Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-50152 | Ceph Monitor subscription handler improperly authorize… |
ceph |
ceph |
2026-08-27T20:53:42.353Z | 2026-08-28T15:06:15.096Z | |
| cve-2026-68967 | 6.5 (v3.1) 7.1 (v4.0) | Out-of-bounds Write in Bendix EC80 Brake ECU |
Bendix |
EC80ESP+ J1708 |
2026-08-27T20:50:22.011Z | 2026-08-28T14:13:53.649Z |
| cve-2026-39944 | Ceph: CephX AES Authentication error |
ceph |
ceph |
2026-08-27T20:47:01.512Z | 2026-08-28T15:57:39.530Z | |
| cve-2026-71396 | 5.4 (v3.1) 5.3 (v4.0) | Use of Hard-coded Credentials in Bendix EC80 Brake ECU |
Bendix |
EC80ESP+ J1708 |
2026-08-27T20:45:52.804Z | 2026-08-28T15:57:46.738Z |
| cve-2026-81835 | RooCodeInc Roo-Code MCP Integration Trust Model malici… |
RooCodeInc |
Roo-Code |
2026-08-27T20:45:10.575Z | 2026-08-28T17:45:48.917Z | |
| cve-2025-30156 | Ceph: AES-CBC misuse in CephX and RADOSGW enables auth… |
ceph |
ceph |
2026-08-27T20:34:41.822Z | 2026-08-27T20:34:41.822Z | |
| cve-2026-18965 | 8.8 (v3.1) 8.7 (v4.0) | Missing Authorization in PayRange API |
PayRange |
PayRange API |
2026-08-27T20:34:16.692Z | 2026-08-28T15:57:53.992Z |
| cve-2026-76060 | 8.8 (v3.1) 8.7 (v4.0) | OS Command Injection in PayRange API |
Zoneminder |
Zoneminder |
2026-08-27T20:29:05.262Z | 2026-08-28T15:58:01.239Z |
| cve-2026-68929 | FastGPT: Unauthenticated WeChat channel hijack and den… |
labring |
FastGPT |
2026-08-27T20:21:30.866Z | 2026-08-28T17:48:00.135Z | |
| cve-2026-18717 | 7.4 (v3.1) 9.1 (v4.0) | Improper Certificate Validation in ASE 2000 |
Applied Systems Engineering |
ASE2000 V2 |
2026-08-27T20:20:23.451Z | 2026-08-28T15:58:08.375Z |
| cve-2026-81731 | 5.1 (v4.0) 5.4 (v3.1) | Frappe 15.11.0 through 16.32.0 Stored XSS via Workspac… |
frappe |
frappe |
2026-08-27T20:07:35.561Z | 2026-08-27T20:07:35.561Z |
| cve-2026-81730 | 8.8 (v4.0) 8.2 (v3.1) | Dolibarr 9.0.0 through 23.0.4 Path Traversal via Email… |
Dolibarr |
dolibarr |
2026-08-27T20:07:34.881Z | 2026-08-28T17:55:52.355Z |
| cve-2026-81729 | 7.1 (v4.0) 6.5 (v3.1) | Dolibarr before 23.0.4 Incorrect Authorization on REST… |
Dolibarr |
dolibarr |
2026-08-27T20:07:34.181Z | 2026-08-27T20:07:34.181Z |
| cve-2026-81728 | 8.6 (v4.0) 8.1 (v3.1) | Dolibarr before 24.0.0 SQL Injection via the CSV and X… |
Dolibarr |
dolibarr |
2026-08-27T20:07:33.503Z | 2026-08-28T14:08:40.368Z |
| cve-2026-81838 | 6.8 (v4.0) 7.1 (v3.1) | Zip Slip Arbitrary File Write in AWS diagram-as-code (… |
aws |
diagram-as-code |
2026-08-27T20:03:59.258Z | 2026-08-28T14:13:53.824Z |
| cve-2026-81834 | RooCodeInc Roo-Code README File ExecaTerminalProcess c… |
RooCodeInc |
Roo-Code |
2026-08-27T20:00:08.895Z | 2026-08-28T15:32:38.871Z | |
| cve-2026-77438 | Trilium unauthenticated share-search discloses passwor… |
TriliumNext |
Trilium |
2026-08-27T19:52:55.731Z | 2026-08-28T15:35:12.098Z | |
| cve-2026-53580 | Trilium arbitrary file read and denial of service via … |
TriliumNext |
Trilium |
2026-08-27T19:46:12.357Z | 2026-08-28T14:55:56.996Z | |
| cve-2026-81833 | RooCodeInc Roo-Code CodeIndexManager helpers.ts optimi… |
RooCodeInc |
Roo-Code |
2026-08-27T19:45:10.936Z | 2026-08-27T19:45:10.936Z | |
| cve-2026-81934 | Redis TLS pending-data list use-after-free |
Redis |
Redis |
2026-08-27T19:40:15.141Z | 2026-08-28T15:14:13.092Z | |
