Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-34500 | Apache Tomcat: OCSP checks sometimes soft-fail with FF… |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:36:52.857Z | 2026-04-10T14:22:31.310Z | |
| cve-2026-34487 | Apache Tomcat: Cloud membership for clustering compone… |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:36:12.048Z | 2026-04-10T17:49:44.314Z | |
| cve-2026-34486 | Apache Tomcat: Fix for CVE-2026-29146 allowed bypass o… |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:35:35.994Z | 2026-04-10T20:20:56.605Z | |
| cve-2026-40087 | LangChain has incomplete f-string validation in prompt… |
langchain-ai |
langchain |
2026-04-09T19:34:55.198Z | 2026-04-14T14:48:03.160Z | |
| cve-2026-34483 | Apache Tomcat: Incomplete escaping of JSON access logs |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:30:28.874Z | 2026-04-10T20:17:38.858Z | |
| cve-2026-5194 | 9.3 (v4.0) | wolfSSL ECDSA Certificate Verification |
wolfSSL |
wolfSSL |
2026-04-09T19:30:24.095Z | 2026-04-22T03:55:45.778Z |
| cve-2026-5974 | FoundationAgents MetaGPT terminal.py Bash.run os comma… |
FoundationAgents |
MetaGPT |
2026-04-09T19:30:15.216Z | 2026-04-09T20:17:26.123Z | |
| cve-2026-40077 | Beszel has an IDOR in hub API endpoints that read syst… |
henrygd |
beszel |
2026-04-09T19:27:39.364Z | 2026-04-13T20:19:45.967Z | |
| cve-2026-32990 | Apache Tomcat: Fix for CVE-2025-66614 is incomplete |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:23:49.618Z | 2026-04-10T18:39:25.498Z | |
| cve-2026-29146 | Apache Tomcat: EncryptInterceptor vulnerable to paddin… |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:21:57.289Z | 2026-04-10T18:17:59.908Z | |
| cve-2026-29145 | Apache Tomcat, Apache Tomcat Native: OCSP checks somet… |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:20:24.601Z | 2026-04-10T18:11:31.014Z | |
| cve-2026-29129 | Apache Tomcat: TLS cipher order is not preserved |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:19:40.645Z | 2026-04-10T18:06:45.771Z | |
| cve-2026-5973 | FoundationAgents MetaGPT common.py get_mime_type os co… |
FoundationAgents |
MetaGPT |
2026-04-09T19:15:13.464Z | 2026-04-14T16:34:08.668Z | |
| cve-2026-25854 | Apache Tomcat: Occasionally open redirect |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:13:13.529Z | 2026-04-10T18:22:34.359Z | |
| cve-2026-24880 | Apache Tomcat: Request smuggling via invalid chunk extension |
Apache Software Foundation |
Apache Tomcat |
2026-04-09T19:12:10.730Z | 2026-04-10T18:33:49.308Z | |
| cve-2026-39977 | flatpak-builder has a path traversal leading to arbitr… |
flatpak |
flatpak-builder |
2026-04-09T19:05:23.616Z | 2026-04-09T20:19:28.323Z | |
| cve-2026-34734 | HDF5: H5T__conv_struct Use After Free |
HDFGroup |
hdf5 |
2026-04-09T19:01:21.794Z | 2026-04-13T20:47:37.724Z | |
| cve-2026-5972 | FoundationAgents MetaGPT terminal.py Terminal.run_comm… |
FoundationAgents |
MetaGPT |
2026-04-09T19:00:20.513Z | 2026-04-10T14:13:32.555Z | |
