Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-82269 | 8.6 (v4.0) 8.1 (v3.1) | Gophish Account Lockout and Forced Password Change Byp… |
gophish |
gophish |
2026-08-28T16:18:52.778Z | 2026-08-28T20:29:19.133Z |
| cve-2026-55834 | Pocket ID: Open Redirect on the OIDC /authorize page v… |
pocket-id |
pocket-id |
2026-08-28T16:27:58.324Z | 2026-08-28T20:28:38.924Z | |
| cve-2026-82264 | 6.1 (v4.0) 6.8 (v3.1) | Duplicacy Path Traversal during Restore via Unsanitize… |
gilbertchen |
duplicacy |
2026-08-28T16:18:49.329Z | 2026-08-28T20:28:04.153Z |
| cve-2026-82283 | 8.6 (v4.0) 8.1 (v3.1) | VoltAgent Memory API Handlers Missing Ownership Checks |
VoltAgent |
voltagent |
2026-08-28T16:19:02.446Z | 2026-08-28T20:27:20.972Z |
| cve-2026-82278 | 8.7 (v4.0) 8.8 (v3.1) | BISHENG Authenticated Arbitrary Python Code Execution … |
dataelement |
bisheng |
2026-08-28T16:18:58.973Z | 2026-08-28T20:26:23.410Z |
| cve-2026-82279 | 7.2 (v4.0) 8.1 (v3.1) | HyperDX Team Management Operations Missing Role-Based … |
hyperdxio |
hyperdx |
2026-08-28T16:18:59.661Z | 2026-08-28T20:25:37.335Z |
| cve-2026-82273 | 7.1 (v4.0) 6.5 (v3.1) | Mastra Memory API Thread Ownership Check Is a No-op Wh… |
mastra-ai |
mastra |
2026-08-28T16:18:55.518Z | 2026-08-28T20:25:25.139Z |
| cve-2026-82268 | 8.7 (v4.0) 7.5 (v3.1) | Qwen-Agent Server-Side Request Forgery via Caller-Supp… |
QwenLM |
Qwen-Agent |
2026-08-28T16:18:52.089Z | 2026-08-28T20:24:39.353Z |
| cve-2026-82263 | 8.2 (v4.0) 6.8 (v3.1) | Logto Server-Side Request Forgery via OIDC SSO Connect… |
logto-io |
logto |
2026-08-28T16:18:48.639Z | 2026-08-28T20:23:27.541Z |
| cve-2026-82284 | 8.6 (v4.0) 8.1 (v3.1) | Quivr Chat Endpoints Missing Ownership Validation |
QuivrHQ |
quivr |
2026-08-28T16:19:03.152Z | 2026-08-28T20:23:13.732Z |
| cve-2026-82288 | 8.7 (v4.0) 7.5 (v3.1) | Stable Diffusion WebUI Credential Disclosure via /sdap… |
AUTOMATIC1111 |
stable-diffusion-webui |
2026-08-28T16:19:05.909Z | 2026-08-28T20:22:40.670Z |
| cve-2026-55108 | KubeVela Terraform remote loader DoS via unbounded file read |
kubevela |
kubevela |
2026-08-28T16:11:58.923Z | 2026-08-28T20:21:47.902Z | |
| cve-2026-82289 | 8.3 (v4.0) 7.4 (v3.1) | Gitingest Prefix-Based Git Host Check Enables Request … |
coderamp-labs |
gitingest |
2026-08-28T16:19:06.587Z | 2026-08-28T20:21:01.003Z |
| cve-2026-54746 | Hatchet: Cross-tenant write/DoS to other tenants' work… |
hatchet-dev |
hatchet |
2026-08-28T16:08:37.816Z | 2026-08-28T20:20:37.452Z | |
| cve-2026-82274 | 5.3 (v4.0) 4.7 (v3.1) | Twenty Open Redirect via OAuth Propagator Callback |
twentyhq |
twenty |
2026-08-28T16:18:56.238Z | 2026-08-28T20:18:56.881Z |
| cve-2026-56854 | N/A | Source-address critical option not enforced for non-pu… |
golang.org/x/crypto |
golang.org/x/crypto/ssh |
2026-08-28T15:14:26.918Z | 2026-08-28T20:17:17.397Z |
| cve-2026-38638 | N/A | An issue in the with_argv function (/unistd/mod.r… |
n/a |
n/a |
2026-08-28T00:00:00.000Z | 2026-08-28T20:13:44.478Z |
