Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-32590 | 7.1 (v3.1) | Mirror-registry: remote code execution using pickle de… |
Red Hat |
mirror registry for Red Hat OpenShift |
2026-04-08T17:04:22.870Z | 2026-04-21T23:33:34.858Z |
| cve-2026-32589 | 7.4 (v3.1) | Mirror-registry: quay: insecure direct object referenc… |
Red Hat |
mirror registry for Red Hat OpenShift |
2026-04-08T17:04:20.284Z | 2026-04-28T06:09:02.117Z |
| cve-2026-33466 | 8.1 (v3.1) | Improper Limitation of a Pathname to a Restricted Dire… |
Elastic |
Logstash |
2026-04-08T16:50:42.186Z | 2026-04-10T03:56:01.015Z |
| cve-2026-33458 | 6.8 (v3.1) | Server-Side Request Forgery (SSRF) in Kibana One Workf… |
Elastic |
Kibana |
2026-04-08T16:47:58.462Z | 2026-04-08T19:22:33.432Z |
| cve-2026-33459 | 6.5 (v3.1) | Uncontrolled Resource Consumption in Kibana Leading to… |
Elastic |
Kibana |
2026-04-08T16:46:02.601Z | 2026-04-09T14:24:44.912Z |
| cve-2026-33460 | 4.3 (v3.1) | Incorrect Authorization in Kibana Fleet Leading to Inf… |
Elastic |
Kibana |
2026-04-08T16:43:30.788Z | 2026-04-09T14:26:20.085Z |
| cve-2025-14243 | 5.3 (v3.1) | Mirror-registry: openshift mirror registry: user enume… |
Red Hat |
mirror registry for Red Hat OpenShift |
2026-04-08T16:41:55.597Z | 2026-04-08T21:46:14.175Z |
| cve-2026-33461 | 7.7 (v3.1) | Incorrect Authorization in Kibana Fleet Leading to Inf… |
Elastic |
Kibana |
2026-04-08T16:41:27.335Z | 2026-04-09T14:27:16.151Z |
| cve-2026-4498 | 7.7 (v3.1) | Execution with Unnecessary Privileges in Kibana Leadin… |
Elastic |
Kibana |
2026-04-08T16:38:59.327Z | 2026-04-09T14:27:38.420Z |
| cve-2026-2377 | 6.5 (v3.1) | Mirror-registry: quay: quay: server-side request forge… |
Red Hat |
mirror registry for Red Hat OpenShift |
2026-04-08T16:26:07.649Z | 2026-04-09T13:49:27.203Z |
| cve-2026-4837 | 6.6 (v3.1) | Eval Injection in Rapid7 Insight Agent |
Rapid7 |
Insight Agent |
2026-04-08T15:59:03.121Z | 2026-04-13T13:04:16.829Z |
| cve-2026-33753 | Improper Certificate Validation in rfc3161-client |
trailofbits |
rfc3161-client |
2026-04-08T14:54:59.704Z | 2026-04-08T16:12:57.796Z | |
| cve-2026-33229 | XWiki Platform affected by remote code execution with … |
xwiki |
xwiki-platform |
2026-04-08T14:53:35.977Z | 2026-04-10T20:33:15.897Z | |
| cve-2026-39410 | Hono has a non-breaking space prefix bypass in cookie … |
honojs |
hono |
2026-04-08T14:44:40.797Z | 2026-04-08T15:17:14.892Z | |
| cve-2026-39409 | Hono has incorrect IP matching in ipRestriction() for … |
honojs |
hono |
2026-04-08T14:43:36.476Z | 2026-04-08T16:13:05.175Z | |
| cve-2026-39408 | Hono has a path traversal in toSSG() allows writing fi… |
honojs |
hono |
2026-04-08T14:42:25.357Z | 2026-04-10T20:31:47.508Z | |
| cve-2026-39407 | Hono has a middleware bypass via repeated slashes in s… |
honojs |
hono |
2026-04-08T14:41:20.301Z | 2026-04-08T16:04:59.862Z | |
| cve-2026-39406 | @hono/node-server has a middleware bypass via repeated… |
honojs |
node-server |
2026-04-08T14:34:30.543Z | 2026-04-08T15:17:38.121Z | |
