Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-82239 | 8.6 (v4.0) 8.1 (v3.1) | Budibase before 3.41.3 Authorization Bypass via dataso… |
budibase |
server |
2026-08-28T10:49:28.004Z | 2026-08-28T15:44:26.965Z |
| cve-2026-82238 | 2.3 (v4.0) 3.1 (v3.1) | filebrowser 2.24.0 Race Condition via TUS concurrent P… |
filebrowser |
filebrowser |
2026-08-28T10:49:27.289Z | 2026-08-28T10:49:27.289Z |
| cve-2026-82237 | 2.3 (v4.0) 3.1 (v3.1) | filebrowser through 2.63.23 Stale Share Link via File Rename |
filebrowser |
filebrowser |
2026-08-28T10:49:26.624Z | 2026-08-28T14:00:00.263Z |
| cve-2026-82236 | 2.3 (v4.0) 3.1 (v3.1) | File Browser 2.63.6 through 2.63.23 Share Link Exposur… |
filebrowser |
filebrowser |
2026-08-28T10:49:25.873Z | 2026-08-28T14:49:07.319Z |
| cve-2026-82235 | 8.2 (v4.0) 5.9 (v3.1) | filebrowser through 2.63.23 Denial of Service via name… |
filebrowser |
filebrowser |
2026-08-28T10:49:25.222Z | 2026-08-28T15:53:04.375Z |
| cve-2026-82234 | 8.4 (v4.0) 8.2 (v3.1) | SiYuan before v3.8.1 SSRF via DNS-Rebinding TOCTOU |
siyuan-note |
siyuan |
2026-08-28T10:49:24.564Z | 2026-08-28T16:10:07.633Z |
| cve-2026-82233 | 6.9 (v4.0) 5.7 (v3.1) | SiYuan before v3.8.1 Path Traversal via asset.upload |
siyuan-note |
siyuan |
2026-08-28T10:49:23.913Z | 2026-08-28T10:49:23.913Z |
| cve-2026-81733 | 5.1 (v4.0) | WWBN AVideo through 30.0 CSRF via myLiveControls.save.… |
WWBN |
AVideo |
2026-08-28T10:49:23.235Z | 2026-08-29T11:48:17.019Z |
| cve-2026-81732 | 6.9 (v4.0) | WWBN AVideo through 30.0 Information Disclosure via re… |
WWBN |
AVideo |
2026-08-28T10:49:22.529Z | 2026-08-29T11:48:16.299Z |
| cve-2026-82222 | 10 (v3.1) | WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Exec… |
Liquid Web / StellarWP |
GiveWP |
2026-08-28T10:46:14.315Z | 2026-08-28T14:50:53.520Z |
| cve-2026-73209 | 6.5 (v3.1) | An attacker that has valid credentials can send c… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:33.625Z | 2026-08-28T15:53:12.773Z |
| cve-2026-73208 | 7.4 (v3.1) | An attacker that holds a token intended for a dif… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:32.679Z | 2026-08-28T15:53:21.257Z |
| cve-2026-52687 | 6.5 (v3.1) | An attacker that has valid credentials can select… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:31.701Z | 2026-08-28T15:53:30.084Z |
| cve-2026-52681 | 3.1 (v3.1) | Sieve CPU resource usage is tracked in the compil… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:30.766Z | 2026-08-28T15:53:36.937Z |
| cve-2026-42395 | 4.3 (v3.1) | A host listed as a trusted proxy can send forward… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:29.710Z | 2026-08-28T15:53:43.599Z |
| cve-2026-42393 | 3.1 (v3.1) | The comparison used for the doveadm password and … |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:28.849Z | 2026-08-28T15:53:51.809Z |
| cve-2026-42392 | 4.3 (v3.1) | An attacker that has valid credentials can send a… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:27.979Z | 2026-08-28T15:53:58.772Z |
| cve-2026-42391 | 7.5 (v3.1) | An unauthenticated attacker can send an IMAP ID c… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:27.000Z | 2026-08-28T15:54:09.305Z |
| cve-2026-42008 | 4.3 (v3.1) | Forwarding information received from a host liste… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:26.018Z | 2026-08-28T15:54:17.203Z |
