Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-75038 | 6.1 (v3.1) 6.9 (v4.0) | Predictable temporary file in /tmp allows symlink atta… |
ilya-zlobintsev |
LACT |
2026-08-25T10:00:47.961Z | 2026-08-25T19:45:49.638Z |
| cve-2026-16231 | 8.1 (v3.1) | hbs vulnerable to XSS via registerAsyncHelper output-e… |
hbs |
hbs |
2026-08-25T10:00:09.678Z | 2026-08-25T19:47:42.474Z |
| cve-2026-49050 | Apache DolphinScheduler: General user can mint admin a… |
Apache Software Foundation |
Apache DolphinScheduler |
2026-08-25T09:57:48.064Z | 2026-08-25T14:40:07.589Z | |
| cve-2026-75037 | 7 (v3.1) 7.3 (v4.0) | Polkit authentication bypass in LACT |
ilya-zlobintsev |
LACT |
2026-08-25T09:52:32.993Z | 2026-08-25T13:57:43.909Z |
| cve-2026-78570 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': '** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.'}], 'providerMetadata': {'orgId': 'b15e7b5b-3da4-40ae-a43c-f7aa60e62599', 'shortName': 'Wordfence', 'dateUpdated': '2026-09-01T13:22:42.888Z'}} | N/A | N/A | 2026-08-25T09:27:52.790Z | 2026-09-01T13:22:42.888Z |
| cve-2026-76128 | eCommerce Product Catalog <= 3.5.10 - Authenticated (C… |
implecode |
eCommerce Product Catalog |
2026-08-25T09:27:52.427Z | 2026-08-25T11:31:27.695Z | |
| cve-2026-78576 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': '** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.'}], 'providerMetadata': {'orgId': 'b15e7b5b-3da4-40ae-a43c-f7aa60e62599', 'shortName': 'Wordfence', 'dateUpdated': '2026-09-01T13:23:54.301Z'}} | N/A | N/A | 2026-08-25T09:27:52.120Z | 2026-09-01T13:23:54.301Z |
| cve-2026-78572 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': '** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.'}], 'providerMetadata': {'orgId': 'b15e7b5b-3da4-40ae-a43c-f7aa60e62599', 'shortName': 'Wordfence', 'dateUpdated': '2026-09-01T13:23:21.868Z'}} | N/A | N/A | 2026-08-25T09:27:51.679Z | 2026-09-01T13:23:21.868Z |
| cve-2026-12878 | 8.6 (v4.0) | In affected versions of the Codefresh platform an… |
Octopus Deploy |
Codefresh |
2026-08-25T09:02:15.246Z | 2026-08-25T13:59:09.902Z |
| cve-2026-56092 | 7.6 (v4.0) | Broken Access Control in extension "Apache Solr for TY… |
TYPO3 |
Extension "Apache Solr for TYPO3 - Enterprise Search" |
2026-08-25T09:00:49.567Z | 2026-08-25T13:59:54.064Z |
| cve-2026-56093 | 6.3 (v4.0) | Broken Access Control in extension "Apache Solr for TY… |
TYPO3 |
Extension "Apache Solr for TYPO3 - Enterprise Search" |
2026-08-25T09:00:48.858Z | 2026-08-25T14:02:05.915Z |
| cve-2026-56094 | 6.3 (v4.0) | Information Disclosure in extension "Apache Solr for T… |
TYPO3 |
Extension "Apache Solr for TYPO3 - Enterprise Search" |
2026-08-25T09:00:48.087Z | 2026-08-25T14:36:04.472Z |
| cve-2026-56095 | 7.7 (v4.0) | Insecure Deserialization in extension "Apache Solr for… |
TYPO3 |
Extension "Apache Solr for TYPO3 - Enterprise Search" |
2026-08-25T09:00:47.261Z | 2026-08-25T14:10:56.394Z |
| cve-2026-56096 | 6.3 (v4.0) | Information Disclosure in extension "Apache Solr for T… |
TYPO3 |
Extension "Apache Solr for TYPO3 - Enterprise Search" |
2026-08-25T09:00:46.440Z | 2026-08-25T14:10:18.510Z |
| cve-2026-77127 | 6 (v4.0) | Information Disclosure in extension "Modules" (modules) |
TYPO3 |
Extension "Modules" |
2026-08-25T09:00:45.715Z | 2026-08-25T14:09:12.595Z |
| cve-2026-77128 | 6.3 (v4.0) | Broken Access Control in extension "Event management a… |
TYPO3 |
Extension "Event management and registration" |
2026-08-25T09:00:44.929Z | 2026-08-25T14:06:14.408Z |
| cve-2026-77129 | 7.7 (v4.0) | Server-Side Template Injection in extension "Event man… |
TYPO3 |
Extension "Event management and registration" |
2026-08-25T09:00:44.104Z | 2026-08-25T14:07:46.294Z |
| cve-2026-77130 | 5.3 (v4.0) | Insufficient Session Expiration in extension "SYSSY - … |
TYPO3 |
Extension "SYSSY - TYPO3 Monitoring & Security Checks" |
2026-08-25T09:00:43.390Z | 2026-08-25T14:51:54.258Z |
| cve-2026-77131 | 5.3 (v4.0) | Cleartext Transmission of Sensitive Information in ext… |
TYPO3 |
Extension "SYSSY - TYPO3 Monitoring & Security Checks" |
2026-08-25T09:00:42.646Z | 2026-08-25T14:51:54.415Z |
| cve-2026-77133 | 6 (v4.0) | Broken Access Control in extension "femanager" (femanager) |
TYPO3 |
Extension "femanager" |
2026-08-25T09:00:41.795Z | 2026-08-25T14:51:54.568Z |
| cve-2026-77134 | 8.3 (v4.0) | Broken Access Control in extension "femanager" (femanager) |
TYPO3 |
Extension "femanager" |
2026-08-25T09:00:40.986Z | 2026-08-25T14:51:54.716Z |
| cve-2026-77135 | 8.2 (v4.0) | Information Disclosure in extension "femanager" (femanager) |
TYPO3 |
Extension "femanager" |
2026-08-25T09:00:40.231Z | 2026-08-25T14:51:54.880Z |
| cve-2026-77136 | 9.5 (v4.0) | Server-Side Template Injection in extension "powermail… |
TYPO3 |
Extension "powermail" |
2026-08-25T09:00:39.526Z | 2026-08-25T14:07:07.220Z |
| cve-2026-77137 | 7.7 (v4.0) | SQL Injection in extension "Forms Export" (frp_form_answers) |
TYPO3 |
Extension "Forms Export" |
2026-08-25T09:00:38.789Z | 2026-08-25T14:06:42.472Z |
| cve-2026-77138 | 9.3 (v4.0) | Remote Code Execution in extension "HTML5 Video Player… |
TYPO3 |
Extension "HTML5 Video Player vs. Powermail" |
2026-08-25T09:00:38.059Z | 2026-08-25T14:05:40.648Z |
| cve-2026-77139 | 6 (v4.0) | Path Traversal in extension "Mask" (mask) |
TYPO3 |
Extension "Mask" |
2026-08-25T09:00:37.199Z | 2026-08-25T14:04:39.871Z |
| cve-2026-77140 | 8.7 (v4.0) | Broken Access Control in extension "Telephone Director… |
TYPO3 |
Extension "Telephone Directory" |
2026-08-25T09:00:36.477Z | 2026-08-27T17:33:00.915Z |
| cve-2026-77141 | 8.8 (v4.0) | Broken Access Control in extension "Club Directory" (c… |
TYPO3 |
Extension "Club Directory" |
2026-08-25T09:00:35.744Z | 2026-08-27T17:35:05.862Z |
| cve-2026-77142 | 8.8 (v4.0) | Broken Access Control in extension "Industry Directory… |
TYPO3 |
Extension "Industry Directory" |
2026-08-25T09:00:35.035Z | 2026-08-27T17:36:41.822Z |
| cve-2026-77143 | 8.8 (v4.0) | Broken Access Control in extension "Forum" (pforum) |
TYPO3 |
Extension "Forum" |
2026-08-25T09:00:34.130Z | 2026-08-26T06:02:18.425Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2007-000176 | Mozilla Firefox cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000165 | Ariel AirOne series cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000161 | ColdFusion error page cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000160 | ColdFusion cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000159 | Adobe JRun cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000135 | CCC Cleaner buffer overflow vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000134 | Sage vulnerable to arbitrary script execution | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000127 | CCC Cleaner buffer overflow vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000094 | MODx cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000093 | Sleipnir RSS bar vulnerable in handling RSS data in an inappropriate security zone | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000091 | Sleipnir RSS bar vulnerable in handling RSS data in an inappropriate security zone | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000090 | b2evolution cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000088 | Shopping Basket Professional vulnerable to OS command injection | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000087 | CGI RESCUE WebFORM missing mail content vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000086 | CGI RESCUE WebFORM vulnerable to cross-site scripting | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000085 | CGI RESCUE WebFORM vulnerable to HTTP header injection | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000074 | phpAdsNew cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000073 | Movable Type cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000071 | Fresh Reader RSS feed cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000070 | Drupal cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2007-000006 | Serene Bach cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000983 | JP1 Request Handling Denial of Service Vulnerabilities | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000975 | Hitachi Soumu Workflow Authentication Bypassing Vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000939 | Multiple vulnerabilities in Webmin and Usermin | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000938 | Webmin directory traversal vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000858 | Ruby vulnerability caused by a problem with the alias funtion so that safe level 4 does not function as a sandbox | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000853 | tDiary arbitrary Ruby script execution vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000852 | Joomla! cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000851 | pnamazu cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000850 | a-blog cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-0239 | Vulnérabilité dans Microsoft Xbox Gaming Services | 2024-03-21T00:00:00.000000 | 2024-03-21T00:00:00.000000 |
| certfr-2024-avi-0238 | Multiples vulnérabilités dans les produits Ivanti | 2024-03-21T00:00:00.000000 | 2024-03-21T00:00:00.000000 |
| certfr-2024-avi-0237 | Multiples vulnérabilités dans les produits Belden | 2024-03-20T00:00:00.000000 | 2024-03-20T00:00:00.000000 |
| certfr-2024-avi-0236 | Vulnérabilité dans Spring Authorization Server | 2024-03-20T00:00:00.000000 | 2024-03-20T00:00:00.000000 |
| certfr-2024-avi-0235 | Multiples vulnérabilités dans Google Chrome | 2024-03-20T00:00:00.000000 | 2024-03-20T00:00:00.000000 |
| certfr-2024-avi-0234 | Multiples vulnérabilités dans les produits Mozilla | 2024-03-20T00:00:00.000000 | 2024-03-20T00:00:00.000000 |
| certfr-2024-avi-0233 | Multiples vulnérabilités dans AXIS OS | 2024-03-19T00:00:00.000000 | 2024-03-19T00:00:00.000000 |
| certfr-2024-avi-0232 | Vulnérabilité dans les produits Spring Security | 2024-03-19T00:00:00.000000 | 2024-03-19T00:00:00.000000 |
| certfr-2024-avi-0231 | Multiples vulnérabilités dans les produits GLPI | 2024-03-19T00:00:00.000000 | 2024-03-19T00:00:00.000000 |
| certfr-2024-avi-0230 | Vulnérabilité dans Kaspersky Password Manager | 2024-03-18T00:00:00.000000 | 2024-03-18T00:00:00.000000 |
| certfr-2024-avi-0229 | Vulnérabilité dans Tenable Nessus | 2024-03-18T00:00:00.000000 | 2024-03-18T00:00:00.000000 |
| certfr-2024-avi-0228 | Multiples vulnérabilités dans IBM | 2024-03-15T00:00:00.000000 | 2024-03-15T00:00:00.000000 |
| certfr-2024-avi-0227 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2024-03-15T00:00:00.000000 | 2024-03-15T00:00:00.000000 |
| certfr-2024-avi-0226 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-03-15T00:00:00.000000 | 2024-03-15T00:00:00.000000 |
| certfr-2024-avi-0225 | Multiples vulnérabilités dans Juniper Secure Analytics | 2024-03-15T00:00:00.000000 | 2024-03-15T00:00:00.000000 |
| certfr-2024-avi-0224 | Multiples vulnérabilités dans Microsoft Edge | 2024-03-15T00:00:00.000000 | 2024-03-15T00:00:00.000000 |
| certfr-2024-avi-0223 | Vulnérabilité dans Spring Framework | 2024-03-15T00:00:00.000000 | 2024-03-15T00:00:00.000000 |
| certfr-2024-avi-0222 | Vulnérabilité dans Synology Router Manager | 2024-03-14T00:00:00.000000 | 2024-03-14T00:00:00.000000 |
| certfr-2024-avi-0221 | Multiples vulnérabilités dans les produits Palo Alto Networks | 2024-03-14T00:00:00.000000 | 2024-03-14T00:00:00.000000 |
| certfr-2024-avi-0220 | Multiples vulnérabilités dans Cisco IOS XR | 2024-03-14T00:00:00.000000 | 2024-03-14T00:00:00.000000 |
| certfr-2024-avi-0219 | Vulnérabilité dans les produits Mitel | 2024-03-14T00:00:00.000000 | 2024-03-14T00:00:00.000000 |
| certfr-2024-avi-0218 | Multiples vulnérabilités dans Apache Tomcat | 2024-03-14T00:00:00.000000 | 2024-03-14T00:00:00.000000 |
| certfr-2024-avi-0217 | Multiples vulnérabilités dans SonicWall | 2024-03-14T00:00:00.000000 | 2024-03-14T00:00:00.000000 |
| certfr-2024-avi-0216 | Multiples vulnérabilités dans les produits Xen | 2024-03-14T00:00:00.000000 | 2024-03-14T00:00:00.000000 |
| certfr-2024-avi-0215 | Vulnérabilité dans Adobe ColdFusion | 2024-03-13T00:00:00.000000 | 2024-03-13T00:00:00.000000 |
| certfr-2024-avi-0214 | Multiples vulnérabilités dans les produits Stormshield Network Security | 2024-03-13T00:00:00.000000 | 2024-03-13T00:00:00.000000 |
| certfr-2024-avi-0213 | Multiples vulnérabilités dans les produits Intel | 2024-03-13T00:00:00.000000 | 2024-03-13T00:00:00.000000 |
| certfr-2024-avi-0212 | Multiples vulnérabilités dans les produits Fortinet | 2024-03-13T00:00:00.000000 | 2024-03-13T00:00:00.000000 |
| certfr-2024-avi-0211 | Multiples vulnérabilités dans les produits Citrix | 2024-03-13T00:00:00.000000 | 2024-03-13T00:00:00.000000 |
| certfr-2024-avi-0210 | Vulnérabilité dans Google Chrome | 2024-03-13T00:00:00.000000 | 2024-03-13T00:00:00.000000 |