Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-77506 | 4.8 (v3.1) | Znuny before LTS 6.5.22 allows AgentTicketEmailRe… |
Znuny |
Znuny |
2026-08-20T20:18:55.670Z | 2026-08-25T19:12:24.097Z |
| cve-2026-75910 | 6.5 (v3.1) 7.1 (v4.0) | Incorrect privilege assignment in the Amazon aws-athen… |
AWS |
Athena Federated Query Clickhouse Connector deployment template |
2026-08-20T20:06:54.217Z | 2026-08-25T19:13:06.552Z |
| cve-2026-72861 | 5.8 (v3.1) 6.9 (v4.0) | Appwrite Templates github-issue-bot Skips Webhook Sign… |
appwrite |
templates |
2026-08-20T19:48:51.102Z | 2026-08-21T21:45:50.993Z |
| cve-2026-77151 | lin-snow Ech0 crypto.go MD5Encrypt risky encryption |
lin-snow |
Ech0 |
2026-08-20T19:45:10.732Z | 2026-08-21T21:45:57.804Z | |
| cve-2026-43678 | N/A | An unauthenticated remote peer can crash any NIOW… |
Apple |
swift-nio |
2026-08-20T18:57:03.222Z | 2026-08-20T21:10:49.702Z |
| cve-2026-49996 | securedrop-proxy origin limitation can be bypassed wit… |
freedomofpress |
securedrop-client |
2026-08-20T18:55:57.513Z | 2026-08-20T19:48:57.931Z | |
| cve-2026-64777 | N/A | A malicious builder peer may be able to request a… |
Apple |
container |
2026-08-20T18:53:12.196Z | 2026-08-20T19:47:09.853Z |
| cve-2026-50190 | Shaarli vulnerable to stored XSS via raw bookmark titl… |
shaarli |
Shaarli |
2026-08-20T18:49:48.952Z | 2026-08-20T19:02:02.984Z | |
| cve-2026-53586 | libgit2: HTTP transport can leak credentials to an off… |
libgit2 |
libgit2 |
2026-08-20T18:40:08.673Z | 2026-08-21T21:46:05.425Z | |
| cve-2026-53583 | libgit2: Inverted IP SubjectAltName Comparison in Open… |
libgit2 |
libgit2 |
2026-08-20T18:39:03.676Z | 2026-08-20T19:04:42.247Z | |
| cve-2026-53585 | libgit2: Unbounded Memory Allocation via Delta Object … |
libgit2 |
libgit2 |
2026-08-20T18:37:44.115Z | 2026-08-25T15:21:43.819Z | |
| cve-2026-53587 | libgit2 - Unauthenticated network-reachable heap out-o… |
libgit2 |
libgit2 |
2026-08-20T18:36:43.055Z | 2026-08-20T19:18:33.821Z | |
| cve-2026-53584 | libgit2: Submodule path traversal |
libgit2 |
libgit2 |
2026-08-20T18:35:10.280Z | 2026-08-20T19:48:17.848Z | |
| cve-2026-19683 | 6.3 (v4.0) | Unencrypted Credential Transmission in Omada Gateway D… |
TP-Link Systems Inc. |
ER7212PC v2 |
2026-08-20T18:32:27.650Z | 2026-08-20T18:58:42.948Z |
| cve-2026-19586 | 9.3 (v4.0) | Pre-Authentication OS Command Injection in Omada Gatew… |
TP-Link Systems Inc. |
ER7212PC v2 |
2026-08-20T18:32:06.942Z | 2026-08-28T16:10:43.693Z |
| cve-2026-9033 | 6 (v4.0) | Unauthenticated Captive Portal Session Termination and… |
TP-Link Systems Inc. |
ER7212PC v2 |
2026-08-20T18:31:54.806Z | 2026-08-20T18:59:36.657Z |
| cve-2026-75514 | BunkerWeb: rDNS bypass via missing forward-confirmatio… |
bunkerity |
bunkerweb |
2026-08-20T18:31:51.527Z | 2026-08-20T19:00:33.894Z | |
| cve-2026-66002 | Frappe: User Enumeration via PDDR |
frappe |
frappe |
2026-08-20T18:29:40.872Z | 2026-08-21T21:46:12.905Z | |
