Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-40015 | 4.3 (v3.1) | An attacker that has valid credentials can open m… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:18.576Z | 2026-08-28T15:03:07.769Z |
| cve-2026-40014 | 6.5 (v3.1) | An attacker that can send mail to a user can craf… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:17.711Z | 2026-08-28T15:54:30.823Z |
| cve-2026-40013 | 4.3 (v3.1) | An attacker that has valid credentials can submit… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:16.751Z | 2026-08-28T15:54:38.082Z |
| cve-2026-33607 | 4.3 (v3.1) | An attacker that has valid credentials can use IM… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:15.779Z | 2026-08-28T15:54:47.683Z |
| cve-2026-33606 | 4.8 (v3.1) | Mail content stored by a user can be crafted so t… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:14.932Z | 2026-08-28T15:55:05.515Z |
| cve-2026-33605 | 7.5 (v3.1) | An unauthenticated attacker can crash the ManageS… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:13.963Z | 2026-08-28T15:55:19.368Z |
| cve-2026-33604 | 5.9 (v3.1) | An attacker that can get Dovecot to relay a messa… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:12.996Z | 2026-08-28T15:55:26.026Z |
| cve-2026-33263 | 4.3 (v3.1) | When mail_max_userip_connections is set (default … |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:12.032Z | 2026-08-28T15:55:33.617Z |
| cve-2026-27852 | 7.5 (v3.1) | An attacker that can send mail to a user can craf… |
Open-Xchange GmbH |
OX Dovecot Pro |
2026-08-28T10:12:11.070Z | 2026-08-28T15:55:41.500Z |
| cve-2026-81777 | 5.3 (v3.1) | WordPress Essential Addons for Elementor plugin <= 6.8… |
WPDeveloper |
Essential Addons for Elementor |
2026-08-28T09:42:11.752Z | 2026-08-28T15:28:16.134Z |
| cve-2026-18393 | 5.4 (v3.1) | Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_curs… |
Red Hat |
Red Hat Enterprise Linux AI (RHEL AI) 3 |
2026-08-28T09:05:35.022Z | 2026-08-28T15:55:50.649Z |
| cve-2026-18918 | 9.1 (v4.0) | OAuth 1.0 session-fixation chain via unauthenticated p… |
Eclipse Foundation |
Eclipse Lyo |
2026-08-28T08:54:07.990Z | 2026-08-28T15:04:16.704Z |
| cve-2026-78071 | 7.5 (v4.0) | Joomla Extension - digital-peak.com - Authenticated, p… |
digital-peak.com |
DP Calendar extension for Joomla |
2026-08-28T07:49:52.253Z | 2026-08-29T04:44:45.545Z |
| cve-2026-78073 | 5.3 (v4.0) | Joomla Extension - j2commerce.com - Reflected XSS attr… |
mrvinoth.com |
All Video Share extension for Joomla |
2026-08-28T07:48:09.002Z | 2026-08-29T04:42:51.643Z |
| cve-2026-78072 | 8.7 (v4.0) | Joomla Extension - Jefferson49 - Unauthenticated blind… |
Jefferson49 |
Sexy Polling Reloaded extension for Joomla |
2026-08-28T07:41:46.050Z | 2026-08-29T04:36:23.681Z |
| cve-2026-78070 | 6.9 (v4.0) | Joomla Extension - digital-peak.com - Authenticated, p… |
digital-peak.com |
DP Calendar extension for Joomla |
2026-08-28T07:41:25.951Z | 2026-08-29T04:36:03.852Z |
| cve-2026-5510 | GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored… |
stellarwp |
GiveWP – Donation Plugin and Fundraising Platform |
2026-08-28T07:40:17.075Z | 2026-08-28T15:11:37.616Z | |
| cve-2026-6128 | All-in-One WP Migration Unlimited Extension <= 2.84 - … |
servmask |
All-in-One WP Migration Unlimited Extension |
2026-08-28T07:40:16.550Z | 2026-08-28T15:55:58.355Z | |
| cve-2026-9548 | 6.5 (v3.1) | An improper neutralization of input during web pa… |