| cve-2026-39394 | CI4MS has an .env CRLF Injection via Unvalidated `host… |
ci4-cms-erp |
ci4ms |
2026-04-08T14:32:31.680Z | 2026-04-08T16:13:10.966Z | |
| cve-2026-39393 | Post-Installation Re-entry via Cache-Dependent Install… |
ci4-cms-erp |
ci4ms |
2026-04-08T14:31:44.692Z | 2026-04-10T20:29:43.521Z | |
| cve-2026-39392 | CI4MS has Stored XSS in Pages Content Due to Missing h… |
ci4-cms-erp |
ci4ms |
2026-04-08T14:30:59.132Z | 2026-04-08T16:05:26.652Z | |
| cve-2026-39391 | CI4MS has Stored XSS via Unescaped Blacklist Note in A… |
ci4-cms-erp |
ci4ms |
2026-04-08T14:30:18.750Z | 2026-04-08T15:18:08.667Z | |
| cve-2026-39390 | CI4MS has Stored XSS via srcdoc attribute bypass in Go… |
ci4-cms-erp |
ci4ms |
2026-04-08T14:29:28.500Z | 2026-04-08T16:13:16.580Z | |
| cve-2026-39389 | CI4MS has a Hidden Items Authorization Bypass in Filee… |
ci4-cms-erp |
ci4ms |
2026-04-08T14:28:29.847Z | 2026-04-10T20:28:55.783Z | |
| cve-2026-39865 | Axios HTTP/2 Session Cleanup State Corruption Vulnerability |
axios |
axios |
2026-04-08T14:25:27.865Z | 2026-04-27T17:00:06.795Z | |
| cve-2025-58713 | 6.4 (v3.1) | Rhpam: privilege escalation via excessive /etc/passwd … |
Red Hat |
Red Hat Process Automation 7 |
2026-04-08T13:55:11.428Z | 2026-04-08T14:28:41.733Z |
| cve-2025-57853 | 6.4 (v3.1) | Web-terminal: privilege escalation via excessive /etc/… |
Red Hat |
Red Hat Web Terminal |
2026-04-08T13:55:06.787Z | 2026-04-08T16:06:20.933Z |
| cve-2025-57854 | 6.4 (v3.1) | Osus-operator: privilege escalation via excessive /etc… |
Red Hat |
Red Hat OpenShift Update Service |
2026-04-08T13:55:06.739Z | 2026-04-08T14:42:32.600Z |
| cve-2025-57851 | 6.4 (v3.1) | Mce: privilege escalation via excessive /etc/passwd pe… |
Red Hat |
Multicluster Engine for Kubernetes |
2026-04-08T13:55:00.925Z | 2026-05-01T20:44:04.799Z |
| cve-2025-57847 | 6.4 (v3.1) | Ansible-automation-platform: privilege escalation via … |
Red Hat |
Red Hat Ansible Automation Platform 2 |
2026-04-08T13:55:00.729Z | 2026-04-08T16:13:23.024Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2022-avi-609 | Multiples vulnérabilités dans Google Chrome | 2022-07-05T00:00:00.000000 | 2022-07-05T00:00:00.000000 |
| certfr-2022-avi-608 | Vulnérabilité dans Nextcloud Server | 2022-07-05T00:00:00.000000 | 2022-07-05T00:00:00.000000 |
| certfr-2022-avi-607 | Multiples vulnérabilités dans OpenSSL | 2022-07-05T00:00:00.000000 | 2022-07-05T00:00:00.000000 |
| certfr-2022-avi-606 | Multiples vulnérabilités dans le noyau Linux de Debian | 2022-07-04T00:00:00.000000 | 2022-07-04T00:00:00.000000 |
| certfr-2022-avi-605 | Vulnérabilité dans CheckPoint Quantum Smart-1 | 2022-07-04T00:00:00.000000 | 2022-07-04T00:00:00.000000 |
| certfr-2022-avi-604 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2022-07-04T00:00:00.000000 | 2022-07-04T00:00:00.000000 |
| certfr-2022-avi-603 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2022-07-04T00:00:00.000000 | 2022-07-04T00:00:00.000000 |