| cve-2026-66001 | Frappe: Improper Authorization in OAuth2 Consent Endpoint |
frappe |
frappe |
2026-08-20T18:27:32.056Z | 2026-08-25T15:20:17.550Z | |
| cve-2026-62315 | Frappe: Mass assignment via set_value |
frappe |
frappe |
2026-08-20T18:25:01.277Z | 2026-08-20T18:56:44.457Z | |
| cve-2026-63654 | Frappe: Unauthenticated Workflow approval via confirm_action |
frappe |
frappe |
2026-08-20T18:23:52.994Z | 2026-08-20T19:47:38.338Z | |
| cve-2026-72854 | 5.3 (v3.1) 5.8 (v4.0) | msgpack-c Integer Overflow in msgpack_unpacker_expand_… |
msgpack |
msgpack-c |
2026-08-20T18:19:24.266Z | 2026-08-20T18:53:26.891Z |
| cve-2026-72852 | 8.5 (v4.0) 7.8 (v3.1) | darknet Integer Overflow in Convolutional Layer Buffer… |
hank-ai |
darknet |
2026-08-20T18:19:23.554Z | 2026-08-25T15:18:13.753Z |
| cve-2026-66788 | 3.7 (v3.1) | Lighthouse: dockerfile build stages use end-of-life fe… |
Red Hat |
Red Hat Advanced Cluster Management for Kubernetes 2.17 |
2026-08-20T18:15:37.408Z | 2026-09-03T04:41:39.269Z |
| cve-2026-15743 | N/A | Catalyst::Plugin::Static::Simple versions through 0.38… |
|
|
2026-08-20T18:15:26.876Z | 2026-08-28T15:07:16.802Z |
| cve-2026-66787 | 5.4 (v3.1) | Lighthouse: go pprof profiling endpoint enabled uncond… |
Red Hat |
Red Hat Advanced Cluster Management for Kubernetes 2.17 |
2026-08-20T18:15:23.339Z | 2026-09-03T04:41:35.217Z |
| cve-2026-53569 | Frappe: Missing authorization in toggle_like and mark_… |
frappe |
frappe |
2026-08-20T18:15:20.170Z | 2026-08-20T19:03:07.692Z | |
| cve-2026-77148 | Comfast CF-N1-S Web Management mbox-config sub_44B50C … |
Comfast |
CF-N1-S |
2026-08-20T18:15:08.812Z | 2026-08-20T19:46:50.485Z | |
| cve-2026-66785 | 2.5 (v3.1) | Submariner: ipsec psk secrets file created with defaul… |
Red Hat |
Red Hat Advanced Cluster Management for Kubernetes 2.17 |
2026-08-20T18:15:06.802Z | 2026-09-03T04:41:31.362Z |
| cve-2026-75526 | django CMS: Stored XSS in edit-mode plugin exception r… |
django-cms |
django-cms |
2026-08-20T18:11:10.220Z | 2026-08-20T19:20:52.755Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2022-avi-096 | Multiples vulnérabilités dans Samba | 2022-02-01T00:00:00.000000 | 2022-02-01T00:00:00.000000 |
| certfr-2022-avi-095 | Vulnérabilité dans les produits ESET | 2022-01-31T00:00:00.000000 | 2022-01-31T00:00:00.000000 |
| certfr-2022-avi-094 | Vulnérabilité dans Symfony | 2022-01-31T00:00:00.000000 | 2022-02-08T00:00:00.000000 |
| certfr-2022-avi-093 | Vulnérabilité dans OpenSSL pour MIPS | 2022-01-31T00:00:00.000000 | 2022-01-31T00:00:00.000000 |
| certfr-2022-avi-092 | Multiples vulnérabilités dans IBM Spectrum Protect Plus | 2022-01-31T00:00:00.000000 | 2022-01-31T00:00:00.000000 |
| certfr-2022-avi-091 | Vulnérabilité dans Synology DiskStation Manager | 2022-01-31T00:00:00.000000 | 2022-04-06T00:00:00.000000 |
| certfr-2022-avi-090 | Multiples vulnérabilités dans Foxit PDF Reader et Foxit PDF Editor | 2022-01-28T00:00:00.000000 | 2022-01-28T00:00:00.000000 |