| cve-2026-42007 | 9.1 (v3.1) | An attacker that has valid credentials can use a … |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:25.136Z | 2026-08-28T15:54:24.354Z |
| cve-2026-40205 | 5.9 (v3.1) | An attacker that holds an OAuth2 token granting o… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:24.186Z | 2026-08-28T14:56:09.120Z |
| cve-2026-40204 | 3.1 (v3.1) | None None None No publicly available exploits are… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:23.236Z | 2026-08-28T14:56:40.510Z |
| cve-2026-40203 | 3.7 (v3.1) | When IMAP compression is enabled, the same compre… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:22.287Z | 2026-08-28T14:57:07.686Z |
| cve-2026-40019 | 5.9 (v3.1) | An unauthenticated attacker can send a truncated … |
Open-Xchange GmbH |
OX Dovecot CE |
2026-08-28T10:12:21.390Z | 2026-08-28T14:58:20.016Z |
| cve-2026-40018 | 7.4 (v3.1) | None None None No publicly available exploits are… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:20.457Z | 2026-08-28T15:00:32.995Z |
| cve-2026-40017 | 6.5 (v3.1) | An attacker that can send mail to a user can craf… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:19.524Z | 2026-08-28T15:02:36.570Z |
| cve-2026-40015 | 4.3 (v3.1) | An attacker that has valid credentials can open m… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:18.576Z | 2026-08-28T15:03:07.769Z |
| cve-2026-40014 | 6.5 (v3.1) | An attacker that can send mail to a user can craf… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:17.711Z | 2026-08-28T15:54:30.823Z |
| cve-2026-40013 | 4.3 (v3.1) | An attacker that has valid credentials can submit… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:16.751Z | 2026-08-28T15:54:38.082Z |
| cve-2026-33607 | 4.3 (v3.1) | An attacker that has valid credentials can use IM… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:15.779Z | 2026-08-28T15:54:47.683Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2025-000010 | acmailer vulnerable to cross-site scripting | 2025-02-12T15:05+09:00 | 2025-02-12T15:05+09:00 |
| jvndb-2025-001017 | Multiple vulnerabilities in STEALTHONE D220/D340/D440 | 2025-02-06T18:27+09:00 | 2025-02-06T18:27+09:00 |
| jvndb-2025-001016 | OMRON NJ/NX series vulnerable to path traversal | 2025-02-06T18:27+09:00 | 2025-05-08T17:44+09:00 |
| jvndb-2025-001018 | Improper restriction of XML external entity reference (XXE) vulnerability in OMRON NB-Designer | 2025-02-06T18:26+09:00 | 2025-02-06T18:26+09:00 |
| jvndb-2025-000008 | Multiple vulnerabilities in Defense Platform Home Edition | 2025-02-05T14:06+09:00 | 2025-02-05T14:06+09:00 |
| jvndb-2025-000009 | WordPress Plugin "Activity Log WinterLock" vulnerable to cross-site request forgery | 2025-02-04T13:58+09:00 | 2025-02-04T13:58+09:00 |
| jvndb-2025-001244 | Clickjacking Vulnerability in JP1/ServerConductor/Deployment Manager | 2025-01-30T18:19+09:00 | 2025-01-30T18:19+09:00 |
| jvndb-2025-000007 | SXF Common Library vulnerable to improper input data handling | 2025-01-29T14:57+09:00 | 2025-01-29T14:57+09:00 |
| jvndb-2025-001238 | Multiple out-of-bounds write vulnerabilities in Canon Office/Small Office Multifunction Printers and Laser Printers | 2025-01-29T13:41+09:00 | 2025-05-27T16:06+09:00 |