| cve-2026-38636 | N/A | An issue in the seekdir() function (/dirent/mod.r… |
n/a |
n/a |
2026-08-28T00:00:00.000Z | 2026-08-28T20:10:15.360Z |
| cve-2026-55634 | Pimcore: Remote Code Execution via DataObject Class-De… |
pimcore |
pimcore |
2026-08-28T19:16:20.078Z | 2026-08-28T20:06:15.024Z | |
| cve-2026-37751 | N/A | An OS command injection vulnerability in the kill… |
n/a |
n/a |
2026-08-28T00:00:00.000Z | 2026-08-28T20:02:53.696Z |
| cve-2026-55484 | ALOS HTTP: Unauthenticated remote DoS: malformed path … |
guno1928 |
alos-http |
2026-08-28T19:19:19.749Z | 2026-08-28T20:00:26.302Z | |
| cve-2026-59313 | N/A | Server Sent Event stream corruption in Spring MVC func… |
Spring |
Spring Framework |
2026-08-27T17:58:03.621Z | 2026-08-28T19:59:45.069Z |
| cve-2026-54766 | Vikunja: Project duplication bypasses write-permission… |
go-vikunja |
vikunja |
2026-08-28T16:36:57.857Z | 2026-08-28T19:59:25.820Z | |
| cve-2026-55559 | Yamcs: Remote Code Execution via instance-template arg… |
yamcs |
yamcs |
2026-08-28T17:22:07.633Z | 2026-08-28T19:58:04.713Z | |
| cve-2026-55067 | Vikunja: Authenticated cross-tenant kanban-bucket relo… |
go-vikunja |
vikunja |
2026-08-28T16:53:59.656Z | 2026-08-28T19:55:24.677Z | |
| cve-2026-55245 | Bifrost: SSRF deny-list incomplete: isPublicIP permits… |
maximhq |
bifrost |
2026-08-28T18:24:16.723Z | 2026-08-28T19:54:10.966Z | |
| cve-2026-55521 | Yamcs : Multiple Missing Function Level Access Control… |
yamcs |
yamcs |
2026-08-28T17:08:16.725Z | 2026-08-28T19:52:43.290Z | |
| cve-2025-32736 | 4.9 (v4.0) | PingFederate Administrative Console CSRF weaknesses |
Ping Identity |
PingFederate |
2026-08-10T21:54:21.818Z | 2026-08-28T19:40:37.084Z |
| cve-2026-20746 | 6.3 (v4.0) | PingDirectory copying of virtual attributes leads to m… |
Ping Identity |
PingDirectory |
2026-06-12T02:16:59.690Z | 2026-08-28T19:38:00.743Z |
| cve-2026-37067 | N/A | Incorrect access control in /vfm-admin/admin-pane… |
n/a |
n/a |
2026-08-27T00:00:00.000Z | 2026-08-28T19:32:56.749Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2023-avi-1012 | Multiples vulnérabilités dans LibreOffice | 2023-12-11T00:00:00.000000 | 2023-12-11T00:00:00.000000 |
| certfr-2023-avi-1011 | Multiples vulnérabilités dans les produits Qnap | 2023-12-11T00:00:00.000000 | 2023-12-11T00:00:00.000000 |
| certfr-2023-avi-1010 | Multiples vulnérabilités dans les produits Ivanti | 2023-12-11T00:00:00.000000 | 2023-12-11T00:00:00.000000 |
| certfr-2023-avi-0995 | Multiples vulnérabilités dans Google Android | 2023-12-05T00:00:00.000000 | 2023-12-11T00:00:00.000000 |
| certfr-2023-avi-1009 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2023-12-08T00:00:00.000000 | 2023-12-08T00:00:00.000000 |
| certfr-2023-avi-1008 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2023-12-08T00:00:00.000000 | 2023-12-08T00:00:00.000000 |
| certfr-2023-avi-1007 | Multiples vulnérabilités dans les produits IBM | 2023-12-08T00:00:00.000000 | 2023-12-08T00:00:00.000000 |