| certfr-2022-avi-089 | Vulnérabilité dans Trend Micro Worry-Free Business Security Server | 2022-01-28T00:00:00.000000 | 2022-01-28T00:00:00.000000 |
| certfr-2022-avi-088 | Multiples vulnérabilités dans les produits Apple | 2022-01-27T00:00:00.000000 | 2022-01-27T00:00:00.000000 |
| certfr-2022-avi-087 | Vulnérabilité dans Nextcloud pour Android | 2022-01-27T00:00:00.000000 | 2022-01-27T00:00:00.000000 |
| certfr-2022-avi-086 | Vulnérabilité dans pkexec de PolicyKit sur SUSE | 2022-01-27T00:00:00.000000 | 2022-01-27T00:00:00.000000 |
| certfr-2022-avi-085 | Vulnérabilité dans pkexec de PolicyKit sur Debian | 2022-01-27T00:00:00.000000 | 2022-01-27T00:00:00.000000 |
| certfr-2022-avi-084 | Vulnérabilité dans pkexec de PolicyKit sur Red Hat | 2022-01-27T00:00:00.000000 | 2022-01-27T00:00:00.000000 |
| certfr-2022-avi-083 | Vulnérabilité dans pkexec de PolicyKit sur Ubuntu | 2022-01-27T00:00:00.000000 | 2022-01-27T00:00:00.000000 |
| certfr-2022-avi-082 | Multiples vulnérabilités dans Apache Tomcat | 2022-01-26T00:00:00.000000 | 2022-01-26T00:00:00.000000 |
| certfr-2022-avi-081 | Multiples vulnérabilités dans Xen | 2022-01-26T00:00:00.000000 | 2022-01-26T00:00:00.000000 |
| certfr-2022-avi-080 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2022-01-26T00:00:00.000000 | 2022-01-26T00:00:00.000000 |
| certfr-2022-avi-079 | Vulnérabilité dans strongSwan | 2022-01-25T00:00:00.000000 | 2022-01-25T00:00:00.000000 |
| certfr-2022-avi-078 | Multiples vulnérabilités dans Foxit PDF Editor et Foxit PDF Reader versions MacOS | 2022-01-25T00:00:00.000000 | 2022-01-25T00:00:00.000000 |
| certfr-2022-avi-077 | Vulnérabilité dans IBM WebSphere | 2022-01-25T00:00:00.000000 | 2022-01-25T00:00:00.000000 |
| certfr-2022-avi-076 | Multiples vulnérabilités dans Moodle | 2022-01-24T00:00:00.000000 | 2022-01-24T00:00:00.000000 |
| certfr-2022-avi-075 | Multiples vulnérabilités dans les produits SonicWall | 2022-01-24T00:00:00.000000 | 2022-01-24T00:00:00.000000 |
| certfr-2022-avi-074 | Vulnérabilité dans Microsoft Windows | 2022-01-24T00:00:00.000000 | 2022-01-24T00:00:00.000000 |
| certfr-2022-avi-073 | Vulnérabilité dans Microsoft Edge pour Android | 2022-01-24T00:00:00.000000 | 2022-01-24T00:00:00.000000 |
| certfr-2022-avi-072 | Vulnérabilité dans IBM QRadar | 2022-01-24T00:00:00.000000 | 2022-01-24T00:00:00.000000 |
| certfr-2022-avi-071 | Multiples vulnérabilités dans le noyau Linux de Debian | 2022-01-24T00:00:00.000000 | 2022-01-24T00:00:00.000000 |
| certfr-2022-avi-070 | Vulnérabilité dans Stormshield SSOAgent | 2022-01-24T00:00:00.000000 | 2022-01-24T00:00:00.000000 |
| certfr-2022-avi-069 | Multiples vulnérabilités dans phpMyAdmin | 2022-01-24T00:00:00.000000 | 2022-01-24T00:00:00.000000 |
| certfr-2022-avi-068 | Multiples vulnérabilités dans Microsoft Edge | 2022-01-21T00:00:00.000000 | 2022-01-21T00:00:00.000000 |
| certfr-2022-avi-067 | Vulnérabilité dans MongoDB pour VS Code | 2022-01-21T00:00:00.000000 | 2022-01-21T00:00:00.000000 |