Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-81100 | 7.6 (v4.0) 6.8 (v3.1) | Timescale tiger-gh-mcp-server DNS Rebinding via Disabl… |
timescale |
tiger-gh-mcp-server |
2026-08-27T14:50:39.728Z | 2026-08-29T11:48:13.548Z |
| cve-2026-81099 | 7.6 (v4.0) 6.8 (v3.1) | Timescale tiger-slack DNS Rebinding via Disabled Host … |
timescale |
tiger-slack |
2026-08-27T14:50:39.029Z | 2026-08-29T11:48:12.861Z |
| cve-2026-81098 | 9.3 (v4.0) 9.1 (v3.1) | Telnyx MCP Server through 6.83.0 Missing Authenticatio… |
team-telnyx |
telnyx-mcp |
2026-08-27T14:50:38.327Z | 2026-08-29T11:48:12.176Z |
| cve-2026-81097 | 8.6 (v4.0) 8.4 (v3.1) | rails-mcp-server 1.4.0 through 1.6.0 OS Command Execut… |
maquina-app |
rails-mcp-server |
2026-08-27T14:50:37.617Z | 2026-08-29T11:48:11.453Z |
| cve-2026-81096 | 9.3 (v4.0) 10 (v3.1) | ToolUniverse through 1.2.6 Unauthenticated Remote Code… |
mims-harvard |
ToolUniverse |
2026-08-27T14:50:36.897Z | 2026-08-29T11:48:10.764Z |
| cve-2026-81095 | 7.6 (v4.0) 6.8 (v3.1) | Timescale pg-aiguide through 0.5.0 DNS Rebinding via D… |
timescale |
pg-aiguide |
2026-08-27T14:50:36.212Z | 2026-08-29T11:48:10.092Z |
| cve-2026-81094 | 9.3 (v4.0) 9.1 (v3.1) | mcp-router CLI before 0.6.3 Binds the MCP Aggregator t… |
mcp-router |
mcp-router |
2026-08-27T14:50:34.879Z | 2026-08-29T11:48:09.437Z |
| cve-2026-81093 | 8.7 (v4.0) 8.6 (v3.1) | Apify Actors MCP Server before 0.9.12 Server-Side Requ… |
apify |
actors-mcp-server |
2026-08-27T14:50:34.013Z | 2026-08-29T11:48:08.801Z |
| cve-2026-81092 | 7.6 (v4.0) 6.8 (v3.1) | mcp-go before 0.56.0 Missing Host Header Validation En… |
mark3labs |
mcp-go |
2026-08-27T14:50:33.286Z | 2026-08-29T11:48:08.125Z |
| cve-2026-81091 | 8.7 (v4.0) 8.6 (v3.1) | mcp-use Inspector Proxy Server-Side Request Forgery vi… |
mcp-use |
mcp-use |
2026-08-27T14:50:32.568Z | 2026-08-29T11:48:07.418Z |
| cve-2026-80427 | 8.6 (v4.0) 8.4 (v3.1) | bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument I… |
nfriedly |
bestzip |
2026-08-26T15:44:55.220Z | 2026-08-29T11:48:06.751Z |
| cve-2026-80426 | 7 (v4.0) 7.1 (v3.1) | FiftyOne before 1.21.0 Stored Cross-Site Scripting via… |
voxel51 |
fiftyone |
2026-08-26T15:44:54.517Z | 2026-08-29T11:48:06.089Z |
| cve-2026-80350 | 7.1 (v4.0) 7.1 (v3.1) | OneUptime before 12.0.7 Server-Side Request Forgery vi… |
OneUptime |
OneUptime |
2026-08-26T10:09:50.075Z | 2026-08-29T11:48:05.396Z |
| cve-2026-80192 | 8.6 (v4.0) 8.1 (v3.1) | better-auth SSO before 1.6.27 Domain Ownership Authent… |
better-auth |
sso |
2026-08-25T23:19:00.371Z | 2026-08-29T11:48:04.728Z |
| cve-2026-80191 | 8.7 (v4.0) 7.5 (v3.1) | GROWI before 8.0.2 Missing Authorization on Attachment… |
GROWI, Inc. |
GROWI |
2026-08-25T23:18:59.672Z | 2026-08-29T11:48:04.052Z |
| cve-2026-80189 | 7.1 (v4.0) 6.5 (v3.1) | LeafWiki 0.10.0 through 0.12.0 Uncontrolled Resource C… |
perber |
leafwiki |
2026-08-25T23:18:58.993Z | 2026-08-29T11:48:03.392Z |
| cve-2026-80104 | 9.3 (v4.0) 9.8 (v3.1) | DB-GPT 0.8.0 Path Traversal Arbitrary File Write via S… |
eosphoros-ai |
DB-GPT |
2026-08-25T20:18:35.843Z | 2026-08-29T11:48:02.709Z |
| cve-2026-79785 | 8.2 (v4.0) 5.9 (v3.1) | X-AnyLabeling before 4.0.0-beta.9 Improper Certificate… |
CVHub520 |
X-AnyLabeling |
2026-08-25T16:03:20.305Z | 2026-08-29T11:48:02.041Z |
| cve-2026-79775 | 7.1 (v4.0) 6.5 (v3.1) | rclone Archive Backend SquashFS Parser Denial of Service |
rclone |
rclone |
2026-08-25T15:16:06.427Z | 2026-08-29T11:48:01.347Z |
| cve-2026-79671 | 5.1 (v4.0) 5.5 (v3.1) | Ech0 before 4.4.3 SSRF via DNS Resolution Bypass |
lin-snow |
Ech0 |
2026-08-25T11:33:32.174Z | 2026-08-29T11:48:00.599Z |
| cve-2026-78209 | 8.4 (v4.0) 8.2 (v3.1) | exceljs through 4.4.0 CSV Formula Injection via Unesca… |
exceljs |
exceljs |
2026-08-24T00:30:48.493Z | 2026-08-29T11:47:59.263Z |
| cve-2026-78208 | 8.7 (v4.0) 7.5 (v3.1) | exceljs through 4.4.0 Path Traversal via Unvalidated a… |
exceljs |
exceljs |
2026-08-24T00:30:47.795Z | 2026-08-29T11:47:58.602Z |
| cve-2026-78207 | 9.3 (v4.0) 9.4 (v3.1) | exceljs through 4.4.0 Prototype Pollution via deepMerg… |
exceljs |
exceljs |
