Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-80606 | drm/xe/userptr: Hold notifier_lock for write on inject… |
Linux |
Linux |
2026-08-28T06:48:30.960Z | 2026-08-29T06:21:16.890Z | |
| cve-2026-80605 | N/A | HID: picolcd: prevent NULL pointer dereference in pico… |
Linux |
Linux |
2026-08-28T06:48:30.362Z | 2026-08-28T06:48:30.362Z |
| cve-2026-80604 | HID: core: Fix OOB read in hid_get_report for numbered… |
Linux |
Linux |
2026-08-28T06:48:29.755Z | 2026-08-29T06:21:15.771Z | |
| cve-2026-80603 | netfilter: nf_conntrack_irc: fix parse_dcc() off-by-on… |
Linux |
Linux |
2026-08-28T06:48:29.158Z | 2026-08-29T06:21:14.540Z | |
| cve-2026-80602 | N/A | perf/x86/amd/lbr: Fix kernel address leakage |
Linux |
Linux |
2026-08-28T06:48:28.553Z | 2026-08-28T06:48:28.553Z |
| cve-2026-80601 | batman-adv: gw: acquire ethernet header only after skb… |
Linux |
Linux |
2026-08-28T06:48:27.948Z | 2026-08-29T06:21:13.415Z | |
| cve-2026-80600 | batman-adv: dat: acquire ARP hw source only after skb … |
Linux |
Linux |
2026-08-28T06:48:27.351Z | 2026-08-29T06:21:12.299Z | |
| cve-2026-80599 | batman-adv: dat: ensure accessible eth_hdr proto field |
Linux |
Linux |
2026-08-28T06:48:26.709Z | 2026-08-29T06:21:11.082Z | |
| cve-2026-80598 | ntfs3: fix out-of-bounds read in decompress_lznt |
Linux |
Linux |
2026-08-28T06:48:24.097Z | 2026-08-30T07:08:34.000Z | |
| cve-2026-80597 | N/A | mtd: maps: vmu-flash: fix NULL pointer dereference in … |
Linux |
Linux |
2026-08-28T06:48:23.499Z | 2026-08-28T06:48:23.499Z |
| cve-2026-80596 | Input: ims-pcu - only expose sysfs attributes on contr… |
Linux |
Linux |
2026-08-28T06:48:22.892Z | 2026-08-29T06:21:08.760Z | |
| cve-2026-80595 | N/A | Input: ims-pcu - add response length checks |
Linux |
Linux |
2026-08-28T06:48:22.291Z | 2026-08-28T06:48:22.291Z |
| cve-2026-80594 | N/A | Input: ims-pcu - fix potential infinite loop in CDC un… |
Linux |
Linux |
2026-08-28T06:48:21.426Z | 2026-08-28T06:48:21.426Z |
| cve-2026-80593 | hwmon: (asus_atk0110) Check package count before acces… |
Linux |
Linux |
2026-08-28T06:48:20.816Z | 2026-08-29T06:21:07.538Z | |
| cve-2026-80592 | N/A | samples/damon/mtier: fail early if address range param… |
Linux |
Linux |
2026-08-28T06:48:20.218Z | 2026-08-28T06:48:20.218Z |
| cve-2026-80591 | f2fs: fix listxattr handling of corrupted xattr entries |
Linux |
Linux |
2026-08-28T06:48:19.617Z | 2026-08-29T06:21:06.412Z | |
| cve-2026-5097 | wpForo Forum <= 2.4.17 - Unauthenticated SQL Injection… |
tomdever |
wpForo Forum |
2026-08-28T06:39:50.561Z | 2026-08-28T10:38:20.772Z | |
| cve-2026-6286 | Booking for Appointments and Events Calendar <= 2.2 - … |
melograno |
Booking for Appointments and Events Calendar – Amelia |
2026-08-28T06:39:50.172Z | 2026-08-28T18:35:55.988Z | |
| cve-2026-76581 | WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to… |
wpmudev |
WPMU DEV Dashboard |
2026-08-28T06:39:49.567Z | 2026-08-28T15:24:54.022Z | |
| cve-2026-80590 | inet: frags: strip GSO state from fragments before rea… |
Linux |
Linux |
2026-08-28T06:35:12.516Z | 2026-08-29T06:21:05.276Z | |
| cve-2026-78032 | 9.8 (v3.0) 9.3 (v4.0) | SOY CMS contains an issue with deserialization o… |
Tsuyoshi Saito |
SOY CMS |
2026-08-28T06:11:11.567Z | 2026-08-28T16:10:55.790Z |