| cve-2026-35063 | 8.7 (v4.0) | Missing Authorization in OpenPLC_V3 |
OpenPLC_V3 |
OpenPLC_V3 |
2026-04-09T19:00:09.980Z | 2026-04-10T18:04:45.721Z |
| cve-2026-35556 | 9.2 (v4.0) | Plaintext storage of a password in OpenPLC_V3 |
OpenPLC_V3 |
OpenPLC_V3 |
2026-04-09T18:57:26.857Z | 2026-04-10T18:03:50.288Z |
| cve-2026-35195 | Wasmtime has an out-of-bounds write or crash when tran… |
bytecodealliance |
wasmtime |
2026-04-09T18:55:56.467Z | 2026-04-13T15:38:27.294Z | |
| cve-2026-28205 | 9.2 (v4.0) | Initialization of a resource with an insecure default … |
OpenPLC_V3 |
OpenPLC_V3 |
2026-04-09T18:54:58.694Z | 2026-04-10T18:02:22.971Z |
| cve-2026-35186 | Wasmtime has an improperly masked return value from `t… |
bytecodealliance |
wasmtime |
2026-04-09T18:54:48.760Z | 2026-04-13T20:18:21.954Z | |
| cve-2026-34988 | Wasmtime leaks data between pooling allocator instances |
bytecodealliance |
wasmtime |
2026-04-09T18:52:26.131Z | 2026-04-09T19:31:07.544Z | |
| cve-2026-34987 | Wasmtime with Winch compiler backend on aarch64 may al… |
bytecodealliance |
wasmtime |
2026-04-09T18:48:33.552Z | 2026-04-10T14:12:55.374Z | |
| cve-2026-34983 | Wasmtime has a use-after-free bug after cloning `wasmt… |
bytecodealliance |
wasmtime |
2026-04-09T18:47:26.575Z | 2026-04-13T15:38:33.779Z | |
| cve-2026-34971 | Wasmtime miscompiled guest heap access enables sandbox… |
bytecodealliance |
wasmtime |
2026-04-09T18:45:44.819Z | 2026-04-13T20:17:15.215Z | |
| cve-2026-34946 | Wasmtime's host panics when Winch compiler executes `t… |
bytecodealliance |
wasmtime |
2026-04-09T18:43:39.137Z | 2026-04-09T19:33:33.709Z | |
| cve-2026-34945 | Wasmtime leaks host data with 64-bit tables and Winch |
bytecodealliance |
wasmtime |
2026-04-09T18:40:48.446Z | 2026-04-10T14:12:18.460Z | |
| cve-2026-34944 | Wasmtime segfault or unused out-of-sandbox load with `… |
bytecodealliance |
wasmtime |
2026-04-09T18:38:16.182Z | 2026-04-13T15:38:40.634Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2023-avi-0074 | Vulnérabilité dans Thunderbird | 2023-02-01T00:00:00.000000 | 2023-02-01T00:00:00.000000 |
| certfr-2023-avi-0073 | Multiples vulnérabilités dans les produits IBM | 2023-01-31T00:00:00.000000 | 2023-01-31T00:00:00.000000 |
| certfr-2023-avi-0072 | Vulnérabilité dans les produits Tenable | 2023-01-31T00:00:00.000000 | 2023-01-31T00:00:00.000000 |
| certfr-2023-avi-0071 | Vulnérabilité dans QNAP QTS et QuTS hero | 2023-01-30T00:00:00.000000 | 2023-01-30T00:00:00.000000 |
| certfr-2023-avi-0070 | Multiples vulnérabilités dans MISP | 2023-01-30T00:00:00.000000 | 2023-01-30T00:00:00.000000 |
| certfr-2023-avi-0069 | Multiples vulnérabilités dans le noyaux Linux de Debian | 2023-01-27T00:00:00.000000 | 2023-01-27T00:00:00.000000 |
| certfr-2023-avi-0068 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2023-01-27T00:00:00.000000 | 2023-01-27T00:00:00.000000 |
| certfr-2023-avi-0067 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2023-01-27T00:00:00.000000 | 2023-01-27T00:00:00.000000 |
