiples vulnérabilités dans Nagios XI | 2024-03-27T00:00:00.000000 | 2024-03-27T00:00:00.000000 |
| certfr-2024-avi-0251 | Multiples vulnérabilités dans Kaspersky Anti Targeted Attack | 2024-03-26T00:00:00.000000 | 2024-03-26T00:00:00.000000 |
| certfr-2024-avi-0250 | Vulnérabilité dans les produits Apple | 2024-03-26T00:00:00.000000 | 2024-03-26T00:00:00.000000 |
| certfr-2024-avi-0249 | Multiples vulnérabilités dans Tenable Security Center | 2024-03-26T00:00:00.000000 | 2024-03-26T00:00:00.000000 |
| certfr-2024-avi-0248 | Vulnérabilité dans Microsoft .Net | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0247 | Multiples vulnérabilités dans Microsoft Edge | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0246 | Multiples vulnérabilités dans Mozilla Firefox | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0245 | Multiples vulnérabilités dans MISP | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0244 | Multiples vulnérabilités dans les produits Netapp | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0243 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-03-22T00:00:00.000000 | 2024-03-22T00:00:00.000000 |
| certfr-2024-avi-0242 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-03-22T00:00:00.000000 | 2024-03-22T00:00:00.000000 |
| certfr-2024-avi-0241 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2024-03-22T00:00:00.000000 | 2024-03-22T00:00:00.000000 |
| certfr-2024-avi-0240 | Multiples vulnérabilités dans les produits IBM | 2024-03-22T00:00:00.000000 | 2024-03-22T00:00:00.000000 |