2026-08-24T00:30:47.125Z | 2026-08-29T11:47:57.933Z |
| cve-2026-78206 | 8.7 (v4.0) 7.5 (v3.1) | exceljs through 4.4.0 Uncontrolled Resource Consumptio… |
exceljs |
exceljs |
2026-08-24T00:30:46.462Z | 2026-08-29T11:47:57.243Z |
| cve-2026-78122 | 8.3 (v4.0) 7.4 (v3.1) | docker-socket-proxy through 0.5.0 Insufficient Access … |
Tecnativa |
docker-socket-proxy |
2026-08-22T23:06:32.896Z | 2026-08-29T11:47:56.573Z |
| cve-2026-77939 | 7.1 (v4.0) 6.5 (v3.1) | Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint |
flextype |
flextype |
2026-08-28T17:06:51.132Z | 2026-08-29T11:47:55.894Z |
| cve-2026-77923 | 5.3 (v4.0) 4.3 (v3.1) | Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clon… |
Dolibarr |
dolibarr |
2026-08-24T19:23:28.160Z | 2026-08-29T11:47:55.204Z |
| cve-2026-77915 | 9.3 (v4.0) 9.8 (v3.1) | rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registr… |
rconfig |
rconfig |
2026-08-24T16:11:44.667Z | 2026-08-29T11:47:54.529Z |
| cve-2026-77914 | 7.1 (v4.0) 6.5 (v3.1) | rConfig Core 8.0.0 < 8.2.13 Core Path Traversal via Ex… |
rconfig |
rconfig |
2026-08-24T16:07:58.448Z | 2026-08-29T11:47:53.860Z |
| cve-2026-77088 | 5.3 (v4.0) 6.1 (v3.1) | justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via… |
EmilStenstrom |
justhtml |
2026-08-23T13:34:12.574Z | 2026-08-29T11:47:53.161Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2006-000617 | Multiple email clients vulnerable to directory traversal due to inappropriate unicode handling | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000616 | DonutP and UnDonut confirmation dialog display vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000615 | Apache Struts Validator allows to bypass input data validation | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000614 | Winny buffer overflow vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000613 | Trac cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000612 | FreeStyleWiki cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000611 | QUICK CART cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000610 | QUICK CART OS command injection vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000609 | CAFEMILK Shopping Cart CGI cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000606 | Minnu's filer2 vulnerable in allowing arbitrary Ruby script execution | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000605 | Hyper NIKKI System allows unauthorized email submission | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000604 | Nagasaki Electronic Prefectural Office System SQL injection vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000603 | Hatena Toolbar sends URL information unecnrypted | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000602 | Multiple email clients vulnerable in handling an attachement inapropriately | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000601 | Eudora Japanese version stops working after the application crashes | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000600 | Nagasaki Electronic Prefectural Office System authentication information vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000599 | Nagasaki Electronic Prefectural Office System vulnerable to bypass authentication | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000540 | Microsoft Windows Indexing Service cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000392 | Ruby contains a vulnerability that prevents safe level 4 from functioning as a sandbox. | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000345 | Microsoft Internet Explorer address bar spoofing vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000326 | Mozilla Firefox vulnerable to HTTP response splitting | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000293 | Sun Java System Web Server cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2006-000251 | SquirrelMail cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2005-000864 | XOOPS cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2005-000805 | nProtect Netizen has multiple vulnerabilities | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2005-000802 | BBSNote cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2005-000801 | WebNote Clip vulnerable to OS command injection | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2005-000800 | Opera bookmark function vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2005-000799 | Problem with referer header handling on mobile phone web browsers | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| jvndb-2005-000798 | MitakeSearch cross-site scripting vulnerability | 2008-05-21T00:00+09:00 | 2008-05-21T00:00+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-0154 | Vulnérabilité dans Spring Framework | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0153 | Multiples vulnérabilités dans les produits VMware | 2024-02-21T00:00:00.000000 | 2024-02-21T00:00:00.000000 |
| certfr-2024-avi-0152 | Multiples vulnérabilités dans Google Chrome | 2024-02-21T00:00:00.000000 | 2024-02-21T00:00:00.000000 |
| certfr-2024-avi-0150 | Multiples vulnérabilités dans les produits Mozilla | 2024-02-21T00:00:00.000000 | 2024-02-21T00:00:00.000000 |
| certfr-2024-avi-0149 | Multiples vulnérabilités dans Moodle | 2024-02-20T00:00:00.000000 | 2024-02-20T00:00:00.000000 |
| certfr-2024-avi-0148 | Vulnérabilité dans Kaspersky Anti Targeted Attack | 2024-02-20T00:00:00.000000 | 2024-02-20T00:00:00.000000 |
| certfr-2024-avi-0147 | Vulnérabilité dans Spring Security | 2024-02-19T00:00:00.000000 | 2024-02-19T00:00:00.000000 |
| certfr-2024-avi-0139 | Multiples vulnérabilités dans les produits Palo Alto Networks | 2024-02-15T00:00:00.000000 | 2024-02-19T00:00:00.000000 |
| certfr-2024-avi-0146 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0145 | Multiples vulnérabilités dans les produits IBM | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0144 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0143 | Multiples vulnérabilités dans le noyau Linux Ubuntu | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0142 | Vulnérabilité dans NetApp SnapCenter | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0141 | Vulnérabilité dans Liferay | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0140 | Multiples vulnérabilités dans Liferay | 2024-02-15T00:00:00.000000 | 2024-02-15T00:00:00.000000 |
| certfr-2024-avi-0138 | Vulnérabilité dans Stormshield Network Security | 2024-02-15T00:00:00.000000 | 2024-02-15T00:00:00.000000 |
| certfr-2024-avi-0137 | Multiples vulnérabilités dans les produits F5 | 2024-02-15T00:00:00.000000 | 2024-02-15T00:00:00.000000 |
| certfr-2024-avi-0136 | Vulnérabilité dans les produits ESET | 2024-02-15T00:00:00.000000 | 2024-02-15T00:00:00.000000 |
| certfr-2024-avi-0135 | Vulnérabilité dans Squid | 2024-02-15T00:00:00.000000 | 2024-02-15T00:00:00.000000 |
| certfr-2024-avi-0134 | Multiples vulnérabilités dans les produits Tenable | 2024-02-15T00:00:00.000000 | 2024-02-15T00:00:00.000000 |
| certfr-2024-avi-0133 | Multiples vulnérabilités dans Nginx | 2024-02-15T00:00:00.000000 | 2024-02-15T00:00:00.000000 |
| certfr-2024-avi-0132 | Vulnérabilité dans Grafana | 2024-02-15T00:00:00.000000 | 2024-02-15T00:00:00.000000 |
| certfr-2024-avi-0131 | Multiples vulnérabilités dans les produits Microsoft | 2024-02-14T00:00:00.000000 | 2024-02-14T00:00:00.000000 |
| certfr-2024-avi-0130 | Multiples vulnérabilités dans Microsoft Azure | 2024-02-14T00:00:00.000000 | 2024-02-14T00:00:00.000000 |
| certfr-2024-avi-0129 | Multiples vulnérabilités dans Microsoft .Net | 2024-02-14T00:00:00.000000 | 2024-02-14T00:00:00.000000 |
| certfr-2024-avi-0128 | Multiples vulnérabilités dans Microsoft Windows | 2024-02-14T00:00:00.000000 | 2024-02-14T00:00:00.000000 |
| certfr-2024-avi-0127 | Multiples vulnérabilités dans Microsoft Office | 2024-02-14T00:00:00.000000 | 2024-02-14T00:00:00.000000 |
| certfr-2024-avi-0126 | Vulnérabilité dans Google Chrome | 2024-02-14T00:00:00.000000 | 2024-02-14T00:00:00.000000 |
| certfr-2024-avi-0125 | Multiples vulnérabilités dans SAP | 2024-02-14T00:00:00.000000 | 2024-02-14T00:00:00.000000 |
| certfr-2024-avi-0124 | Multiples vulnérabilités dans les produits Intel | 2024-02-14T00:00:00.000000 | 2024-02-14T00:00:00.000000 |