Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-76060 | 8.8 (v3.1) 8.7 (v4.0) | OS Command Injection in PayRange API |
Zoneminder |
Zoneminder |
2026-08-27T20:29:05.262Z | 2026-08-28T15:58:01.239Z |
| cve-2026-68929 | FastGPT: Unauthenticated WeChat channel hijack and den… |
labring |
FastGPT |
2026-08-27T20:21:30.866Z | 2026-08-28T17:48:00.135Z | |
| cve-2026-18717 | 7.4 (v3.1) 9.1 (v4.0) | Improper Certificate Validation in ASE 2000 |
Applied Systems Engineering |
ASE2000 V2 |
2026-08-27T20:20:23.451Z | 2026-08-28T15:58:08.375Z |
| cve-2026-81731 | 5.1 (v4.0) 5.4 (v3.1) | Frappe 15.11.0 through 16.32.0 Stored XSS via Workspac… |
frappe |
frappe |
2026-08-27T20:07:35.561Z | 2026-08-27T20:07:35.561Z |
| cve-2026-81730 | 8.8 (v4.0) 8.2 (v3.1) | Dolibarr 9.0.0 through 23.0.4 Path Traversal via Email… |
Dolibarr |
dolibarr |
2026-08-27T20:07:34.881Z | 2026-08-28T17:55:52.355Z |
| cve-2026-81729 | 7.1 (v4.0) 6.5 (v3.1) | Dolibarr before 23.0.4 Incorrect Authorization on REST… |
Dolibarr |
dolibarr |
2026-08-27T20:07:34.181Z | 2026-08-27T20:07:34.181Z |
| cve-2026-81728 | 8.6 (v4.0) 8.1 (v3.1) | Dolibarr before 24.0.0 SQL Injection via the CSV and X… |
Dolibarr |
dolibarr |
2026-08-27T20:07:33.503Z | 2026-08-28T14:08:40.368Z |
| cve-2026-81838 | 6.8 (v4.0) 7.1 (v3.1) | Zip Slip Arbitrary File Write in AWS diagram-as-code (… |
aws |
diagram-as-code |
2026-08-27T20:03:59.258Z | 2026-08-28T14:13:53.824Z |
| cve-2026-81834 | RooCodeInc Roo-Code README File ExecaTerminalProcess c… |
RooCodeInc |
Roo-Code |
2026-08-27T20:00:08.895Z | 2026-08-28T15:32:38.871Z | |
| cve-2026-77438 | Trilium unauthenticated share-search discloses passwor… |
TriliumNext |
Trilium |
2026-08-27T19:52:55.731Z | 2026-08-28T15:35:12.098Z | |
| cve-2026-53580 | Trilium arbitrary file read and denial of service via … |
TriliumNext |
Trilium |
2026-08-27T19:46:12.357Z | 2026-08-28T14:55:56.996Z | |
| cve-2026-81833 | RooCodeInc Roo-Code CodeIndexManager helpers.ts optimi… |
RooCodeInc |
Roo-Code |
2026-08-27T19:45:10.936Z | 2026-08-27T19:45:10.936Z | |
| cve-2026-81934 | Redis TLS pending-data list use-after-free |
Redis |
Redis |
2026-08-27T19:40:15.141Z | 2026-08-28T15:14:13.092Z | |
| cve-2026-10036 | 8.7 (v4.0) 8.8 (v3.1) | SpeechBrain < 1.1.1 Arbitrary Code Execution via CKPT.… |
speechbrain |
speechbrain |
2026-08-27T19:36:57.357Z | 2026-08-29T11:47:29.345Z |
| cve-2026-81931 | 4.8 (v4.0) | Unrestricted upload of file with dangerous type in Pro… |
Roskus |
Prospero Flow CRM |
2026-08-27T19:33:27.288Z | 2026-08-28T15:36:24.352Z |
| cve-2026-53579 | Trilium: Note Import to RCE via Book Note |
TriliumNext |
Trilium |
2026-08-27T19:33:24.490Z | 2026-08-28T15:58:18.142Z | |
| cve-2026-53578 | Trilium: Note Import to RCE via Mind Elixir dangerousl… |
TriliumNext |
Trilium |
2026-08-27T19:21:21.331Z | 2026-08-27T19:21:21.331Z | |
| cve-2026-18374 | 4.9 (v3.1) | Passing an effectively empty string to the `,ccs=… |
The GNU C Library |
glibc |
2026-08-27T19:20:40.426Z | 2026-08-28T15:37:10.821Z |
| cve-2026-74820 | 10 (v4.0) | Unauthenticated SQL Injection via Dynamic Schema ORDER… |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T19:05:04.612Z | 2026-08-29T03:56:10.853Z |