Synology |
Synology Chat Server |
2026-08-28T07:08:51.584Z | 2026-08-28T11:03:02.420Z |
| cve-2026-9491 | 4.3 (v3.1) | A server-ide request forgery (SSRF) vulnerability… |
Synology |
Synology Chat Server |
2026-08-28T07:07:57.240Z | 2026-08-28T11:03:53.629Z |
| cve-2026-40541 | 9 (v3.1) | An improper neutralization of input during web pa… |
Synology |
Synology Chat Server |
2026-08-28T07:07:24.049Z | 2026-08-28T11:44:42.311Z |
| cve-2026-80724 | ptp: vmclock: prevent read-only mappings from becoming… |
Linux |
Linux |
2026-08-28T07:03:08.410Z | 2026-08-29T06:22:41.352Z | |
| cve-2026-82123 | 6.5 (v3.1) | WordPress Loops & Logic - Reflected XSS |
Tangible |
Loops & Logic |
2026-08-28T06:54:43.365Z | 2026-08-28T16:10:28.897Z |
| cve-2026-80723 | of: reserved_mem: prevent OOB when too many dynamic re… |
Linux |
Linux |
2026-08-28T06:53:18.485Z | 2026-08-29T06:22:40.126Z | |
| cve-2026-80722 | wifi: mac80211: validate individual TWT params before … |
Linux |
Linux |
2026-08-28T06:53:17.886Z | 2026-08-29T06:22:38.281Z | |
| cve-2026-80721 | Bluetooth: ISO: ensure no dangling hcon references in … |
Linux |
Linux |
2026-08-28T06:53:17.278Z | 2026-08-30T07:08:36.447Z | |
| cve-2026-80720 | iomap: add a separate bio_set for iomap_split_ioend |
Linux |
Linux |
2026-08-28T06:53:16.683Z | 2026-08-29T06:22:35.780Z | |
| cve-2026-80719 | N/A | mm: mglru: fix stale batch updates after memcg reparenting |
Linux |
Linux |
2026-08-28T06:53:16.087Z | 2026-08-28T06:53:16.087Z |
| cve-2026-80718 | mm/percpu-km: fix bitmap overflow and accounting in pc… |
Linux |
Linux |
2026-08-28T06:53:15.490Z | 2026-08-29T06:22:34.556Z | |
| cve-2026-80717 | sctp: validate Adaptation Indication parameter length |
Linux |
Linux |
2026-08-28T06:53:14.886Z | 2026-08-29T06:22:33.315Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2024-000120 | "Kura Sushi Official App Produced by EPARK" for Android uses a hard-coded cryptographic key | 2024-11-20T13:56+09:00 | 2024-11-20T13:56+09:00 |
| jvndb-2024-012941 | Multiple vulnerabilities in Rakuten Turbo 5G | 2024-11-19T10:41+09:00 | 2024-11-19T10:41+09:00 |
| jvndb-2024-000119 | Multiple vulnerabilities in FitNesse | 2024-11-15T13:37+09:00 | 2024-11-20T11:18+09:00 |
| jvndb-2024-012461 | Multiple vulnerabilities in SoftBank Mesh Wi-Fi router RP562B | 2024-11-13T14:26+09:00 | 2024-11-26T16:11+09:00 |
| jvndb-2024-000118 | WordPress Plugin "VK All in One Expansion Unit" vulnerable to cross-site scripting | 2024-11-13T13:50+09:00 | 2024-11-13T13:50+09:00 |
| jvndb-2024-012017 | Trend Micro Deep Security 20 Agent for Windows vulnerable to improper access control | 2024-11-06T11:00+09:00 | 2024-11-06T11:00+09:00 |
| jvndb-2024-011833 | Incorrect authorization vulnerability in OMRON Sysmac Studio | 2024-11-05T15:29+09:00 | 2024-11-05T15:29+09:00 |
| jvndb-2024-011747 | Command injection vulnerability in Trend Micro Cloud Edge | 2024-11-01T14:28+09:00 | 2024-11-01T14:28+09:00 |
| jvndb-2024-011744 | REST-APIs unintentionally enabled in Century Systems FutureNet NXR series routers | 2024-11-01T13:49+09:00 | 2024-11-01T13:49+09:00 |
| jvndb-2024-000117 | Stack-based buffer overflow vulnerability in multiple laser printers and MFPs which implement Ricoh Web Image Monitor | 2024-10-31T16:44+09:00 | 2025-05-19T17:59+09:00 |
| jvndb-2024-000116 | Hikvision network camera security enhancement to prevent cleartext transmission of Dynamic DNS credentials | 2024-10-30T15:07+09:00 | 2024-10-30T15:07+09:00 |
| jvndb-2024-011256 | Multiple vulnerabilities in Sharp and Toshiba Tec MFPs | 2024-10-28T17:33+09:00 | 2024-10-28T17:33+09:00 |
| jvndb-2024-000115 | Chatwork Desktop Application (Windows) uses a potentially dangerous function | 2024-10-28T14:29+09:00 | 2024-10-28T14:29+09:00 |
| jvndb-2024-000114 | Multiple vulnerabilities in baserCMS | 2024-10-25T15:07+09:00 | 2025-02-18T15:35+09:00 |
| jvndb-2024-010802 | Multiple SQL injection vulnerabilities in Trend Micro Deep Discovery Inspector | 2024-10-22T13:02+09:00 | 2024-10-22T13:02+09:00 |
| jvndb-2024-000106 | Multiple vulnerabilities in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software | 2024-10-21T11:58+09:00 | 2024-11-21T11:37+09:00 |
| jvndb-2024-000113 | N-LINE vulnerable to HTML injection | 2024-10-18T14:48+09:00 | 2024-10-25T16:48+09:00 |
| jvndb-2024-000112 | MUSASI version 3 performing authentication on client-side | 2024-10-18T14:40+09:00 | 2024-10-25T16:55+09:00 |
| jvndb-2024-000111 | SHIRASAGI vulnerable to path traversal | 2024-10-16T14:12+09:00 | 2024-10-23T17:35+09:00 |
| jvndb-2024-000110 | Multiple vulnerabilities in Exment | 2024-10-11T14:13+09:00 | 2024-10-11T14:13+09:00 |
| jvndb-2024-000109 | baserCMS plugin "BurgerEditor" vulnerable to directory listing | 2024-10-10T14:57+09:00 | 2024-11-06T14:45+09:00 |
| jvndb-2024-009667 | Multiple vulnerabilities in JTEKT ELECTRONICS Kostac PLC Programming Software | 2024-10-03T13:42+09:00 | 2024-10-03T13:42+09:00 |
| jvndb-2024-000108 | Apache Tomcat improper handling of TLS handshake process data | 2024-10-01T17:51+09:00 | 2024-10-01T17:51+09:00 |
| jvndb-2024-009498 | Vulnerability in Cosminexus | 2024-10-01T16:01+09:00 | 2024-10-01T16:01+09:00 |
| jvndb-2024-009481 | Insecure initial password configuration issue in SEIKO EPSON Web Config | 2024-10-01T14:14+09:00 | 2024-11-12T10:25+09:00 |
| jvndb-2024-000107 | RevoWorks Cloud vulnerable to unintended process execution | 2024-09-30T15:17+09:00 | 2024-09-30T15:17+09:00 |
| jvndb-2024-003932 | File Permissions Vulnerability in Hitachi Ops Center Common Services | 2024-09-30T14:15+09:00 | 2024-09-30T14:15+09:00 |
| jvndb-2024-000105 | Multiple vulnerabilities in Smart-tab | 2024-09-30T14:14+09:00 | 2024-09-30T14:14+09:00 |
| jvndb-2024-009396 | SNMP service is enabled by default in Sharp NEC Display Solutions projectors | 2024-09-30T12:46+09:00 | 2024-09-30T12:46+09:00 |
| jvndb-2024-000104 | MF Teacher Performance Management System vulnerable to cross-site scripting | 2024-09-27T15:00+09:00 | 2024-10-10T11:14+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2026-avi-0705 | Multiples vulnérabilités dans les produits Spring | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0704 | Vulnérabilité dans CPython | 2026-06-09T00:00:00.000000 | 2026-06-09T00:00:00.000000 |
| certfr-2026-avi-0703 | Vulnérabilité dans Laravel | 2026-06-08T00:00:00.000000 | 2026-06-08T00:00:00.000000 |
| certfr-2026-avi-0702 | Multiples vulnérabilités dans Spring Micrometer | 2026-06-08T00:00:00.000000 | 2026-06-08T00:00:00.000000 |
| certfr-2026-avi-0701 | Multiples vulnérabilités dans les produits Microsoft | 2026-06-08T00:00:00.000000 | 2026-06-08T00:00:00.000000 |
| certfr-2026-avi-0700 | Multiples vulnérabilités dans Microsoft Edge | 2026-06-08T00:00:00.000000 | 2026-06-08T00:00:00.000000 |