| certfr-2023-avi-0066 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2023-01-27T00:00:00.000000 | 2023-01-27T00:00:00.000000 |
| certfr-2023-avi-0065 | Multiples vulnérabilités dans Microsoft Edge | 2023-01-27T00:00:00.000000 | 2023-01-27T00:00:00.000000 |
| certfr-2023-avi-0064 | Multiples vulnérabilités dans Stormshield SSL VPN Client | 2023-01-27T00:00:00.000000 | 2023-01-27T00:00:00.000000 |
| certfr-2023-avi-0063 | Vulnérabilité dans Grafana | 2023-01-26T00:00:00.000000 | 2023-01-26T00:00:00.000000 |
| certfr-2023-avi-0062 | Vulnérabilité dans Xen libxl | 2023-01-26T00:00:00.000000 | 2023-01-26T00:00:00.000000 |
| certfr-2023-avi-0061 | Multiples vulnérabilités dans Tenable.sc | 2023-01-26T00:00:00.000000 | 2023-01-26T00:00:00.000000 |
| certfr-2023-avi-0060 | Multiples vulnérabilités dans IBM QRadar WinCollect Agent | 2023-01-26T00:00:00.000000 | 2023-01-26T00:00:00.000000 |
| certfr-2023-avi-0059 | Multiples vulnérabilités dans ISC BIND | 2023-01-26T00:00:00.000000 | 2023-01-26T00:00:00.000000 |
| certfr-2023-avi-0058 | Multiples vulnérabilités dans VMware vRealize Log Insight | 2023-01-25T00:00:00.000000 | 2023-01-25T00:00:00.000000 |
| certfr-2023-avi-0057 | Multiples vulnérabilités dans Google Chrome | 2023-01-25T00:00:00.000000 | 2023-01-25T00:00:00.000000 |
| certfr-2023-avi-0056 | Multiples vulnérabilités dans les produits Apple | 2023-01-24T00:00:00.000000 | 2023-01-24T00:00:00.000000 |
| certfr-2023-avi-0055 | Vulnérabilité dans IBM WebSphere Application Server | 2023-01-24T00:00:00.000000 | 2023-01-24T00:00:00.000000 |
| certfr-2023-avi-0054 | Multiples vulnérabilités dans Moodle | 2023-01-24T00:00:00.000000 | 2023-01-24T00:00:00.000000 |
| certfr-2023-avi-0053 | Multiples vulnérabilités dans Elastic Endpoint et Security | 2023-01-24T00:00:00.000000 | 2023-01-24T00:00:00.000000 |
| certfr-2023-avi-0052 | Multiples vulnérabilités dans Mozilla Thunderbird | 2023-01-23T00:00:00.000000 | 2023-01-23T00:00:00.000000 |
| certfr-2023-avi-0051 | Multiples vulnérabilités dans les produits Juniper | 2023-01-23T00:00:00.000000 | 2023-01-23T00:00:00.000000 |
| certfr-2023-avi-0050 | Multiples vulnérabilités dans Broadcom Symantec Identity Manager | 2023-01-23T00:00:00.000000 | 2023-01-23T00:00:00.000000 |
| certfr-2023-avi-0049 | Vulnérabilité dans PostgreSQL Pgpool-II | 2023-01-23T00:00:00.000000 | 2023-01-23T00:00:00.000000 |
| certfr-2023-avi-0048 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2023-01-20T00:00:00.000000 | 2023-01-20T00:00:00.000000 |
| certfr-2023-avi-0047 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2023-01-20T00:00:00.000000 | 2023-01-20T00:00:00.000000 |
| certfr-2023-avi-0046 | Multiples vulnérabilités dans Microsoft Edge | 2023-01-20T00:00:00.000000 | 2023-01-20T00:00:00.000000 |
| certfr-2023-avi-0045 | Vulnérabilité dans Sonicwall Secure Mobile Access | 2023-01-20T00:00:00.000000 | 2023-01-20T00:00:00.000000 |