Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-35604 | File Browser share links remain accessible after Share… |
filebrowser |
filebrowser |
2026-04-07T16:22:51.557Z | 2026-04-07T18:26:43.881Z | |
| cve-2026-35585 | File Browser has a Command Injection via Hook Runner |
filebrowser |
filebrowser |
2026-04-07T16:20:46.019Z | 2026-04-08T18:51:09.641Z | |
| cve-2026-35592 | pyLoad has an Incomplete Tar Path Traversal Fix in UnT… |
pyload |
pyload |
2026-04-07T16:11:38.209Z | 2026-04-08T14:58:21.343Z | |
| cve-2026-35586 | Authorization Bypass for SSL Certificate/Key Configura… |
pyload |
pyload |
2026-04-07T16:09:11.856Z | 2026-04-07T18:16:14.387Z | |
| cve-2026-35584 | FreeScout has an Unauthenticated IDOR in Open Tracking… |
freescout-help-desk |
freescout |
2026-04-07T16:07:33.883Z | 2026-04-09T14:29:09.627Z | |
| cve-2026-39384 | FreeScout Customer Merge Cross-Mailbox Authorization Bypass |
freescout-help-desk |
freescout |
2026-04-07T16:05:16.793Z | 2026-04-09T16:18:45.817Z | |
| cve-2026-35523 | Authentication bypass in strawberry-graphql via legacy… |
strawberry-graphql |
strawberry |
2026-04-07T15:58:17.694Z | 2026-04-09T16:18:51.112Z | |
| cve-2026-35583 | Emissary has a Path Traversal via Blacklist Bypass in … |
NationalSecurityAgency |
emissary |
2026-04-07T15:57:41.496Z | 2026-04-09T16:18:56.328Z | |
| cve-2026-35581 | Emissary has a Command Injection via PLACE_NAME Config… |
NationalSecurityAgency |
emissary |
2026-04-07T15:56:55.838Z | 2026-04-08T14:57:47.316Z | |
| cve-2026-35580 | Emissary has GitHub Actions Shell Injection via Workfl… |
NationalSecurityAgency |
emissary |
2026-04-07T15:55:56.074Z | 2026-04-07T18:25:26.662Z | |
| cve-2026-35578 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': 'This CVE is a duplicate of another CVE.** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39940. Reason: This candidate is a reservation duplicate of CVE-2026-39940. Notes: All CVE users should reference CVE-2026-39940 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.'}], 'replacedBy': ['CVE-2026-39940'], 'providerMetadata': {'orgId': 'a0819718-46f1-4df5-94e2-005712e83aaa', 'shortName': 'GitHub_M', 'dateUpdated': '2026-04-13T16:35:54.049Z'}} | N/A | N/A | 2026-04-07T15:53:05.516Z | 2026-04-13T16:35:54.049Z |
| cve-2026-35567 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': '** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39327. Reason: This candidate is a duplicate of CVE-2026-39327. Notes: All CVE users should reference CVE-2026-39327 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.another CVE.'}], 'replacedBy': ['CVE-2026-39327'], 'providerMetadata': {'orgId': 'a0819718-46f1-4df5-94e2-005712e83aaa', 'shortName': 'GitHub_M', 'dateUpdated': '2026-04-09T16:51:09.351Z'}} | N/A | N/A | 2026-04-07T15:49:55.587Z | 2026-04-09T16:51:09.351Z |
| cve-2026-35566 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': '** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39319. Reason: This candidate is a duplicate of CVE-2026-39319. Notes: All CVE users should reference CVE-2026-39319 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.another CVE.'}], 'replacedBy': ['CVE-2026-39319'], 'providerMetadata': {'orgId': 'a0819718-46f1-4df5-94e2-005712e83aaa', 'shortName': 'GitHub_M', 'dateUpdated': '2026-04-07T18:27:20.468Z'}} | N/A | N/A | 2026-04-07T15:48:33.952Z | 2026-04-07T18:27:20.468Z |
