Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-78470 | WP Project Manager Pro <= 4.0.1 - Authenticated (Subsc… |
wedevs |
WP Project Manager Pro |
2026-08-25T05:31:28.953Z | 2026-08-25T15:09:07.908Z | |
| cve-2026-78466 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': '** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78278. Reason: This candidate is a reservation duplicate of CVE-2026-78278. Notes: All CVE users should reference CVE-2026-78278 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.'}], 'providerMetadata': {'orgId': 'b15e7b5b-3da4-40ae-a43c-f7aa60e62599', 'shortName': 'Wordfence', 'dateUpdated': '2026-08-26T16:39:13.200Z'}} | N/A | N/A | 2026-08-25T05:31:28.620Z | 2026-08-26T16:39:13.200Z |
| cve-2026-78478 | Måne <= 1.7 - Unauthenticated Local File Inclusion |
Elated-Themes |
Mane |
2026-08-25T05:31:28.313Z | 2026-08-25T12:02:00.193Z | |
| cve-2026-78467 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': '** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78272. Reason: This candidate is a reservation duplicate of CVE-2026-78272. Notes: All CVE users should reference CVE-2026-78272 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.'}], 'providerMetadata': {'orgId': 'b15e7b5b-3da4-40ae-a43c-f7aa60e62599', 'shortName': 'Wordfence', 'dateUpdated': '2026-08-26T16:41:46.643Z'}} | N/A | N/A | 2026-08-25T05:31:27.833Z | 2026-08-26T16:41:46.643Z |
| cve-2026-78638 | peerigon unzip-crx/unzip-crx-3 Archive Extraction inde… |
peerigon |
unzip-crx |
2026-08-25T05:30:08.899Z | 2026-08-27T14:36:08.272Z | |
| cve-2026-78637 | Fdawgs node-poppler Argument Injection index.js pdfUni… |
Fdawgs |
node-poppler |
2026-08-25T04:45:11.359Z | 2026-08-25T15:13:59.379Z | |
| cve-2026-13215 | 6.8 (v3.1) | Zephyr ext2 mount: unvalidated superblock block size c… |
zephyrproject |
zephyr |
2026-08-25T04:37:21.765Z | 2026-08-25T15:15:11.838Z |
| cve-2026-13214 | 9.8 (v3.1) | Stack buffer overflow in OCPP GetConfiguration key parsing |
zephyrproject |
zephyr |
2026-08-25T04:37:20.629Z | 2026-08-25T15:15:52.330Z |
| cve-2026-12561 | tagDiv Composer <= 5.4.5 - Authenticated (Contributor+… |
tagDiv |
tagDiv Composer |
2026-08-25T04:27:01.129Z | 2026-08-25T12:06:05.846Z | |
| cve-2026-19943 | Gutenverse <= 4.0.2 - Authenticated (Contributor+) Sto… |
jegstudio |
Gutenverse – WordPress Blocks, Page Builder & Site Editor |
2026-08-25T03:27:07.375Z | 2026-08-25T18:12:00.782Z | |
| cve-2026-14280 | Events Manager <= 7.3.7.4 - Authenticated (Administrat… |
netweblogic |
Events Manager – Calendar, Bookings, Tickets, and more! |
2026-08-25T03:27:07.025Z | 2026-08-25T19:22:20.406Z | |
| cve-2026-17089 | Events Manager <= 7.4.0.1 - Reflected Cross-Site Scrip… |
netweblogic |
Events Manager – Calendar, Bookings, Tickets, and more! |
2026-08-25T03:27:06.684Z | 2026-08-25T12:12:47.435Z | |
| cve-2026-76063 | FundEngine <= 1.8.1 - Authenticated (Subscriber+) Stor… |
roxnor |
FundEngine – Donation and Crowdfunding Platform |
2026-08-25T03:27:06.337Z | 2026-08-25T19:22:31.342Z | |
| cve-2026-19892 | InfusedWoo Pro <= 5.1.18 - Authenticated (Subscriber+)… |
Infused Addons |
InfusedWoo Pro |
2026-08-25T03:27:05.993Z | 2026-08-27T14:58:11.711Z | |
| cve-2026-75930 | FundEngine <= 1.8.1 - Missing Authorization to Authent… |
roxnor |
FundEngine – Donation and Crowdfunding Platform |
2026-08-25T03:27:05.464Z | 2026-08-25T15:19:49.192Z | |
| cve-2026-75019 | Cozy Blocks <= 2.2.16 - Authenticated (Contributor+) S… |
cozythemes |
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates |
2026-08-25T02:26:49.343Z | 2026-08-25T18:11:08.599Z | |
| cve-2025-9878 | Password Protect WordPress Lite <= 1.9.21 - Authentica… |
buildwps |
PPWP – Password Protect Pages |
2026-08-25T02:26:48.990Z | 2026-08-25T12:17:27.199Z | |
| cve-2026-75982 | LearnPress <= 4.4.4 - Missing Authorization to Authent… |
thimpress |
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses |
2026-08-25T02:26:48.639Z | 2026-08-25T15:20:51.772Z | |
| cve-2026-10627 | Events Manager <= 7.4.0 - Missing Authorization to Una… |
netweblogic |
Events Manager – Calendar, Bookings, Tickets, and more! |
2026-08-25T02:26:48.141Z | 2026-08-27T14:57:35.761Z | |