| certfr-2026-avi-0699 | Vulnérabilité dans Cisco Catalyst SD-WAN | 2026-06-05T00:00:00.000000 | 2026-06-10T00:00:00.000000 |
| certfr-2026-avi-0698 | Multiples vulnérabilités dans les produits IBM | 2026-06-05T00:00:00.000000 | 2026-06-05T00:00:00.000000 |
| certfr-2026-avi-0697 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-06-05T00:00:00.000000 | 2026-06-05T00:00:00.000000 |
| certfr-2026-avi-0696 | Multiples vulnérabilités dans le noyau Linux de Debian LTS | 2026-06-05T00:00:00.000000 | 2026-06-05T00:00:00.000000 |
| certfr-2026-avi-0695 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2026-06-05T00:00:00.000000 | 2026-06-05T00:00:00.000000 |
| certfr-2026-avi-0694 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2026-06-05T00:00:00.000000 | 2026-06-05T00:00:00.000000 |
| certfr-2026-avi-0693 | Multiples vulnérabilités dans Microsoft Azure Linux | 2026-06-05T00:00:00.000000 | 2026-06-05T00:00:00.000000 |
| certfr-2026-avi-0692 | Multiples vulnérabilités dans Google Chrome | 2026-06-05T00:00:00.000000 | 2026-06-05T00:00:00.000000 |
| certfr-2026-avi-0691 | Multiples vulnérabilités dans CPython | 2026-06-05T00:00:00.000000 | 2026-06-05T00:00:00.000000 |
| certfr-2026-avi-0690 | Multiples vulnérabilités dans Traefik | 2026-06-05T00:00:00.000000 | 2026-06-05T00:00:00.000000 |
| certfr-2026-avi-0689 | Vulnérabilité dans les produits Cisco | 2026-06-04T00:00:00.000000 | 2026-06-04T00:00:00.000000 |
| certfr-2026-avi-0688 | Multiples vulnérabilités dans FreeRadius | 2026-06-04T00:00:00.000000 | 2026-06-04T00:00:00.000000 |
| certfr-2026-avi-0687 | Multiples vulnérabilités dans Synology Chat Server pour DSM | 2026-06-04T00:00:00.000000 | 2026-06-04T00:00:00.000000 |
| certfr-2026-avi-0686 | Multiples vulnérabilités dans les produits NetApp | 2026-06-04T00:00:00.000000 | 2026-06-04T00:00:00.000000 |
| certfr-2026-avi-0685 | Multiples vulnérabilités dans Microsoft Azure Linux | 2026-06-03T00:00:00.000000 | 2026-06-03T00:00:00.000000 |
| certfr-2026-avi-0684 | Multiples vulnérabilités dans Mozilla Firefox | 2026-06-03T00:00:00.000000 | 2026-06-03T00:00:00.000000 |
| certfr-2026-avi-0683 | Vulnérabilité dans HPE Aruba Networking AOS-CX | 2026-06-03T00:00:00.000000 | 2026-06-03T00:00:00.000000 |
| certfr-2026-avi-0682 | Vulnérabilité dans les produits Laravel | 2026-06-03T00:00:00.000000 | 2026-06-03T00:00:00.000000 |
| certfr-2026-avi-0681 | Multiples vulnérabilités dans les produits Microsoft | 2026-06-02T00:00:00.000000 | 2026-06-02T00:00:00.000000 |
| certfr-2026-avi-0680 | Multiples vulnérabilités dans Microsoft Edge | 2026-06-02T00:00:00.000000 | 2026-06-02T00:00:00.000000 |
| certfr-2026-avi-0679 | Multiples vulnérabilités dans Google Android | 2026-06-02T00:00:00.000000 | 2026-06-02T00:00:00.000000 |
| certfr-2026-avi-0678 | Vulnérabilité dans Apache Kafka | 2026-06-02T00:00:00.000000 | 2026-06-02T00:00:00.000000 |
| certfr-2026-avi-0677 | Vulnérabilité dans les produits Ivanti | 2026-06-02T00:00:00.000000 | 2026-06-02T00:00:00.000000 |
| certfr-2026-avi-0676 | Multiples vulnérabilités dans Mozilla Firefox | 2026-06-02T00:00:00.000000 | 2026-06-02T00:00:00.000000 |
| ID | Description | Published | Updated |
|---|---|---|---|
| certa-2000-ale-002 | Alerte de virus NEWLOVE | 2000-05-19T00:00:00.000000 | 2000-05-19T00:00:00.000000 |
| certa-2000-ale-001 | Alerte de virus LOVE-LETTER-FOR-YOU | 2000-05-05T00:00:00.000000 | 2000-07-05T00:00:00.000000 |