| cve-2026-78238 | 5.4 (v3.0) 4.8 (v4.0) | SOY Gallery contains a cross-site scripting vuln… |
Tsuyoshi Saito |
SOY Gallery |
2026-08-28T06:11:06.057Z | 2026-08-28T16:11:28.141Z |
| cve-2026-77838 | 5.4 (v3.0) 4.8 (v4.0) | SOY Calendar contains a cross-site scripting vuln… |
Tsuyoshi Saito |
SOY Calendar |
2026-08-28T06:10:58.005Z | 2026-08-28T16:12:47.204Z |
| cve-2026-73827 | 5.4 (v3.0) 4.8 (v4.0) | SOY Calendar contains a cross-site scripting vuln… |
Tsuyoshi Saito |
SOY Calendar |
2026-08-28T06:10:48.880Z | 2026-08-28T16:14:39.069Z |
| cve-2026-79996 | N/A | User Registration & Membership < 5.2.6 - Authenticated… |
Unknown |
User Registration & Membership |
2026-08-28T06:00:17.519Z | 2026-08-28T13:03:20.076Z |
| cve-2026-79995 | N/A | User Registration & Membership < 5.2.5 - Subscriber+ P… |
Unknown |
User Registration & Membership |
2026-08-28T06:00:17.343Z | 2026-08-28T13:03:20.229Z |
| cve-2026-79706 | N/A | Breeze Cache < 2.5.13 - Unauthenticated File Creation … |
Unknown |
Breeze Cache |
2026-08-28T06:00:17.170Z | 2026-08-28T13:03:20.389Z |
| cve-2026-79615 | N/A | Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Q… |
Unknown |
Quiz and Survey Master (QSM) |
2026-08-28T06:00:17.000Z | 2026-08-28T13:03:20.541Z |
| cve-2026-77701 | N/A | WCFM Marketplace < 3.8.2 - Unauthenticated Refund Requ… |
Unknown |
WCFM Marketplace |
2026-08-28T06:00:16.799Z | 2026-08-28T13:03:20.688Z |
| cve-2026-19423 | N/A | Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privi… |
Unknown |
Ultimate Member |
2026-08-28T06:00:16.618Z | 2026-08-28T13:03:20.842Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2024-001462 | File and Directory Permissions Vulnerability in Hitachi Tuning Manager | 2024-02-05T14:54+09:00 | 2024-02-05T14:54+09:00 |
| jvndb-2024-000016 | Group Office vulnerable to cross-site scripting | 2024-02-01T13:48+09:00 | 2024-03-11T18:04+09:00 |
| jvndb-2024-000015 | Payment EX vulnerable to information disclosure | 2024-02-01T13:41+09:00 | 2024-03-11T17:42+09:00 |
| jvndb-2024-001161 | Multiple vulnerabilities in SHARP Energy Management Controller with Cloud Services | 2024-01-31T16:01+09:00 | 2024-01-31T16:01+09:00 |
| jvndb-2024-001160 | File and Directory Permissions Vulnerability in Hitachi Storage Plug-in for VMware vCenter | 2024-01-31T15:25+09:00 | 2024-03-11T17:41+09:00 |
| jvndb-2024-001062 | Yamaha wireless LAN access point devices vulnerable to active debug code | 2024-01-24T17:16+09:00 | 2024-03-13T17:24+09:00 |
| jvndb-2024-001061 | ELECOM wireless LAN routers vulnerable to OS command injection | 2024-01-24T17:16+09:00 | 2026-05-15T15:32+09:00 |
| jvndb-2024-000014 | Oracle WebLogic Server vulnerable to HTTP header injection | 2024-01-24T13:53+09:00 | 2024-01-24T13:53+09:00 |
| jvndb-2024-000005 | "Mercari" App for Android fails to restrict custom URL schemes properly | 2024-01-24T13:46+09:00 | 2024-03-04T18:01+09:00 |
| jvndb-2024-000008 | Improper restriction of XML external entity references (XXE) in MLIT "Electronic Delivery Check System" and "Electronic delivery item Inspection Support System" | 2024-01-23T16:57+09:00 | 2024-03-13T17:40+09:00 |
| jvndb-2024-000013 | Android App "Spoon" uses a hard-coded API key for an external service | 2024-01-23T16:53+09:00 | 2024-03-14T17:44+09:00 |