| jvndb-2025-000006 | WordPress Plugin "Simple Image Sizes" vulnerable to cross-site scripting | 2025-01-28T13:44+09:00 | 2025-01-28T13:44+09:00 |
| jvndb-2025-000005 | EXIF Viewer Classic vulnerable to cross-site scripting | 2025-01-27T14:25+09:00 | 2025-01-27T14:25+09:00 |
| jvndb-2025-000004 | Multiple vulnerabilities in I-O DATA router UD-LT2 | 2025-01-22T13:55+09:00 | 2025-02-20T15:55+09:00 |
| jvndb-2025-000003 | FortiWeb vulnerable to SQL injection | 2025-01-21T15:59+09:00 | 2025-01-21T15:59+09:00 |
| jvndb-2025-001027 | Linux Ratfor vulnerable to stack-based buffer overflow | 2025-01-16T13:27+09:00 | 2025-01-16T13:27+09:00 |
| jvndb-2025-000001 | PLANEX COMMUNICATIONS MZK-DP300N vulnerable to cross-site scripting | 2025-01-08T17:08+09:00 | 2025-01-08T17:08+09:00 |
| jvndb-2024-015471 | Trend Micro Deep Security 20.0 Agent (for Windows) vulnerable to uncontrolled search path element | 2024-12-25T11:28+09:00 | 2024-12-25T11:28+09:00 |
| jvndb-2024-015393 | Multiple security updates for Trend Micro Apex One and Apex One as a Service (December 2024) | 2024-12-23T12:52+09:00 | 2024-12-23T12:52+09:00 |
| jvndb-2024-014918 | Authentication Bypass Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2024-12-17T15:23+09:00 | 2024-12-17T15:23+09:00 |
| jvndb-2024-000128 | Multiple vulnerabilities in SHARP routers | 2024-12-17T07:54+09:00 | 2024-12-17T07:54+09:00 |
| jvndb-2024-000127 | "Shonen Jump+" App for Android fails to restrict custom URL schemes properly | 2024-12-16T15:07+09:00 | 2024-12-16T15:07+09:00 |
| jvndb-2024-014825 | WordPress Plugin "My WP Customize Admin/Frontend" vulnerable to cross-site scripting | 2024-12-16T13:57+09:00 | 2024-12-16T13:57+09:00 |
| jvndb-2024-014793 | Multiple vulnerabilities in FXC AE1021 and AE1021PE | 2024-12-16T11:51+09:00 | 2024-12-16T11:51+09:00 |
| jvndb-2024-014079 | Trend Micro Deep Security Agent for Windows and Deep Security Notifier on DSVA vulnerable to OS command injection | 2024-12-06T12:11+09:00 | 2024-12-06T12:11+09:00 |
| jvndb-2024-000125 | Multiple vulnerabilities in I-O DATA routers UD-LT1 and UD-LT1/EX | 2024-12-04T15:22+09:00 | 2024-12-18T15:20+09:00 |
| jvndb-2024-000124 | Multiple vulnerabilities in UNIVERGE IX/IX-R/IX-V series routers | 2024-12-02T16:38+09:00 | 2024-12-02T16:38+09:00 |
| jvndb-2024-000123 | Multiple FCNT Android devices vulnerable to authentication bypass | 2024-11-29T15:30+09:00 | 2024-11-29T15:30+09:00 |
| jvndb-2024-013702 | Multiple vulnerabilities in FUJI ELECTRIC products | 2024-11-29T14:42+09:00 | 2024-11-29T14:42+09:00 |
| jvndb-2024-000122 | HAProxy vulnerable to HTTP request/response smuggling | 2024-11-27T14:36+09:00 | 2024-11-27T14:36+09:00 |
| jvndb-2024-000121 | WordPress Plugin "WP Admin UI Customize" vulnerable to cross-site scripting | 2024-11-26T13:57+09:00 | 2024-11-26T13:57+09:00 |
| jvndb-2024-013260 | Multiple vulnerabilities in Edgecross Basic Software for Windows | 2024-11-22T10:59+09:00 | 2025-11-04T16:41+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2026-avi-0735 | Multiples vulnérabilités dans MongoDB | 2026-06-11T00:00:00.000000 | 2026-06-11T00:00:00.000000 |
| certfr-2026-avi-0734 | Multiples vulnérabilités dans les produits Palo Alto Networks | 2026-06-11T00:00:00.000000 | 2026-06-11T00:00:00.000000 |
| certfr-2026-avi-0733 | Multiples vulnérabilités dans GitLab | 2026-06-11T00:00:00.000000 | 2026-06-11T00:00:00.000000 |