| cve-2026-35534 | ChurchCRM has Stored XSS in PersonView.php via Faceboo… |
ChurchCRM |
CRM |
2026-04-07T15:47:44.342Z | 2026-04-09T16:19:01.737Z | |
| cve-2026-35571 | Emissary has Stored XSS via Navigation Template Link I… |
NationalSecurityAgency |
emissary |
2026-04-07T15:26:30.391Z | 2026-04-08T14:57:05.392Z | |
| cve-2026-35526 | Strawberry GraphQL affected by a Denial of Service via… |
strawberry-graphql |
strawberry |
2026-04-07T15:23:36.548Z | 2026-04-08T14:55:58.026Z | |
| cve-2026-4931 | N/A | CVE-2026-4931 |
Marginal |
Marginal Smart Contract |
2026-04-07T15:22:36.700Z | 2026-04-08T14:45:03.884Z |
| cve-2026-35521 | Pi-hole FTL affected by Remote Code Execution (RCE) vi… |
pi-hole |
FTL |
2026-04-07T15:20:26.583Z | 2026-04-07T18:21:43.428Z | |
| cve-2026-33816 | N/A | CVE-2026-33816 in github.com/jackc/pgx |
github.com/jackc/pgx/v5 |
github.com/jackc/pgx/v5/pgproto3 |
2026-04-07T15:19:24.529Z | 2026-04-15T15:49:13.116Z |
| cve-2026-33815 | N/A | CVE-2026-33815 in github.com/jackc/pgx |
github.com/jackc/pgx/v5 |
github.com/jackc/pgx/v5/pgproto3 |
2026-04-07T15:19:24.344Z | 2026-04-17T18:30:29.157Z |
| cve-2026-35520 | Pi-hole FTL affected by Remote Code Execution (RCE) vi… |
pi-hole |
FTL |
2026-04-07T15:19:21.875Z | 2026-04-09T14:35:45.884Z | |
| cve-2026-35519 | Pi-hole FTL affected by Remote Code Execution (RCE) vi… |
pi-hole |
FTL |
2026-04-07T15:18:27.377Z | 2026-04-09T16:19:08.569Z | |
| cve-2026-1079 | 6 (v4.0) | A native messaging host vulnerability in Pega Browser … |
Pegasystems |
Pega Browser Extension (PBE) |
2026-04-07T15:17:47.205Z | 2026-04-07T20:06:55.833Z |
| cve-2026-35518 | Pi-hole FTL affected by Remote Code Execution (RCE) vi… |
pi-hole |
FTL |
2026-04-07T15:17:39.977Z | 2026-04-08T14:55:05.699Z | |
| cve-2026-35517 | Pi-hole FTL affected by Remote Code Execution (RCE) vi… |
pi-hole |
FTL |
2026-04-07T15:16:02.955Z | 2026-04-07T18:19:50.497Z | |
| cve-2026-35516 | LinkAce has SSRF via CheckLinksCommand - Link URL Upda… |
Kovah |
LinkAce |
2026-04-07T15:14:45.891Z | 2026-04-09T14:36:27.061Z | |
| cve-2025-24819 | N/A | A Relative Path Traversal vulnerability in Nokia MantaRay NM |
Nokia |
MantaRay NM |
2026-04-07T15:14:42.719Z | 2026-04-07T17:56:15.517Z |
| cve-2025-24818 | N/A | An OS Command Injection vulnerability in Nokia MantaRay NM |
Nokia |
MantaRay NM |
2026-04-07T15:13:22.492Z | 2026-04-07T20:11:29.811Z |
| cve-2025-24817 | N/A | An OS Command Injection vulnerability in Nokia MantaRay NM |
Nokia |
MantaRay NM |
2026-04-07T15:09:47.125Z | 2026-04-08T16:15:12.963Z |
| cve-2026-35515 | @nestjs/core Improperly Neutralizes Special Elements i… |
nestjs |
nest |
2026-04-07T15:06:10.619Z | 2026-04-07T15:58:37.067Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2022-avi-069 | Multiples vulnérabilités dans phpMyAdmin | 2022-01-24T00:00:00.000000 | 2022-01-24T00:00:00.000000 |
| certfr-2022-avi-068 | Multiples vulnérabilités dans Microsoft Edge | 2022-01-21T00:00:00.000000 | 2022-01-21T00:00:00.000000 |
| certfr-2022-avi-067 | Vulnérabilité dans MongoDB pour VS Code | 2022-01-21T00:00:00.000000 | 2022-01-21T00:00:00.000000 |