| jvndb-2024-000010 | Improper restriction of XML external entity references (XXE) in "Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version)" | 2024-01-23T15:25+09:00 | 2024-03-14T17:33+09:00 |
| jvndb-2024-000009 | Improper restriction of XML external entity references (XXE) in Electronic Deliverables Creation Support Tool provided by Ministry of Defense | 2024-01-23T15:13+09:00 | 2024-03-13T17:46+09:00 |
| jvndb-2024-000012 | Access analysis CGI An-Analyzer vulnerable to open redirect | 2024-01-22T15:57+09:00 | 2024-03-13T17:34+09:00 |
| jvndb-2024-000011 | Multiple vulnerabilities in a-blog cms | 2024-01-22T15:08+09:00 | 2024-03-13T17:50+09:00 |
| jvndb-2024-000006 | FusionPBX vulnerable to cross-site scripting | 2024-01-19T12:30+09:00 | 2024-03-12T17:31+09:00 |
| jvndb-2024-000007 | Multiple Dahua Technology products vulnerable to authentication bypass | 2024-01-18T13:43+09:00 | 2024-07-11T16:10+09:00 |
| jvndb-2024-000004 | Drupal vulnerable to improper handling of structural elements | 2024-01-16T13:41+09:00 | 2024-03-12T17:33+09:00 |
| jvndb-2024-000003 | Pleasanter vulnerable to cross-site scripting | 2024-01-15T15:59+09:00 | 2024-01-15T15:59+09:00 |
| jvndb-2024-000002 | Thermal camera TMC series vulnerable to insufficient technical documentation | 2024-01-15T15:19+09:00 | 2024-03-11T18:17+09:00 |
| jvndb-2024-000001 | Improper input validation vulnerability in WordPress Plugin "WordPress Quiz Maker Plugin" | 2024-01-12T13:51+09:00 | 2024-03-14T12:28+09:00 |
| jvndb-2024-001002 | Multiple TP-Link products vulnerable to OS command injection | 2024-01-10T13:57+09:00 | 2024-03-14T13:52+09:00 |
| jvndb-2024-001001 | Multiple vulnerabilities in Panasonic Control FPWIN Pro7 | 2024-01-10T13:46+09:00 | 2024-01-10T13:46+09:00 |
| jvndb-2023-000126 | Multiple vulnerabilities in PowerCMS | 2023-12-26T16:46+09:00 | 2024-03-18T17:58+09:00 |
| jvndb-2023-000125 | Multiple vulnerabilities in BUFFALO VR-S1000 | 2023-12-26T15:51+09:00 | 2024-03-19T17:56+09:00 |
| jvndb-2023-014781 | Brother iPrint&Scan Desktop for Windows vulnerable to improper link resolution before file access | 2023-12-26T09:27+09:00 | 2024-03-18T18:05+09:00 |
| jvndb-2023-012042 | WordPress plugin "MW WP Form" vulnerable to arbitrary file upload | 2023-12-15T15:17+09:00 | 2024-03-26T17:39+09:00 |
| jvndb-2023-000123 | Multiple vulnerabilities in GROWI | 2023-12-13T15:30+09:00 | 2024-03-19T17:46+09:00 |
| jvndb-2023-011403 | ELECOM wireless LAN routers vulnerable to OS command injection | 2023-12-13T15:06+09:00 | 2024-04-18T17:22+09:00 |
| jvndb-2023-000122 | Multiple denial-of-service (DoS) vulnerabilities in JTEKT ELECTRONICS HMI GC-A2 series | 2023-12-11T14:12+09:00 | 2024-04-22T16:55+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2026-avi-0525 | Multiples vulnérabilités dans Microsoft Edge | 2026-05-04T00:00:00.000000 | 2026-05-04T00:00:00.000000 |
| certfr-2026-avi-0524 | Multiples vulnérabilités dans Exim | 2026-04-30T00:00:00.000000 | 2026-04-30T00:00:00.000000 |
| certfr-2026-avi-0523 | Multiples vulnérabilités dans les produits IBM | 2026-04-30T00:00:00.000000 | 2026-04-30T00:00:00.000000 |
| certfr-2026-avi-0522 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2026-04-30T00:00:00.000000 | 2026-04-30T00:00:00.000000 |