| certfr-2026-avi-0732 | Vulnérabilité dans LibreNMS | 2026-06-11T00:00:00.000000 | 2026-08-10T00:00:00.000000 |
| certfr-2026-avi-0731 | Multiples vulnérabilités dans les produits Microsoft | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0730 | Multiples vulnérabilités dans Microsoft Azure | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0729 | Multiples vulnérabilités dans Microsoft .Net | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0728 | Multiples vulnérabilités dans Microsoft Windows | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0727 | Multiples vulnérabilités dans Microsoft Office | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0726 | Multiples vulnérabilités dans Microsoft Edge | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0725 | Multiples vulnérabilités dans les produits Fortinet | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0724 | Multiples vulnérabilités dans les produits Ivanti | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0723 | Vulnérabilité dans Stormshield Network Security | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0722 | Multiples vulnérabilités dans Typo3 | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0721 | Multiples vulnérabilités dans Xen | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0720 | Multiples vulnérabilités dans les produits Adobe | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0719 | Multiples vulnérabilités dans les produits Spring | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0718 | Vulnérabilité dans PostgreSQL | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0717 | Multiples vulnérabilités dans OpenSSL | 2026-06-10T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0716 | Multiples vulnérabilités dans FreeBSD | 2026-06-10T00:00:00.000000 | 2026-06-12T00:00:00.000000 |
| certfr-2026-avi-0715 | Multiples vulnérabilités dans les produits SAP | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0714 | Multiples vulnérabilités dans les produits Siemens | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0713 | Vulnérabilité dans les produits Schneider Electric EcoStruxure IT Data Center Expert | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0712 | Vulnérabilité dans Veeam Backup & Replication | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0711 | Multiples vulnérabilités dans les VPN Check Point | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0710 | Multiples vulnérabilités dans Apache HTTP Server | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0709 | Vulnérabilité dans strongSwan | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0708 | Multiples vulnérabilités dans Google Chrome | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0707 | Vulnérabilité dans Moodle | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0706 | Multiples vulnérabilités dans Apereo CAS | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| ID | Description | Published | Updated |
|---|---|---|---|
| certa-2001-ale-016 | Propagation du ver badtrans - variante B | 2001-11-27T00:00:00.000000 | 2001-11-27T00:00:00.000000 |
| certa-2001-ale-015 | Exploitation massive d'une ancienne vulnérabilité de SSH | 2001-11-19T00:00:00.000000 | 2001-11-19T00:00:00.000000 |
| certa-2001-ale-014 | Risque de divulgation de données personnelles/confidentielles par des produits Microsoft | 2001-10-19T00:00:00.000000 | 2001-10-19T00:00:00.000000 |