| cve-2026-18886 | 10 (v4.0) | Unauthenticated Privilege Escalation via System Config… |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T19:00:01.715Z | 2026-08-29T03:56:09.659Z |
| cve-2026-18885 | 10 (v4.0) | Unauthenticated Remote Code Execution in GraphQL Compo… |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T18:54:14.827Z | 2026-08-29T03:56:08.287Z |
| cve-2026-6876 | 8.7 (v4.0) | Sandbox Escape in Now Platform |
ServiceNow |
Now Platform |
2026-08-27T18:46:04.798Z | 2026-08-29T03:56:06.852Z |
| cve-2026-81893 | 4.7 (v3.1) | Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc prof… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-08-27T18:34:03.016Z | 2026-08-28T14:29:06.460Z |
| cve-2026-34616 | 5.5 (v3.1) | DNG SDK | Out-of-bounds Read (CWE-125) |
Adobe |
Adobe DNG Software Development Kit (SDK) |
2026-08-27T18:33:58.874Z | 2026-08-28T15:42:40.150Z |
| cve-2026-34620 | 5.5 (v3.1) | DNG SDK | Out-of-bounds Write (CWE-787) |
Adobe |
Adobe DNG Software Development Kit (SDK) |
2026-08-27T18:33:58.189Z | 2026-08-27T22:15:57.269Z |
| cve-2026-81530 | 6.8 (v4.0) 5.6 (v3.1) | KMS master key exposure via unredacted credential seri… |
MongoDB |
C# Driver |
2026-08-27T18:32:32.877Z | 2026-08-28T15:44:10.176Z |
| cve-2026-81529 | 7.1 (v4.0) 7.1 (v3.1) | Connection-option injection via unescaped settings in … |
MongoDB |
C# Driver |
2026-08-27T18:32:31.650Z | 2026-08-28T16:37:37.138Z |
| cve-2026-81528 | 5.3 (v4.0) 5.4 (v3.1) | NoSQL injection via array replacement bypassing update… |
MongoDB |
C# Driver |
2026-08-27T18:32:30.215Z | 2026-08-28T15:45:22.840Z |
| cve-2026-81527 | 6.9 (v4.0) 6.5 (v3.1) | NoSQL injection via unquoted constant GroupBy keys in … |
MongoDB |
C# Driver |
2026-08-27T18:32:28.926Z | 2026-08-28T15:46:55.682Z |
| cve-2026-81526 | 7.1 (v4.0) 6.5 (v3.1) | Cross-database write redirection via unvalidated dotte… |
MongoDB |
Rust Driver |
2026-08-27T18:32:27.704Z | 2026-08-28T15:48:02.435Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2022-000027 | Hammock AssetView missing authentication for critical functions | 2022-04-22T13:53+09:00 | 2024-06-20T12:15+09:00 |
| jvndb-2022-000026 | WordPress Plugin "MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership" vulnerable to cross-site request forgery | 2022-04-15T13:15+09:00 | 2024-06-25T18:04+09:00 |
| jvndb-2022-001526 | Trend Micro Antivirus for Mac vulnerable to privilege escalation | 2022-04-07T16:58+09:00 | 2022-04-07T16:58+09:00 |
| jvndb-2022-001494 | Trend Micro Apex Central and Trend Micro Apex Central as a Service vulnerable to improper check for file contents | 2022-03-31T17:25+09:00 | 2022-03-31T17:25+09:00 |
| jvndb-2022-000024 | Zero-channel BBS Plus vulnerable to cross-site scripting | 2022-03-30T15:36+09:00 | 2024-06-20T17:34+09:00 |
| jvndb-2022-000023 | WordPress Plugin "Advanced Custom Fields" vulnerable to missing authorization | 2022-03-30T15:23+09:00 | 2024-06-21T12:25+09:00 |
| jvndb-2022-000022 | AttacheCase may insecurely load Dynamic Link Libraries | 2022-03-30T14:00+09:00 | 2024-06-21T11:42+09:00 |