| certfr-2026-avi-0521 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2026-04-30T00:00:00.000000 | 2026-04-30T00:00:00.000000 |
| certfr-2026-avi-0520 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-04-30T00:00:00.000000 | 2026-04-30T00:00:00.000000 |
| certfr-2026-avi-0519 | Multiples vulnérabilités dans Microsoft Azure Linux | 2026-04-30T00:00:00.000000 | 2026-04-30T00:00:00.000000 |
| certfr-2026-avi-0518 | Multiples vulnérabilités dans Wireshark | 2026-04-30T00:00:00.000000 | 2026-04-30T00:00:00.000000 |
| certfr-2026-avi-0517 | Multiples vulnérabilités dans les produits SonicWall | 2026-04-30T00:00:00.000000 | 2026-04-30T00:00:00.000000 |
| certfr-2026-avi-0516 | Vulnérabilité dans les produits Netgate | 2026-04-30T00:00:00.000000 | 2026-04-30T00:00:00.000000 |
| certfr-2026-avi-0515 | Multiples vulnérabilités dans MISP | 2026-04-30T00:00:00.000000 | 2026-06-03T00:00:00.000000 |
| certfr-2026-avi-0514 | Multiples vulnérabilités dans Curl | 2026-04-29T00:00:00.000000 | 2026-04-29T00:00:00.000000 |
| certfr-2026-avi-0513 | Multiples vulnérabilités dans les produits Microsoft | 2026-04-29T00:00:00.000000 | 2026-04-29T00:00:00.000000 |
| certfr-2026-avi-0512 | Vulnérabilité dans Microsoft Edge | 2026-04-29T00:00:00.000000 | 2026-04-29T00:00:00.000000 |
| certfr-2026-avi-0511 | Vulnérabilité dans Elastic Package Registry | 2026-04-29T00:00:00.000000 | 2026-04-29T00:00:00.000000 |
| certfr-2026-avi-0510 | Multiples vulnérabilités dans Citrix XenServer | 2026-04-29T00:00:00.000000 | 2026-04-29T00:00:00.000000 |
| certfr-2026-avi-0509 | Multiples vulnérabilités dans Xen | 2026-04-29T00:00:00.000000 | 2026-04-29T00:00:00.000000 |
| certfr-2026-avi-0508 | Multiples vulnérabilités dans Moodle | 2026-04-29T00:00:00.000000 | 2026-04-29T00:00:00.000000 |
| certfr-2026-avi-0507 | Multiples vulnérabilités dans les produits Mozilla | 2026-04-29T00:00:00.000000 | 2026-04-29T00:00:00.000000 |
| certfr-2026-avi-0506 | Multiples vulnérabilités dans Google Chrome | 2026-04-29T00:00:00.000000 | 2026-04-29T00:00:00.000000 |
| certfr-2026-avi-0505 | Vulnérabilité dans Python | 2026-04-28T00:00:00.000000 | 2026-04-28T00:00:00.000000 |
| certfr-2026-avi-0504 | Multiples vulnérabilités dans Spring | 2026-04-28T00:00:00.000000 | 2026-04-28T00:00:00.000000 |
| certfr-2026-avi-0503 | Multiples vulnérabilités dans les produits Microsoft | 2026-04-27T00:00:00.000000 | 2026-04-27T00:00:00.000000 |
| certfr-2026-avi-0502 | Multiples vulnérabilités dans Microsoft Edge | 2026-04-27T00:00:00.000000 | 2026-04-27T00:00:00.000000 |
| certfr-2026-avi-0501 | Multiples vulnérabilités dans les produits FoxIT | 2026-04-27T00:00:00.000000 | 2026-04-27T00:00:00.000000 |
| certfr-2026-avi-0500 | Multiples vulnérabilités dans VMware Tanzu | 2026-04-27T00:00:00.000000 | 2026-04-27T00:00:00.000000 |
| certfr-2026-avi-0499 | Multiples vulnérabilités dans les produits Moxa | 2026-04-27T00:00:00.000000 | 2026-04-27T00:00:00.000000 |
| certfr-2026-avi-0498 | Multiples vulnérabilités dans Zabbix Agent2 | 2026-04-27T00:00:00.000000 | 2026-04-27T00:00:00.000000 |
| certfr-2026-avi-0497 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-04-24T00:00:00.000000 | 2026-04-24T00:00:00.000000 |
| certfr-2026-avi-0496 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2026-04-24T00:00:00.000000 | 2026-04-24T00:00:00.000000 |