| cve-2026-10036 | 8.7 (v4.0) 8.8 (v3.1) | SpeechBrain < 1.1.1 Arbitrary Code Execution via CKPT.… |
speechbrain |
speechbrain |
2026-08-27T19:36:57.357Z | 2026-08-29T11:47:29.345Z |
| cve-2026-81931 | 4.8 (v4.0) | Unrestricted upload of file with dangerous type in Pro… |
Roskus |
Prospero Flow CRM |
2026-08-27T19:33:27.288Z | 2026-08-28T15:36:24.352Z |
| cve-2026-53579 | Trilium: Note Import to RCE via Book Note |
TriliumNext |
Trilium |
2026-08-27T19:33:24.490Z | 2026-08-28T15:58:18.142Z | |
| cve-2026-53578 | Trilium: Note Import to RCE via Mind Elixir dangerousl… |
TriliumNext |
Trilium |
2026-08-27T19:21:21.331Z | 2026-08-27T19:21:21.331Z | |
| cve-2026-18374 | 4.9 (v3.1) | Passing an effectively empty string to the `,ccs=… |
The GNU C Library |
glibc |
2026-08-27T19:20:40.426Z | 2026-08-28T15:37:10.821Z |
| cve-2026-74820 | 10 (v4.0) | Unauthenticated SQL Injection via Dynamic Schema ORDER… |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T19:05:04.612Z | 2026-08-29T03:56:10.853Z |
| cve-2026-18886 | 10 (v4.0) | Unauthenticated Privilege Escalation via System Config… |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T19:00:01.715Z | 2026-08-29T03:56:09.659Z |
| cve-2026-18885 | 10 (v4.0) | Unauthenticated Remote Code Execution in GraphQL Compo… |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T18:54:14.827Z | 2026-08-29T03:56:08.287Z |
| cve-2026-6876 | 8.7 (v4.0) | Sandbox Escape in Now Platform |
ServiceNow |
Now Platform |
2026-08-27T18:46:04.798Z | 2026-08-29T03:56:06.852Z |
| cve-2026-81893 | 4.7 (v3.1) | Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc prof… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-08-27T18:34:03.016Z | 2026-08-28T14:29:06.460Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2022-000049 | HOME SPOT CUBE2 vulnerable to OS command injection | 2022-06-29T13:42+09:00 | 2024-06-17T10:45+09:00 |
| jvndb-2022-000048 | L2Blocker Sensor setup screen vulnerable to authentication bypass | 2022-06-24T14:21+09:00 | 2024-06-18T10:45+09:00 |
| jvndb-2022-000047 | web2py vulnerable to open redirect | 2022-06-23T14:21+09:00 | 2024-06-18T10:48+09:00 |
| jvndb-2022-000046 | Gitlab vulnerable to server-side request forgery | 2022-06-17T12:26+09:00 | 2024-06-20T15:39+09:00 |
| jvndb-2022-001953 | Growi vulnerable to weak password requirements | 2022-06-15T17:47+09:00 | 2022-06-15T17:47+09:00 |
| jvndb-2022-000045 | FreeBSD vulnerable to denial-of-service (DoS) | 2022-06-15T12:28+09:00 | 2024-06-13T16:31+09:00 |
| jvndb-2022-000044 | Cisco Catalyst 2940 Series Switches vulnerable to cross-site scripting | 2022-06-14T13:46+09:00 | 2024-06-18T10:51+09:00 |
| jvndb-2022-000043 | SHIRASAGI vulnerable to cross-site scripting | 2022-06-09T13:31+09:00 | 2024-06-18T11:13+09:00 |
| jvndb-2022-001948 | Multiple vulnerabilities in Trend Micro Apex One and Apex One as a Service | 2022-06-03T12:17+09:00 | 2024-06-18T16:30+09:00 |
| jvndb-2022-000042 | T&D Data Server and THERMO RECORDER DATA SERVER contain a directory traversal vulnerability. | 2022-06-01T16:12+09:00 | 2024-06-18T10:34+09:00 |
| jvndb-2022-000041 | WordPress Plugin "Modern Events Calendar Lite" vulnerable to cross-site scripting | 2022-06-01T13:39+09:00 | 2024-06-18T10:42+09:00 |
| jvndb-2022-000039 | RevoWorks incomplete filtering of MS Office v4 macros | 2022-05-27T16:09+09:00 | 2024-06-18T16:31+09:00 |
| jvndb-2022-000040 | Mobaoku-Auction & Flea Market App for iOS vulnerable to improper server certificate verification | 2022-05-27T15:48+09:00 | 2024-06-18T11:06+09:00 |
| jvndb-2022-001929 | Multiple vulnerabilities in Fuji Electric V-SFT | 2022-05-27T15:39+09:00 | 2024-06-18T13:44+09:00 |
| jvndb-2022-001931 | Multiple vulnerabilities in Fuji Electric V-SFT, V-Server and V-Server Lite | 2022-05-27T15:37+09:00 | 2024-06-18T16:28+09:00 |
| jvndb-2022-001923 | Multiple vulnerabilities in CONTEC SolarView Compact | 2022-05-27T15:28+09:00 | 2024-06-20T11:34+09:00 |
| jvndb-2022-001809 | Trend Micro Password Manager vulnerable to privilege escalation | 2022-05-24T15:27+09:00 | 2024-06-18T17:52+09:00 |
| jvndb-2022-000038 | WordPress plugin "WP Statistics" vulnerable to cross-site scripting | 2022-05-24T15:00+09:00 | 2024-06-18T15:41+09:00 |
| jvndb-2022-000037 | Spring Security OAuth (spring-security-oauth2) vulnerable to denial-of-service (DoS) | 2022-05-20T17:04+09:00 | 2024-06-20T12:09+09:00 |
| jvndb-2022-000036 | Multiple vulnerabilities in Rakuten Casa | 2022-05-19T15:13+09:00 | 2024-06-18T12:09+09:00 |
| jvndb-2022-000035 | Multiple vulnerabilities in Cybozu Garoon | 2022-05-16T14:25+09:00 | 2024-06-17T16:34+09:00 |
| jvndb-2022-000033 | Strapi vulnerable to cross-site scripting | 2022-05-13T16:45+09:00 | 2024-06-18T11:17+09:00 |
| jvndb-2022-000034 | EC-CUBE plugin "Easy Blog for EC-CUBE4" vulnerable to cross-site request forgery | 2022-05-13T16:31+09:00 | 2024-06-18T12:13+09:00 |
| jvndb-2022-001800 | Installer of Trend Micro HouseCall for Home Networks may insecurely load Dynamic Link Libraries | 2022-05-13T16:24+09:00 | 2022-05-13T16:24+09:00 |
| jvndb-2022-001795 | Command injection vulnerability in QNAP VioStar series NVR | 2022-05-12T18:07+09:00 | 2024-06-20T11:31+09:00 |
| jvndb-2022-000032 | Installer of Trend Micro Password Manager may insecurely load Dynamic Link Libraries | 2022-05-11T15:21+09:00 | 2024-06-18T17:46+09:00 |
| jvndb-2022-000031 | GENEREX RCCMD vulnerable to directory traversal | 2022-05-10T15:47+09:00 | 2024-06-18T15:35+09:00 |
| jvndb-2022-000030 | Multiple vulnerabilities in Operation management interface of FUJITSU Network IPCOM | 2022-05-09T15:02+09:00 | 2024-07-18T16:30+09:00 |
| jvndb-2022-000029 | KOYO Electronics Screen Creator Advance2 vulnerable to authentication bypass | 2022-05-09T14:43+09:00 | 2024-06-19T16:03+09:00 |
| jvndb-2022-000028 | Multiple vulnerabilities in multiple MEIKYO ELECTRIC products | 2022-05-09T14:31+09:00 | 2024-06-19T15:55+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2026-avi-0225 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-02-27T00:00:00.000000 | 2026-02-27T00:00:00.000000 |
| certfr-2026-avi-0224 | Multiples vulnérabilités dans les produits IBM | 2026-02-27T00:00:00.000000 | 2026-02-27T00:00:00.000000 |
| certfr-2026-avi-0223 | Multiples vulnérabilités dans les produits Microsoft | 2026-02-27T00:00:00.000000 | 2026-02-27T00:00:00.000000 |
| certfr-2026-avi-0222 | Multiples vulnérabilités dans Microsoft Edge | 2026-02-27T00:00:00.000000 | 2026-02-27T00:00:00.000000 |
| certfr-2026-avi-0221 | Multiples vulnérabilités dans les produits Centreon | 2026-02-27T00:00:00.000000 | 2026-02-27T00:00:00.000000 |