| jvndb-2022-001477 | Netcommunity OG410X and OG810X VoIP gateway/Hikari VoIP adapter for business offices vulnerable to OS command injection | 2022-03-23T12:08+09:00 | 2022-03-23T12:08+09:00 |
| jvndb-2022-000021 | Multiple vulnerabilities in KINGSOFT "WPS Office" and "KINGSOFT Internet Security" | 2022-03-16T14:46+09:00 | 2022-03-16T14:46+09:00 |
| jvndb-2022-000020 | Multiple vulnerabilities in pfSense | 2022-03-15T14:58+09:00 | 2024-06-21T11:59+09:00 |
| jvndb-2021-008345 | Installer of Trend Micro Portable Security may insecurely load Dynamic Link Libraries | 2022-03-14T16:43+09:00 | 2022-03-14T16:43+09:00 |
| jvndb-2022-001404 | Installer of Trend Micro Password Manager may insecurely load Dynamic Link Libraries | 2022-03-11T15:55+09:00 | 2022-03-11T15:55+09:00 |
| jvndb-2022-000016 | UNIVERGE WA Series vulnerable to OS command injection | 2022-03-10T14:31+09:00 | 2022-03-10T14:31+09:00 |
| jvndb-2022-001387 | Installer of WPS Office for Windows misconfigures the ACL for the installation directory | 2022-03-09T12:30+09:00 | 2024-06-21T11:37+09:00 |
| jvndb-2022-001384 | Multiple vulnerabilities in OMRON CX-Programmer | 2022-03-08T15:56+09:00 | 2024-06-21T11:32+09:00 |
| jvndb-2022-001383 | Directory Permission Vulnerability in Hitachi Ops Center Viewpoint | 2022-03-07T15:45+09:00 | 2022-03-07T15:45+09:00 |
| jvndb-2022-001382 | File Permission Vulnerability in Hitachi Command Suite | 2022-03-07T15:35+09:00 | 2022-03-07T15:35+09:00 |
| jvndb-2022-000008 | i-FILTER vulnerable to improper check for certificate revocation | 2022-03-04T14:12+09:00 | 2022-03-04T14:12+09:00 |
| jvndb-2022-000019 | pfSense-pkg-WireGuard vulnerable to directory traversal | 2022-03-03T15:08+09:00 | 2024-06-20T16:51+09:00 |
| jvndb-2022-001381 | Multiple vulnerabilities in Trend Micro ServerProtect | 2022-03-03T14:42+09:00 | 2024-06-21T17:58+09:00 |
| jvndb-2022-000018 | MarkText vulnerable to cross-site scripting | 2022-03-03T14:40+09:00 | 2024-06-20T16:46+09:00 |
| jvndb-2022-000017 | Norton Security for Mac improperly processes ICMP packets | 2022-03-03T14:32+09:00 | 2022-03-03T14:32+09:00 |
| jvndb-2022-001380 | Multiples security updates for Trend Micro Endpoint security products for enterprises (March 2022) | 2022-03-02T17:07+09:00 | 2022-03-02T17:07+09:00 |
| jvndb-2022-000015 | EC-CUBE improperly handles HTTP Host header values | 2022-02-22T14:22+09:00 | 2024-06-21T17:39+09:00 |
| jvndb-2022-000013 | EC-CUBE plugin "Mail Magazine Management Plugin" vulnerable to cross-site request forgery | 2022-02-22T14:09+09:00 | 2024-06-21T14:05+09:00 |
| jvndb-2022-000014 | Multiple vulnerabilities in a-blog cms | 2022-02-18T15:55+09:00 | 2022-02-18T15:55+09:00 |
| jvndb-2022-001372 | Trend Micro Antivirus for MAC vulnerable to privilege escalation | 2022-02-18T14:55+09:00 | 2024-06-21T18:04+09:00 |
| jvndb-2022-000012 | Multiple vulnerabilities in phpUploader | 2022-02-17T15:20+09:00 | 2022-02-17T15:20+09:00 |
| jvndb-2022-000011 | HPE Agentless Management registers unquoted service paths | 2022-02-09T15:49+09:00 | 2022-02-09T15:49+09:00 |
