Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-1078 | 7.2 (v4.0) | An arbitrary file-write vulnerability in Pega Browser … |
Pegasystems |
Pega Robot Studio |
2026-04-07T15:04:32.765Z | 2026-04-07T19:59:49.928Z |
| cve-2026-35492 | Kedro-Datasets has a path traversal vulnerability in P… |
kedro-org |
kedro-plugins |
2026-04-07T15:03:45.893Z | 2026-04-08T14:50:03.601Z | |
| cve-2026-35491 | Pi-hole FTL: CLI API sessions can import Teleporter ar… |
pi-hole |
FTL |
2026-04-07T15:00:11.079Z | 2026-04-07T17:52:48.043Z | |
| cve-2026-5745 | 5.5 (v3.1) | Libarchive: a null pointer dereference vulnerability e… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-04-07T14:57:31.587Z | 2026-04-09T16:28:20.715Z |
| cve-2026-35490 | changedetection.io has an Authentication Bypass via De… |
dgtlmoon |
changedetection.io |
2026-04-07T14:55:24.120Z | 2026-04-09T14:37:01.267Z | |
| cve-2026-35489 | Tandoor Recipes — `amount`/`unit` bypass serializer in… |
TandoorRecipes |
recipes |
2026-04-07T14:53:18.333Z | 2026-04-07T15:58:45.810Z | |
| cve-2026-35488 | Tandoor Recipes — CustomIsShared permits DELETE/PUT on… |
TandoorRecipes |
recipes |
2026-04-07T14:51:25.861Z | 2026-04-08T14:48:54.946Z | |
| cve-2026-35487 | text-generation-webui has a Path Traversal in load_pro… |
oobabooga |
text-generation-webui |
2026-04-07T14:50:25.103Z | 2026-04-07T18:14:46.381Z | |
| cve-2026-35486 | text-generation-webui has a SSRF in superbooga/superbo… |
oobabooga |
text-generation-webui |
2026-04-07T14:49:37.805Z | 2026-04-09T14:37:31.599Z | |
| cve-2026-35485 | text-generation-webui has a Path Traversal in load_gra… |
oobabooga |
text-generation-webui |
2026-04-07T14:47:37.593Z | 2026-04-07T15:58:51.812Z | |
| cve-2026-35484 | text-generation-webui has a Path Traversal in load_pre… |
oobabooga |
text-generation-webui |
2026-04-07T14:46:42.351Z | 2026-04-08T14:46:53.620Z | |
| cve-2026-35483 | text-generation-webui has a Path Traversal in load_tem… |
oobabooga |
text-generation-webui |
2026-04-07T14:45:07.141Z | 2026-04-07T17:55:20.808Z | |
| cve-2026-35480 | go-ipld-prime's DAG-CBOR decoder unbounded memory allo… |
ipld |
go-ipld-prime |
2026-04-07T14:43:24.781Z | 2026-04-09T14:40:11.103Z | |
| cve-2026-35464 | pyLoad has an incomplete fix for CVE-2026-33509: unpro… |
pyload |
pyload |
2026-04-07T14:38:02.480Z | 2026-04-07T15:58:59.013Z | |
| cve-2026-35463 | pyLoad has Improper Neutralization of Special Elements… |
pyload |
pyload |
2026-04-07T14:32:44.149Z | 2026-04-08T14:46:07.056Z | |
| cve-2026-4740 | 8.2 (v3.1) | Rhacm: open cluster management (ocm): cross-cluster pr… |
Red Hat |
Multicluster Engine for Kubernetes |
2026-04-07T14:30:36.396Z | 2026-04-09T14:40:43.580Z |
| cve-2026-35462 | Papra Does Not Reject Expired API Keys |
papra-hq |
papra |
2026-04-07T14:30:17.479Z | 2026-04-07T17:54:02.880Z | |
| cve-2026-35461 | Papra has a Blind Server-Side Request Forgery (SSRF) v… |
papra-hq |
papra |
2026-04-07T14:28:42.063Z | 2026-04-09T14:41:13.998Z | |
| cve-2026-35460 | Papra has an HTML Injection in Transactional Emails vi… |
papra-hq |
papra |
2026-04-07T14:26:52.943Z | 2026-04-07T15:59:07.465Z | |
| cve-2026-35458 | Gotenberg has a ReDoS via extraHttpHeaders scope feature |
gotenberg |
gotenberg |
2026-04-07T14:24:21.651Z | 2026-04-09T14:20:52.933Z | |
| cve-2026-33034 | Potential denial-of-service vulnerability in ASGI requ… |
djangoproject |
Django |
2026-04-07T14:22:59.942Z | 2026-04-07T20:44:01.819Z | |
| cve-2026-33033 | Potential denial-of-service vulnerability in MultiPart… |
djangoproject |
Django |
2026-04-07T14:22:48.624Z | 2026-04-07T15:21:27.926Z | |
| cve-2026-4292 | Privilege abuse in ModelAdmin.list_editable |
djangoproject |
Django |
2026-04-07T14:22:38.254Z | 2026-04-07T15:12:56.065Z | |
| cve-2026-4277 | Privilege abuse in GenericInlineModelAdmin |
djangoproject |
Django |
2026-04-07T14:22:25.547Z | 2026-04-09T20:21:50.751Z | |
| cve-2026-35457 | libp2p-rust has unbounded rendezvous DISCOVER cookies … |
libp2p |
rust-libp2p |
2026-04-07T14:22:19.941Z | 2026-04-07T17:53:37.355Z | |