| certfr-2022-avi-066 | Multiples vulnérabilités dans le noyau Linux de Ubuntu | 2022-01-21T00:00:00.000000 | 2022-01-21T00:00:00.000000 |
| certfr-2022-avi-065 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2022-01-21T00:00:00.000000 | 2022-01-21T00:00:00.000000 |
| certfr-2022-avi-064 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2022-01-21T00:00:00.000000 | 2022-01-21T00:00:00.000000 |
| certfr-2022-avi-063 | Multiples vulnérabilités dans F5 NGINX | 2022-01-20T00:00:00.000000 | 2022-01-20T00:00:00.000000 |
| certfr-2022-avi-062 | Multiples vulnérabilités dans F5 BIG-IP et BIG-IQ | 2022-01-20T00:00:00.000000 | 2022-01-20T00:00:00.000000 |
| certfr-2022-avi-061 | Multiples vulnérabilités dans TrendMicro Deep Security Agent | 2022-01-20T00:00:00.000000 | 2022-01-20T00:00:00.000000 |
| certfr-2022-avi-060 | Multiples vulnérabilités dans les produits Cisco | 2022-01-20T00:00:00.000000 | 2022-01-21T00:00:00.000000 |
| certfr-2022-avi-059 | Multiples vulnérabilités dans IBM Db2 | 2022-01-20T00:00:00.000000 | 2022-01-20T00:00:00.000000 |
| certfr-2022-avi-058 | Multiples vulnérabilités dans Drupal core | 2022-01-20T00:00:00.000000 | 2022-01-20T00:00:00.000000 |
| certfr-2022-avi-057 | Multiples vulnérabilités dans Google Chrome | 2022-01-20T00:00:00.000000 | 2022-01-20T00:00:00.000000 |
| certfr-2022-avi-056 | Multiples vulnérabilités dans Oracle WebLogic Server | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-055 | Multiples vulnérabilités dans Oracle VM VirtualBox | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-054 | Multiples vulnérabilités dans Oracle Systems | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-053 | Multiples vulnérabilités dans Oracle PeopleSoft | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-052 | Multiples vulnérabilités dans Oracle MySQL | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-051 | Multiples vulnérabilités dans Oracle Java SE | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-050 | Multiples vulnérabilités dans Oracle Database Server | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-049 | Vulnérabilité dans les produits VMware | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-048 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-047 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2022-01-19T00:00:00.000000 | 2022-01-19T00:00:00.000000 |
| certfr-2022-avi-046 | Vulnérabilité dans SolarWinds Serv-U | 2022-01-18T00:00:00.000000 | 2022-01-18T00:00:00.000000 |
| certfr-2022-avi-045 | Multiples vulnérabilités dans Postfix | 2022-01-17T00:00:00.000000 | 2022-01-17T00:00:00.000000 |
| certfr-2022-avi-044 | Vulnérabilité dans Juniper Junos | 2022-01-17T00:00:00.000000 | 2022-01-17T00:00:00.000000 |
| certfr-2022-avi-043 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2022-01-17T00:00:00.000000 | 2022-01-17T00:00:00.000000 |
| certfr-2022-avi-042 | Vulnérabilité dans Junos OS et Junos OS Evolved | 2022-01-14T00:00:00.000000 | 2022-01-14T00:00:00.000000 |
| certfr-2022-avi-041 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2022-01-14T00:00:00.000000 | 2022-01-14T00:00:00.000000 |
| certfr-2022-avi-040 | Multiples vulnérabilités dans les produits Juniper | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |