Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-82453 | 8.7 (v4.0) 7.5 (v3.1) | rust-iot-platform Cleartext Password Storage via User Model |
iot-ecology |
rust-iot-platform |
2026-08-29T13:47:55.410Z | 2026-08-29T13:47:55.410Z |
| cve-2026-82452 | 9.3 (v4.0) 9.8 (v3.1) | rust-iot-platform Authentication Bypass via Missing Re… |
iot-ecology |
rust-iot-platform |
2026-08-29T13:47:54.696Z | 2026-08-29T13:47:54.696Z |
| cve-2026-82451 | 5.3 (v4.0) 6.1 (v3.1) | Formwork through 2.3.14 Stored XSS via Referer Header |
getformwork |
Formwork |
2026-08-29T13:47:54.007Z | 2026-08-29T13:47:54.007Z |
| cve-2026-82450 | 8.7 (v4.0) 8.8 (v3.1) | BookStack before 26.05.4 Remote Code Execution via Boo… |
bookstackapp |
bookstack |
2026-08-29T13:47:53.312Z | 2026-08-29T13:47:53.312Z |
| cve-2026-82252 | 8.7 (v4.0) 7.5 (v3.1) | gitoxide before 0.52.1 Repository Boundary Violation v… |
GitoxideLabs |
gitoxide |
2026-08-28T10:49:36.897Z | 2026-08-29T13:38:27.910Z |
| cve-2026-82251 | 8.7 (v4.0) 7.5 (v3.1) | gitoxide before 0.52.1 Path Traversal via Submodule Name |
GitoxideLabs |
gitoxide |
2026-08-28T10:49:36.185Z | 2026-08-29T13:38:27.250Z |
| cve-2026-79658 | 8.7 (v4.0) 7.5 (v3.1) | Ech0 before 5.0.1 Denial of Service via Accept-Language |
lin-snow |
Ech0 |
2026-08-25T11:33:23.319Z | 2026-08-29T13:38:26.568Z |
| cve-2026-11404 | 8.7 (v4.0) 7.5 (v3.1) | Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN … |
Cesanta |
Mongoose |
2026-07-09T15:13:40.148Z | 2026-08-29T13:38:25.855Z |
| cve-2024-58315 | 8.5 (v4.0) 7.8 (v3.1) | Tosibox Key Service 3.3.0 Local Privilege Escalation v… |
Tosibox Oy |
Tosibox Key Service |
2025-12-30T22:41:44.147Z | 2026-08-29T13:38:24.925Z |
| cve-2026-82449 | 6.9 (v4.0) 5.3 (v3.1) | Cockpit CMS before 2.14.1 Account Enumeration via Auth… |
cockpit-hq |
cockpit |
2026-08-29T12:05:35.516Z | 2026-08-29T12:05:35.516Z |
| cve-2026-82448 | 9.3 (v4.0) 9.8 (v3.1) | Shinobi before commit 5a76c74f Arbitrary Database Quer… |
Shinobi Systems |
Shinobi |
2026-08-29T12:05:34.812Z | 2026-08-29T12:05:34.812Z |
| cve-2026-82447 | 8.7 (v4.0) 8.8 (v3.1) | Skyvern before 1.0.45 Sandbox Escape via TextPromptBlock |
Skyvern-AI |
skyvern |
2026-08-29T12:05:34.113Z | 2026-08-29T12:05:34.113Z |
| cve-2026-82291 | 8.1 (v3.1) | HeyForm Reflects Any Origin in CORS Responses While Al… |
heyform |
heyform |
2026-08-28T16:19:07.930Z | 2026-08-29T11:48:21.218Z |
| cve-2026-82021 | 9 (v4.0) 8.3 (v3.1) | Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain … |
NousResearch |
hermes-agent |
2026-08-28T18:50:38.180Z | 2026-08-29T11:48:19.100Z |
| cve-2026-82020 | 7.6 (v4.0) 6.8 (v3.1) | Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrit… |
NousResearch |
hermes-agent |
2026-08-28T18:47:06.377Z | 2026-08-29T11:48:18.426Z |
| cve-2026-81735 | 10 (v4.0) 10 (v3.1) | UI-TARS-desktop @agent-infra MCP Servers Bind Every In… |
bytedance |
UI-TARS-desktop |
2026-08-27T14:51:20.291Z | 2026-08-29T11:48:17.695Z |
| cve-2026-81733 | 5.1 (v4.0) | WWBN AVideo through 30.0 CSRF via myLiveControls.save.… |
WWBN |
AVideo |
2026-08-28T10:49:23.235Z | 2026-08-29T11:48:17.019Z |
| cve-2026-81732 | 6.9 (v4.0) | WWBN AVideo through 30.0 Information Disclosure via re… |
WWBN |
AVideo |
2026-08-28T10:49:22.529Z | 2026-08-29T11:48:16.299Z |
| cve-2026-81678 | 6.9 (v4.0) 7.5 (v3.1) | AVideo SSRF Guard Bypass via IPv6 Transition Addresses |
WWBN |
AVideo |
2026-08-27T14:50:45.173Z | 2026-08-29T11:48:15.601Z |
| cve-2026-81102 | 2.3 (v4.0) 3.1 (v3.1) | Dropbox Dash MCP Server DNS Rebinding via Missing Host… |
dropbox |
mcp-server-dash |
2026-08-27T14:50:41.263Z | 2026-08-29T11:48:14.917Z |
| cve-2026-81101 | 6.9 (v4.0) 6.5 (v3.1) | Airtable MCP CLI before 0.2.5 Credential Disclosure vi… |
Airtable |
airtable-mcp-cli |
2026-08-27T14:50:40.449Z | 2026-08-29T11:48:14.223Z |
| cve-2026-81100 | 7.6 (v4.0) 6.8 (v3.1) | Timescale tiger-gh-mcp-server DNS Rebinding via Disabl… |
timescale |
tiger-gh-mcp-server |
2026-08-27T14:50:39.728Z | 2026-08-29T11:48:13.548Z |
| cve-2026-81099 | 7.6 (v4.0) 6.8 (v3.1) | Timescale tiger-slack DNS Rebinding via Disabled Host … |
timescale |
tiger-slack |
2026-08-27T14:50:39.029Z | 2026-08-29T11:48:12.861Z |
| cve-2026-81098 | 9.3 (v4.0) 9.1 (v3.1) | Telnyx MCP Server through 6.83.0 Missing Authenticatio… |
team-telnyx |
telnyx-mcp |
2026-08-27T14:50:38.327Z | 2026-08-29T11:48:12.176Z |
| cve-2026-81097 | 8.6 (v4.0) 8.4 (v3.1) | rails-mcp-server 1.4.0 through 1.6.0 OS Command Execut… |
maquina-app |
rails-mcp-server |
2026-08-27T14:50:37.617Z | 2026-08-29T11:48:11.453Z |
| cve-2026-81096 | 9.3 (v4.0) 10 (v3.1) | ToolUniverse through 1.2.6 Unauthenticated Remote Code… |
mims-harvard |
ToolUniverse |
2026-08-27T14:50:36.897Z | 2026-08-29T11:48:10.764Z |
| cve-2026-81095 | 7.6 (v4.0) 6.8 (v3.1) | Timescale pg-aiguide through 0.5.0 DNS Rebinding via D… |
timescale |
pg-aiguide |
2026-08-27T14:50:36.212Z | 2026-08-29T11:48:10.092Z |
| cve-2026-81094 | 9.3 (v4.0) 9.1 (v3.1) | mcp-router CLI before 0.6.3 Binds the MCP Aggregator t… |
mcp-router |
mcp-router |
2026-08-27T14:50:34.879Z | 2026-08-29T11:48:09.437Z |
| cve-2026-81093 | 8.7 (v4.0) 8.6 (v3.1) | Apify Actors MCP Server before 0.9.12 Server-Side Requ… |
apify |
actors-mcp-server |
2026-08-27T14:50:34.013Z | 2026-08-29T11:48:08.801Z |
| cve-2026-81092 | 7.6 (v4.0) 6.8 (v3.1) | mcp-go before 0.56.0 Missing Host Header Validation En… |
mark3labs |
mcp-go |
2026-08-27T14:50:33.286Z | 2026-08-29T11:48:08.125Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2024-000043 | Multiple vulnerabilities in MosP kintai kanri | 2024-05-09T14:10+09:00 | 2024-05-09T14:10+09:00 |
| jvndb-2023-000111 | Remarshal unlimitedly expanding YAML alias nodes | 2023-11-10T14:41+09:00 | 2024-05-08T17:53+09:00 |
| jvndb-2024-000044 | WordPress Plugin "Heateor Social Login WordPress" vulnerable to cross-site scripting | 2024-05-08T13:43+09:00 | 2024-05-08T13:43+09:00 |
| jvndb-2024-003178 | Trend Micro Maximum Security vulnerable to improper link resolution (CVE-2024-32849) | 2024-05-08T10:19+09:00 | 2024-05-08T10:19+09:00 |
| jvndb-2023-002725 | Multiple vulnerabilities in Command Center RX (CCRX) of Kyocera Document Solutions MFPs and printers | 2023-07-28T18:24+09:00 | 2024-05-07T18:15+09:00 |
| jvndb-2023-000108 | Inkdrop vulnerable to code injection | 2023-10-30T13:48+09:00 | 2024-05-07T16:09+09:00 |
| jvndb-2023-000106 | Multiple vulnerabilities in baserCMS | 2023-10-27T14:46+09:00 | 2024-05-07T15:59+09:00 |
| jvndb-2023-000109 | Cybozu Remote Service vulnerable to uncontrolled resource consumption | 2023-10-31T13:43+09:00 | 2024-05-07T15:51+09:00 |
| jvndb-2023-004919 | FUJIFILM Business Innovation Corp. and Xerox Corporation MFPs export Address Books with insufficient encryption strength | 2023-11-02T17:21+09:00 | 2024-05-07T15:25+09:00 |
| jvndb-2023-000114 | Multiple vulnerabilities in Cisco Firepower Management Center Software | 2023-11-13T14:01+09:00 | 2024-05-07T15:07+09:00 |
| jvndb-2023-000060 | Multiple vulnerabilities in Pleasanter | 2023-06-22T15:49+09:00 | 2024-05-07T14:10+09:00 |
| jvndb-2023-000110 | Improper restriction of XML external entity references (XXE) in e-Tax software | 2023-11-02T13:38+09:00 | 2024-05-01T18:41+09:00 |
| jvndb-2023-007152 | Multiple vulnerabilities in EXPRESSCLUSTER X | 2023-11-20T14:09+09:00 | 2024-05-01T18:10+09:00 |
| jvndb-2023-000113 | HOTELDRUID vulnerable to cross-site scripting | 2023-11-10T14:41+09:00 | 2024-05-01T17:47+09:00 |
| jvndb-2023-000115 | OSS Calendar vulnerable to SQL injection | 2023-11-14T14:05+09:00 | 2024-05-01T17:38+09:00 |
| jvndb-2023-000118 | Multiple vulnerabilities in CubeCart | 2023-11-17T14:22+09:00 | 2024-04-30T18:15+09:00 |
| jvndb-2023-000068 | "NewsPicks" App uses a hard-coded API key for an external service | 2023-06-30T15:06+09:00 | 2024-04-30T18:09+09:00 |
| jvndb-2023-006578 | ASUSTeK COMPUTER RT-AC87U vulnerable to improper access control | 2023-11-15T17:44+09:00 | 2024-04-30T18:08+09:00 |
| jvndb-2023-000064 | SYNCK GRAPHICA Mailform Pro CGI vulnerable to Regular expression Denial-of-Service (ReDoS) | 2023-06-20T14:48+09:00 | 2024-04-26T18:03+09:00 |
| jvndb-2023-000067 | WordPress Plugin "Snow Monkey Forms" vulnerable to directory traversal | 2023-06-27T17:05+09:00 | 2024-04-26T17:56+09:00 |
| jvndb-2023-000033 | Trend Micro Security may insecurely load Dynamic Link Libraries | 2023-04-14T15:44+09:00 | 2024-04-26T17:48+09:00 |
| jvndb-2023-006588 | Multiple vulnerabilities in ELECOM and LOGITEC routers | 2023-11-15T18:27+09:00 | 2024-04-26T15:22+09:00 |
| jvndb-2023-002511 | File and Directory Permissions Vulnerability in Hitachi Command Suite | 2023-07-19T14:48+09:00 | 2024-04-26T12:29+09:00 |
| jvndb-2023-002512 | EL Injection Vulnerability in Hitachi Replication Manager | 2023-07-19T14:48+09:00 | 2024-04-26T12:24+09:00 |
| jvndb-2024-003119 | NETGEAR routers vulnerable to buffer overflow | 2024-04-25T11:21+09:00 | 2024-04-25T11:21+09:00 |
| jvndb-2024-000042 | Multiple vulnerabilities in RoamWiFi R10 | 2024-04-24T13:44+09:00 | 2024-04-24T13:44+09:00 |
| jvndb-2024-003008 | Sangoma Technologies CG/MG family driver cg6kwin2k.sys vulnerable to insufficient access control on its IOCTL | 2024-03-22T13:50+09:00 | 2024-04-24T11:45+09:00 |
| jvndb-2023-003028 | Phoenix Technologies Windows kernel driver vulnerable to insufficient access control on its IOCTL | 2023-08-30T10:05+09:00 | 2024-04-24T11:43+09:00 |
| jvndb-2024-003116 | Multiple vulnerabilities in OMRON Sysmac Studio/CX-One and CX-Programmer | 2024-04-24T10:13+09:00 | 2024-04-24T10:13+09:00 |
| jvndb-2024-000901 | TvRock vulnerable to cross-site request forgery | 2024-04-23T18:22+09:00 | 2024-04-23T18:22+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2026-avi-0378 | Vulnérabilité dans Symantec Data Loss Prevention (DLP) | 2026-03-31T00:00:00.000000 | 2026-03-31T00:00:00.000000 |