| cve-2026-3902 | ASGI header spoofing via underscore/hyphen conflation |
djangoproject |
Django |
2026-04-07T14:22:07.190Z | 2026-04-07T16:14:07.198Z | |
| cve-2026-35405 | libp2p-rendezvous: Unlimited namespace registrations p… |
libp2p |
rust-libp2p |
2026-04-07T14:21:15.377Z | 2026-04-09T17:44:08.836Z | |
| cve-2026-5384 | 5.8 (v3.1) | runZero Platform incorrect credential scope |
runZero |
Platform |
2026-04-07T14:12:42.547Z | 2026-04-07T19:59:57.769Z |
| cve-2026-5383 | 4.4 (v3.1) | runZero Explorer missing authorization check |
runZero |
Explorer |
2026-04-07T14:12:32.422Z | 2026-04-07T20:00:12.927Z |
| cve-2026-5382 | 3 (v3.1) | runZero Platform MCP endpoint information leak |
runZero |
Platform |
2026-04-07T14:12:23.331Z | 2026-04-07T15:38:38.395Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2022-avi-039 | Multiples vulnérabilités dans Moxa VPort | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-038 | Multiples vulnérabilités dans Tenable.sc | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-037 | Multiples vulnérabilités dans Citrix Hypervisor | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-036 | Vulnérabilité dans ClamAV | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-035 | Multiples vulnérabilités dans IBM WebSphere | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-034 | Vulnérabilité dans Apple iOS et iPadOS | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-033 | Multiples vulnérabilités dans les produits QNAP | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-032 | Multiples vulnérabilités dans Palo Alto Cortex XDR | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-031 | Vulnérabilité dans Cisco Unified Contact Center | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-030 | Multiples vulnérabilités dans Synology DiskStation Manager | 2022-01-13T00:00:00.000000 | 2022-01-13T00:00:00.000000 |
| certfr-2022-avi-029 | Multiples vulnérabilités dans les produits Microsoft | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-028 | Vulnérabilité dans Microsoft .Net | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-027 | Multiples vulnérabilités dans Microsoft Windows | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-026 | Multiples vulnérabilités dans Microsoft Office | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-025 | Multiples vulnérabilités dans les produits GitLab | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-024 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-023 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-022 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-021 | Multiples vulnérabilités dans Thunderbird | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-020 | Multiples vulnérabilités dans Mozilla Firefox et Firefox ESR | 2022-01-12T00:00:00.000000 | 2022-01-12T00:00:00.000000 |
| certfr-2022-avi-019 | Vulnérabilité dans Citrix Workspace App | 2022-01-11T00:00:00.000000 | 2022-01-11T00:00:00.000000 |
| certfr-2022-avi-018 | Multiples vulnérabilités dans les produits Siemens | 2022-01-11T00:00:00.000000 | 2022-01-11T00:00:00.000000 |
| certfr-2022-avi-017 | Multiples vulnérabilités dans les produits Schneider | 2022-01-11T00:00:00.000000 | 2022-01-11T00:00:00.000000 |
| certfr-2022-avi-016 | Multiples vulnérabilités dans les produits SAP | 2022-01-11T00:00:00.000000 | 2022-01-11T00:00:00.000000 |
| certfr-2022-avi-015 | Multiples vulnérabilités dans Belden Tofino | 2022-01-11T00:00:00.000000 | 2022-01-11T00:00:00.000000 |
| certfr-2022-avi-014 | Vulnérabilité dans Samba | 2022-01-11T00:00:00.000000 | 2022-01-11T00:00:00.000000 |
| certfr-2022-avi-013 | Vulnérabilité dans la base de données H2 | 2022-01-10T00:00:00.000000 | 2022-01-10T00:00:00.000000 |
| certfr-2022-avi-012 | Multiples vulnérabilités dans Microsoft Edge | 2022-01-07T00:00:00.000000 | 2022-01-07T00:00:00.000000 |
| certfr-2022-avi-011 | Vulnérabilité dans IBM AIX | 2022-01-07T00:00:00.000000 | 2022-01-07T00:00:00.000000 |
| certfr-2022-avi-010 | Multiples vulnérabilités dans WordPress | 2022-01-07T00:00:00.000000 | 2022-01-11T00:00:00.000000 |