| cve-2026-78685 | 8.8 (v3.1) 8.6 (v4.0) | Le-yan|Medical Practice Management System - Remote Cod… |
Le-yan |
Medical Practice Management System |
2026-08-25T02:05:09.515Z | 2026-08-25T15:23:01.167Z |
| cve-2026-78683 | 9.4 (v4.0) 9.6 (v3.1) | NLTK before 3.10.0 Remote Code Execution via Unsafe Pi… |
nltk |
nltk |
2026-08-25T01:30:39.451Z | 2026-08-25T15:19:32.286Z |
| cve-2026-78682 | 8.7 (v4.0) 7.5 (v3.1) | NLTK before 3.10.3 SSRF Protection Bypass via Proxy |
nltk |
nltk |
2026-08-25T01:30:38.486Z | 2026-08-25T15:23:57.389Z |
| cve-2026-78681 | 8.7 (v4.0) 7.5 (v3.1) | NLTK before 3.10.3 Entity Expansion DoS via ElementTree |
nltk |
nltk |
2026-08-25T01:30:37.749Z | 2026-08-26T16:12:19.369Z |
| cve-2026-78680 | 8.5 (v4.0) 7.8 (v3.1) | NLTK before 3.10.3 Arbitrary Code Execution via Graphv… |
nltk |
nltk |
2026-08-25T01:30:37.044Z | 2026-08-25T12:43:04.211Z |
| cve-2026-78679 | 7.1 (v4.0) 6.5 (v3.1) | GitPython before 3.1.59 Arbitrary File Read via TagRef… |
gitpython-developers |
GitPython |
2026-08-25T01:30:36.339Z | 2026-08-27T14:56:36.199Z |
| cve-2026-78678 | 7.1 (v4.0) 6.5 (v3.1) | GitPython before 3.1.59 Arbitrary File Read via Repo.blame() |
gitpython-developers |
GitPython |
2026-08-25T01:30:35.582Z | 2026-08-25T15:18:02.854Z |
| cve-2026-78677 | 8.7 (v4.0) 7.5 (v3.1) | GitPython before 3.1.59 Path Traversal via separate-git-dir |
gitpython-developers |
GitPython |
2026-08-25T01:30:34.719Z | 2026-08-25T15:24:57.573Z |
| cve-2026-78676 | 9.3 (v4.0) 9.8 (v3.1) | GitPython before 3.1.59 Remote Code Execution via Conf… |
gitpython-developers |
GitPython |
2026-08-25T01:30:33.754Z | 2026-08-26T16:12:27.979Z |
| cve-2026-78675 | 8.6 (v4.0) 8.4 (v3.1) | GitPython before 3.1.59 Local File Content Disclosure … |
gitpython-developers |
GitPython |
2026-08-25T01:30:32.739Z | 2026-08-25T12:52:44.531Z |
| cve-2026-76846 | 8.7 (v4.0) 7.5 (v3.1) | Grav before 2.0.16 Information Disclosure via Twig Sandbox |
getgrav |
grav |
2026-08-25T01:30:31.891Z | 2026-08-27T14:55:30.423Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2006-000646 | Owl SQL injection vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000644 | NetCommons cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000643 | 04WebServer directory traversal vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000642 | 04WebServer cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000641 | Kiri directory traversal vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000640 | Drupal cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000638 | Dokeos cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000637 | QwikiWiki cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000636 | Loudblog cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000635 | Geeklog cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000634 | ServerView directory traversal vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000633 | ServerView cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000632 | ATutor cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000631 | ACollab SQL injection vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000630 | Wiki clone products vulnerable to denial of service attacks | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000629 | Wiki clone products vulnerable to denial of service attacks | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000628 | Wiki clone products vulnerable to denial of service attacks | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000627 | Phorum cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000626 | dotProject cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000625 | CGI RESCUE WebFORM allows unauthorized email transmission | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000624 | CGI RESCUE WebFORM allows unauthorized email transmission | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000623 | Joomla! cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000622 | dotProject cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000621 | RWiki cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000620 | RWiki arbitrary Ruby script execution vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000619 | MyWeb SQL injection vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000617 | Multiple email clients vulnerable to directory traversal due to inappropriate unicode handling | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000616 | DonutP and UnDonut confirmation dialog display vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000615 | Apache Struts Validator allows to bypass input data validation | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000614 | Winny buffer overflow vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-0179 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-03-01T00:00:00.000000 | 2024-03-01T00:00:00.000000 |
| certfr-2024-avi-0178 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-03-01T00:00:00.000000 | 2024-03-01T00:00:00.000000 |
| certfr-2024-avi-0177 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2024-03-01T00:00:00.000000 | 2024-03-01T00:00:00.000000 |
| certfr-2024-avi-0176 | Multiples vulnérabilités dans Mitel MiContact Center Business | 2024-03-01T00:00:00.000000 | 2024-03-01T00:00:00.000000 |
| certfr-2024-avi-0175 | Multiples vulnérabilités dans Microsoft Edge | 2024-03-01T00:00:00.000000 | 2024-03-01T00:00:00.000000 |
| certfr-2024-avi-0174 | Multiples vulnérabilités dans Cisco NX-OS | 2024-02-29T00:00:00.000000 | 2024-02-29T00:00:00.000000 |
| certfr-2024-avi-0173 | Multiples vulnérabilités dans Juniper Secure Analytics | 2024-02-29T00:00:00.000000 | 2024-02-29T00:00:00.000000 |
| certfr-2024-avi-0172 | Multiples vulnérabilités dans Zimbra Collaboration | 2024-02-28T00:00:00.000000 | 2024-02-28T00:00:00.000000 |
| certfr-2024-avi-0171 | Multiples vulnérabilités dans Aruba ClearPass Policy Manager | 2024-02-28T00:00:00.000000 | 2024-02-28T00:00:00.000000 |
| certfr-2024-avi-0170 | Multiples vulnérabilités dans Google Chrome | 2024-02-28T00:00:00.000000 | 2024-02-28T00:00:00.000000 |
| certfr-2024-avi-0169 | Vulnérabilité dans les produits VMware | 2024-02-28T00:00:00.000000 | 2024-02-28T00:00:00.000000 |
| certfr-2024-avi-0168 | Vulnérabilité dans les produits Xen | 2024-02-27T00:00:00.000000 | 2024-02-27T00:00:00.000000 |
| certfr-2024-avi-0167 | Vulnérabilité dans les produits Moxa | 2024-02-27T00:00:00.000000 | 2024-02-27T00:00:00.000000 |
| certfr-2024-avi-0166 | Vulnérabilité dans les produits WithSecure | 2024-02-26T00:00:00.000000 | 2024-02-26T00:00:00.000000 |
| certfr-2024-avi-0165 | Multiples vulnérabilités dans Microsoft Edge | 2024-02-26T00:00:00.000000 | 2024-02-26T00:00:00.000000 |
| certfr-2024-avi-0164 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0163 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0162 | Multiples vulnérabilités dans les produits IBM | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0161 | Vulnérabilité dans les produits SonicWall | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0160 | Multiples vulnérabilités dans Ruby on Rails | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0159 | Multiples vulnérabilités dans les produits Mozilla | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0158 | Vulnérabilité dans Kaspersky Endpoint Security | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0157 | Vulnérabilité dans PostgreSQL JDBC | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0156 | Multiples vulnérabilités dans les produits Tenable | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0155 | Multiples vulnérabilités dans Gitlab | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0154 | Vulnérabilité dans Spring Framework | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0153 | Multiples vulnérabilités dans les produits VMware | 2024-02-21T00:00:00.000000 | 2024-02-21T00:00:00.000000 |
| certfr-2024-avi-0152 | Multiples vulnérabilités dans Google Chrome | 2024-02-21T00:00:00.000000 | 2024-02-21T00:00:00.000000 |
| certfr-2024-avi-0151 | Multiples vulnérabilités dans Joomla! | 2024-02-21T00:00:00.000000 | 2025-01-28T00:00:00.000000 |
| certfr-2024-avi-0150 | Multiples vulnérabilités dans les produits Mozilla | 2024-02-21T00:00:00.000000 | 2024-02-21T00:00:00.000000 |