| certfr-2023-avi-1006 | Multiples vulnérabilités dans Microsoft Edge | 2023-12-08T00:00:00.000000 | 2023-12-08T00:00:00.000000 |
| certfr-2023-avi-1004 | Multiples vulnérabilités dans Nagios XI | 2023-12-07T00:00:00.000000 | 2023-12-07T00:00:00.000000 |
| certfr-2023-avi-1003 | Vulnérabilité dans WordPress | 2023-12-07T00:00:00.000000 | 2023-12-07T00:00:00.000000 |
| certfr-2023-avi-1002 | Vulnérabilité dans MISP | 2023-12-07T00:00:00.000000 | 2023-12-07T00:00:00.000000 |
| certfr-2023-avi-1001 | Vulnérabilité dans Atlassian Confluence | 2023-12-06T00:00:00.000000 | 2023-12-06T00:00:00.000000 |
| certfr-2023-avi-1000 | Multiples vulnérabilités dans Progress MOVEit Transfer | 2023-12-06T00:00:00.000000 | 2023-12-06T00:00:00.000000 |
| certfr-2023-avi-0999 | Vulnérabilité dans ElasticSearch pour Hadoop | 2023-12-06T00:00:00.000000 | 2023-12-06T00:00:00.000000 |
| certfr-2023-avi-0998 | Multiples vulnérabilités dans Google Chrome | 2023-12-06T00:00:00.000000 | 2023-12-06T00:00:00.000000 |
| certfr-2023-avi-0997 | Vulnérabilité dans SolarWinds Serv-U | 2023-12-06T00:00:00.000000 | 2023-12-06T00:00:00.000000 |
| certfr-2023-avi-0996 | Vulnérabilité dans TheGreenBow VPN Client | 2023-12-05T00:00:00.000000 | 2023-12-05T00:00:00.000000 |
| certfr-2023-avi-0994 | Multiples vulnérabilités dans SonicWall SMA | 2023-12-05T00:00:00.000000 | 2023-12-05T00:00:00.000000 |
| certfr-2023-avi-0993 | Multiples vulnérabilités dans Squid | 2023-12-04T00:00:00.000000 | 2023-12-04T00:00:00.000000 |
| certfr-2023-avi-0992 | Vulnérabilité dans SolarWinds Platform | 2023-12-01T00:00:00.000000 | 2023-12-01T00:00:00.000000 |
| certfr-2023-avi-0991 | Multiples vulnérabilités dans GitLab | 2023-12-01T00:00:00.000000 | 2023-12-01T00:00:00.000000 |
| certfr-2023-avi-0990 | Multiples vulnérabilités dans les produits IBM | 2023-12-01T00:00:00.000000 | 2023-12-01T00:00:00.000000 |
| certfr-2023-avi-0989 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2023-12-01T00:00:00.000000 | 2023-12-01T00:00:00.000000 |
| certfr-2023-avi-0988 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2023-12-01T00:00:00.000000 | 2023-12-01T00:00:00.000000 |
| certfr-2023-avi-0987 | Multiples vulnérabilités dans les produits Apple | 2023-12-01T00:00:00.000000 | 2023-12-01T00:00:00.000000 |
| certfr-2023-avi-0986 | Multiples vulnérabilités dans Tenable Nessus Network Monitor | 2023-11-30T00:00:00.000000 | 2023-11-30T00:00:00.000000 |
| certfr-2023-avi-0985 | Multiples vulnérabilités dans Microsoft Edge | 2023-11-30T00:00:00.000000 | 2023-11-30T00:00:00.000000 |
| certfr-2023-avi-0984 | Multiples vulnérabilités dans les produits Axis | 2023-11-29T00:00:00.000000 | 2023-11-30T00:00:00.000000 |
| certfr-2023-avi-0983 | Multiples vulnérabilités dans Google Chrome | 2023-11-29T00:00:00.000000 | 2023-11-29T00:00:00.000000 |
| certfr-2023-avi-0982 | Vulnérabilité dans Apache Tomcat | 2023-11-29T00:00:00.000000 | 2023-11-29T00:00:00.000000 |