| certfr-2022-avi-602 | Multiples vulnérabilités dans le noyau Linux de Debian LTS | 2022-07-04T00:00:00.000000 | 2022-07-04T00:00:00.000000 |
| certfr-2022-avi-601 | Multiples vulnérabilités dans Belden ProSoft RadioLinx RLX2 | 2022-07-01T00:00:00.000000 | 2022-07-01T00:00:00.000000 |
| certfr-2022-avi-600 | Vulnérabilité dans Microsoft Edge | 2022-07-01T00:00:00.000000 | 2022-07-01T00:00:00.000000 |
| certfr-2022-avi-599 | Multiples vulnérabilités dans ElasticSearch et Kibana | 2022-07-01T00:00:00.000000 | 2022-07-01T00:00:00.000000 |
| certfr-2022-avi-598 | Multiples vulnérabilités dans les produits GitLab | 2022-07-01T00:00:00.000000 | 2022-07-01T00:00:00.000000 |
| certfr-2022-avi-597 | Multiples vulnérabilités dans IBM Spectrum Protect Plus | 2022-07-01T00:00:00.000000 | 2022-07-01T00:00:00.000000 |
| certfr-2022-avi-596 | Multiples vulnérabilités dans Tenable.sc | 2022-07-01T00:00:00.000000 | 2022-07-01T00:00:00.000000 |
| certfr-2022-avi-595 | Vulnérabilité dans les produits Check Point | 2022-07-01T00:00:00.000000 | 2022-07-01T00:00:00.000000 |
| certfr-2022-avi-594 | Multiples vulnérabilités dans Microsoft Windows | 2022-06-30T00:00:00.000000 | 2022-06-30T00:00:00.000000 |
| certfr-2022-avi-593 | Vulnérabilité dans Mozilla Firefox | 2022-06-30T00:00:00.000000 | 2022-06-30T00:00:00.000000 |
| certfr-2022-avi-592 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2022-06-30T00:00:00.000000 | 2022-06-30T00:00:00.000000 |
| certfr-2022-avi-591 | Multiples vulnérabilités dans les produits IBM | 2022-06-30T00:00:00.000000 | 2022-06-30T00:00:00.000000 |
| certfr-2022-avi-590 | Multiples vulnérabilités dans les produits Mozilla | 2022-06-29T00:00:00.000000 | 2022-06-29T00:00:00.000000 |
| certfr-2022-avi-589 | Vulnérabilité dans le noyau Linux de SUSE | 2022-06-29T00:00:00.000000 | 2022-06-29T00:00:00.000000 |
| certfr-2022-avi-588 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2022-06-29T00:00:00.000000 | 2022-06-29T00:00:00.000000 |
| certfr-2022-avi-587 | Multiples vulnérabilités dans les produits Foxit | 2022-06-28T00:00:00.000000 | 2022-06-28T00:00:00.000000 |
| certfr-2022-avi-586 | Multiples vulnérabilités dans Google ChromeOS | 2022-06-28T00:00:00.000000 | 2022-06-28T00:00:00.000000 |
| certfr-2022-avi-585 | Vulnérabilité dans le noyau Linux d'Ubuntu | 2022-06-28T00:00:00.000000 | 2022-06-28T00:00:00.000000 |
| certfr-2022-avi-584 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2022-06-27T00:00:00.000000 | 2022-06-27T00:00:00.000000 |
| certfr-2022-avi-583 | Multiples vulnérabilités dans Synology Router Manager (SRM) | 2022-06-27T00:00:00.000000 | 2022-06-27T00:00:00.000000 |
| certfr-2022-avi-582 | Multiples vulnérabilités dans les produits Citrix | 2022-06-27T00:00:00.000000 | 2022-06-27T00:00:00.000000 |
| certfr-2022-avi-581 | Multiples vulnérabilités dans Microsoft Edge | 2022-06-27T00:00:00.000000 | 2022-06-27T00:00:00.000000 |
| certfr-2022-avi-580 | Multiples vulnérabilités dans IBM Db2 | 2022-06-27T00:00:00.000000 | 2022-06-27T00:00:00.000000 |