| certfr-2026-avi-0220 | Multiples vulnérabilités dans les produits Elastic | 2026-02-27T00:00:00.000000 | 2026-02-27T00:00:00.000000 |
| certfr-2026-avi-0219 | Vulnérabilité dans Stormshield Network Security | 2026-02-27T00:00:00.000000 | 2026-02-27T00:00:00.000000 |
| certfr-2026-avi-0218 | Multiples vulnérabilités dans les produits VMware | 2026-02-26T00:00:00.000000 | 2026-02-26T00:00:00.000000 |
| certfr-2026-avi-0217 | Multiples vulnérabilités dans SPIP | 2026-02-26T00:00:00.000000 | 2026-03-03T00:00:00.000000 |
| certfr-2026-avi-0216 | Vulnérabilité dans PostgreSQL | 2026-02-26T00:00:00.000000 | 2026-02-26T00:00:00.000000 |
| certfr-2026-avi-0215 | Multiples vulnérabilités dans les produits Microsoft | 2026-02-26T00:00:00.000000 | 2026-02-26T00:00:00.000000 |
| certfr-2026-avi-0214 | Vulnérabilité dans Juniper Networks Junos OS Evolved | 2026-02-26T00:00:00.000000 | 2026-02-26T00:00:00.000000 |
| certfr-2026-avi-0213 | Multiples vulnérabilités dans les produits Cisco | 2026-02-26T00:00:00.000000 | 2026-02-26T00:00:00.000000 |
| certfr-2026-avi-0212 | Multiples vulnérabilités dans les produits Centreon | 2026-02-26T00:00:00.000000 | 2026-02-26T00:00:00.000000 |
| certfr-2026-avi-0211 | Multiples vulnérabilités dans Wireshark | 2026-02-26T00:00:00.000000 | 2026-02-26T00:00:00.000000 |
| certfr-2026-avi-0210 | Multiples vulnérabilités dans Cisco Catalyst SD-WAN | 2026-02-25T00:00:00.000000 | 2026-02-25T00:00:00.000000 |
| certfr-2026-avi-0209 | Multiples vulnérabilités dans les produits VMware | 2026-02-25T00:00:00.000000 | 2026-02-25T00:00:00.000000 |
| certfr-2026-avi-0208 | Vulnérabilité dans les produits Synology | 2026-02-25T00:00:00.000000 | 2026-02-25T00:00:00.000000 |
| certfr-2026-avi-0207 | Multiples vulnérabilités dans GitLab | 2026-02-25T00:00:00.000000 | 2026-02-25T00:00:00.000000 |
| certfr-2026-avi-0206 | Multiples vulnérabilités dans les produits Trend Micro | 2026-02-25T00:00:00.000000 | 2026-02-25T00:00:00.000000 |
| certfr-2026-avi-0205 | Multiples vulnérabilités dans SolarWinds Serv-U | 2026-02-25T00:00:00.000000 | 2026-02-25T00:00:00.000000 |
| certfr-2026-avi-0204 | Multiples vulnérabilités dans les produits Mozilla | 2026-02-25T00:00:00.000000 | 2026-02-25T00:00:00.000000 |
| certfr-2026-avi-0203 | Vulnérabilité dans Microsoft Azure Linux | 2026-02-24T00:00:00.000000 | 2026-02-24T00:00:00.000000 |
| certfr-2026-avi-0202 | Multiples vulnérabilités dans les produits SonicWall | 2026-02-24T00:00:00.000000 | 2026-02-24T00:00:00.000000 |
| certfr-2026-avi-0201 | Multiples vulnérabilités dans Mattermost Server | 2026-02-24T00:00:00.000000 | 2026-03-26T00:00:00.000000 |
| certfr-2026-avi-0200 | Vulnérabilité dans Centreon open tickets | 2026-02-24T00:00:00.000000 | 2026-02-24T00:00:00.000000 |
| certfr-2026-avi-0199 | Multiples vulnérabilités dans les produits VMware | 2026-02-24T00:00:00.000000 | 2026-02-24T00:00:00.000000 |
| certfr-2026-avi-0198 | Multiples vulnérabilités dans Google Chrome | 2026-02-24T00:00:00.000000 | 2026-02-24T00:00:00.000000 |
| certfr-2026-avi-0197 | Multiples vulnérabilités dans Microsoft Edge | 2026-02-23T00:00:00.000000 | 2026-02-23T00:00:00.000000 |
| certfr-2026-avi-0196 | Multiples vulnérabilités dans les produits IBM | 2026-02-20T00:00:00.000000 | 2026-02-20T00:00:00.000000 |