| certa-2001-ale-013 | Propagation du ver/virus NIMDA (Concept Virus) | 2001-09-19T00:00:00.000000 | 2001-09-19T00:00:00.000000 |
| certa-2001-ale-012 | Rappels concernant les virus | 2001-09-13T00:00:00.000000 | 2002-01-09T00:00:00.000000 |
| certa-2001-ale-011 | <TT>antivirus2001</TT> est un cheval de Troie | 2001-09-10T00:00:00.000000 | 2001-09-13T00:00:00.000000 |
| certa-2001-ale-010 | Propagation du ver "Code Blue" | 2001-09-07T00:00:00.000000 | 2001-09-07T00:00:00.000000 |
| certa-2001-ale-009 | Propagation importante du virus SirCam | 2001-07-24T00:00:00.000000 | 2001-07-26T00:00:00.000000 |
| certa-2001-ale-008 | Propagation du ver « Code Red » | 2001-07-18T00:00:00.000000 | 2001-08-13T00:00:00.000000 |
| certa-2001-ale-007 | Propagation d'un ver affectant sadmind et IIS | 2001-05-09T00:00:00.000000 | 2001-05-09T00:00:00.000000 |
| certa-2001-ale-006 | Prolifération en Europe du virus HOMEPAGE | 2001-05-09T00:00:00.000000 | 2001-05-09T00:00:00.000000 |
| certa-2001-ale-005 | Vulnérabilités dans les modems ADSL d'Alcatel | 2001-04-11T00:00:00.000000 | 2001-04-11T00:00:00.000000 |
| certa-2001-ale-004 | Vulnérabilité dans le démon snmpXdmid sous Sun Solaris | 2001-03-30T00:00:00.000000 | 2001-03-30T00:00:00.000000 |
| certa-2001-ale-003 | Prolifération du ver Li0n | 2001-03-26T00:00:00.000000 | 2001-03-26T00:00:00.000000 |
| certa-2001-ale-002 | Risque d'exploitation des ressources partagées sous Windows | 2001-03-26T00:00:00.000000 | 2001-03-26T00:00:00.000000 |
| certa-2001-ale-001 | Propagation du ver Ramen sous Linux. | 2001-01-19T00:00:00.000000 | 2001-01-19T00:00:00.000000 |
| certa-2000-ale-016 | Connexion à Wanadoo | 2000-11-30T00:00:00.000000 | 2000-11-30T00:00:00.000000 |
| certa-2000-ale-015 | Risque d'usurpation de l'identité de Sun Microsystems | 2000-10-25T00:00:00.000000 | 2000-10-25T00:00:00.000000 |
| certa-2000-ale-013 | Virus VBS Quatro-A | 2000-09-18T00:00:00.000000 | 2000-09-18T00:00:00.000000 |
| certa-2000-ale-014 | Vulnérabilité dans la bibliothèque glibc sous Unix | 2000-09-14T00:00:00.000000 | 2000-09-14T00:00:00.000000 |
| certa-2000-ale-012 | Mauvaise compatibilité des scanners de virus avec NTFS | 2000-09-08T00:00:00.000000 | 2000-09-08T00:00:00.000000 |
| certa-2000-ale-011 | Trojan Simpsons | 2000-06-29T00:00:00.000000 | 2000-06-29T00:00:00.000000 |
| certa-2000-ale-010 | Vulnérabilités dans le serveur de fichier wu-ftpd | 2000-06-26T00:00:00.000000 | 2000-06-26T00:00:00.000000 |
| certa-2000-ale-009 | Ver VBS/Stages-A, Mirc/stages-a, pIRC/Stages-A | 2000-06-20T00:00:00.000000 | 2000-06-20T00:00:00.000000 |
| certa-2000-ale-008 | The Serbian Badman Trojan (TSB) | 2000-06-13T00:00:00.000000 | 2000-06-13T00:00:00.000000 |
| certa-2000-ale-007 | Virus VBS/LoveLet-AS | 2000-06-09T00:00:00.000000 | 2000-06-09T00:00:00.000000 |
| certa-2000-ale-006 | Deni de service sous Firewall-1 | 2000-06-08T00:00:00.000000 | 2000-06-08T00:00:00.000000 |
| certa-2000-ale-005 | Virus macro V97M/Resume.A | 2000-05-29T00:00:00.000000 | 2000-05-29T00:00:00.000000 |
| certa-2000-ale-004 | Virus Macro OF97/Cybernet-A | 2000-05-26T00:00:00.000000 | 2000-05-26T00:00:00.000000 |
| certa-2000-ale-003 | « Mesures de performances » de l'Internet | 2000-05-26T00:00:00.000000 | 2000-05-26T00:00:00.000000 |