| certfr-2026-avi-0377 | Multiples vulnérabilités dans Papercut | 2026-03-31T00:00:00.000000 | 2026-03-31T00:00:00.000000 |
| certfr-2026-avi-0376 | Multiples vulnérabilités dans les produits Microsoft | 2026-03-30T00:00:00.000000 | 2026-03-30T00:00:00.000000 |
| certfr-2026-avi-0375 | Multiples vulnérabilités dans Microsoft Edge | 2026-03-30T00:00:00.000000 | 2026-03-30T00:00:00.000000 |
| certfr-2026-avi-0374 | Vulnérabilité dans Docker Desktop | 2026-03-30T00:00:00.000000 | 2026-03-30T00:00:00.000000 |
| certfr-2026-avi-0372 | Multiples vulnérabilités dans les produits IBM | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0371 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0370 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0369 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0368 | Vulnérabilité dans les produits Microsoft | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0367 | Multiples vulnérabilités dans Zabbix | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0366 | Multiples vulnérabilités dans Traefik | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0365 | Multiples vulnérabilités dans Spring AI | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0364 | Multiples vulnérabilités dans les produits Siemens | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0363 | Multiples vulnérabilités dans les produits NetApp | 2026-03-27T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0300 | Multiples vulnérabilités dans Mattermost Server | 2026-03-17T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0133 | Multiples vulnérabilités dans Roundcube | 2026-02-09T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0362 | Multiples vulnérabilités dans les produits Microsoft | 2026-03-26T00:00:00.000000 | 2026-03-26T00:00:00.000000 |
| certfr-2026-avi-0361 | Multiples vulnérabilités dans Cisco IOS et IOS XE | 2026-03-26T00:00:00.000000 | 2026-03-26T00:00:00.000000 |
| certfr-2026-avi-0360 | Multiples vulnérabilités dans ISC BIND | 2026-03-26T00:00:00.000000 | 2026-03-26T00:00:00.000000 |
| certfr-2026-avi-0359 | Multiples vulnérabilités dans Grafana | 2026-03-26T00:00:00.000000 | 2026-03-26T00:00:00.000000 |
| certfr-2026-avi-0201 | Multiples vulnérabilités dans Mattermost Server | 2026-02-24T00:00:00.000000 | 2026-03-26T00:00:00.000000 |
| certfr-2026-avi-0358 | Vulnérabilité dans Citrix XenServer | 2026-03-25T00:00:00.000000 | 2026-03-25T00:00:00.000000 |
| certfr-2026-avi-0357 | Multiples vulnérabilités dans GitLab | 2026-03-25T00:00:00.000000 | 2026-03-25T00:00:00.000000 |
| certfr-2026-avi-0356 | Vulnérabilité dans ISC Kea | 2026-03-25T00:00:00.000000 | 2026-03-25T00:00:00.000000 |
| certfr-2026-avi-0355 | Multiples vulnérabilités dans les produits Apple | 2026-03-25T00:00:00.000000 | 2026-03-25T00:00:00.000000 |
| certfr-2026-avi-0354 | Multiples vulnérabilités dans les produits Mozilla | 2026-03-25T00:00:00.000000 | 2026-03-25T00:00:00.000000 |
| certfr-2026-avi-0353 | Multiples vulnérabilités dans Zabbix | 2026-03-25T00:00:00.000000 | 2026-03-25T00:00:00.000000 |
| certfr-2026-avi-0352 | Multiples vulnérabilités dans les produits F5 | 2026-03-25T00:00:00.000000 | 2026-03-25T00:00:00.000000 |
| certfr-2026-avi-0351 | Vulnérabilité dans Tenable OT Platform | 2026-03-25T00:00:00.000000 | 2026-03-25T00:00:00.000000 |