| jvndb-2022-001299 | Cross-site Scripting Vulnerability in JP1/IT Desktop Management 2 | 2022-02-08T17:15+09:00 | 2022-02-08T17:15+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2026-avi-0195 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-02-20T00:00:00.000000 | 2026-02-20T00:00:00.000000 |
| certfr-2026-avi-0194 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2026-02-20T00:00:00.000000 | 2026-02-20T00:00:00.000000 |
| certfr-2026-avi-0193 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2026-02-20T00:00:00.000000 | 2026-02-20T00:00:00.000000 |
| certfr-2026-avi-0192 | Multiples vulnérabilités dans le noyau Linux de Debian | 2026-02-20T00:00:00.000000 | 2026-02-20T00:00:00.000000 |
| certfr-2026-avi-0191 | Vulnérabilité dans Traefik | 2026-02-20T00:00:00.000000 | 2026-02-20T00:00:00.000000 |
| certfr-2026-avi-0190 | Multiples vulnérabilités dans Microsoft Edge | 2026-02-19T00:00:00.000000 | 2026-02-19T00:00:00.000000 |
| certfr-2026-avi-0189 | Vulnérabilité dans F5 BIG-IP | 2026-02-19T00:00:00.000000 | 2026-02-19T00:00:00.000000 |
| certfr-2026-avi-0188 | Multiples vulnérabilités dans les produits Splunk | 2026-02-19T00:00:00.000000 | 2026-02-19T00:00:00.000000 |
| certfr-2026-avi-0187 | Multiples vulnérabilités dans Tenable Security Center | 2026-02-19T00:00:00.000000 | 2026-02-23T00:00:00.000000 |
| certfr-2026-avi-0186 | Multiples vulnérabilités dans Google Chrome | 2026-02-19T00:00:00.000000 | 2026-02-19T00:00:00.000000 |
| certfr-2026-avi-0185 | Vulnérabilité dans Microsoft Windows | 2026-02-18T00:00:00.000000 | 2026-02-18T00:00:00.000000 |
| certfr-2026-avi-0184 | Multiples vulnérabilités dans Microsoft Edge | 2026-02-18T00:00:00.000000 | 2026-02-18T00:00:00.000000 |
| certfr-2026-avi-0183 | Vulnérabilité dans HPE Aruba Networking ClearPass Policy Manager | 2026-02-18T00:00:00.000000 | 2026-02-18T00:00:00.000000 |
| certfr-2026-avi-0182 | Multiples vulnérabilités dans Atlassian Confluence | 2026-02-18T00:00:00.000000 | 2026-02-18T00:00:00.000000 |
| certfr-2026-avi-0181 | Vulnérabilité dans Apache Tomcat | 2026-02-18T00:00:00.000000 | 2026-02-18T00:00:00.000000 |
| certfr-2026-avi-0180 | Vulnérabilité dans NetApp StorageGRID | 2026-02-18T00:00:00.000000 | 2026-02-18T00:00:00.000000 |
| certfr-2026-avi-0179 | Multiples vulnérabilités dans SPIP | 2026-02-18T00:00:00.000000 | 2026-02-25T00:00:00.000000 |
| certfr-2026-avi-0178 | Multiples vulnérabilités dans Tenable Security Center | 2026-02-18T00:00:00.000000 | 2026-02-18T00:00:00.000000 |
| certfr-2026-avi-0177 | Multiples vulnérabilités dans Moodle | 2026-02-17T00:00:00.000000 | 2026-02-17T00:00:00.000000 |
| certfr-2026-avi-0176 | Vulnérabilité dans Mattermost Server | 2026-02-17T00:00:00.000000 | 2026-03-17T00:00:00.000000 |
| certfr-2026-avi-0175 | Multiples vulnérabilités dans les produits Mozilla | 2026-02-17T00:00:00.000000 | 2026-02-17T00:00:00.000000 |
| certfr-2026-avi-0174 | Multiples vulnérabilités dans LibreNMS | 2026-02-17T00:00:00.000000 | 2026-02-17T00:00:00.000000 |
| certfr-2026-avi-0173 | Multiples vulnérabilités dans les produits Mattermost | 2026-02-16T00:00:00.000000 | 2026-03-17T00:00:00.000000 |
| certfr-2026-avi-0172 | Vulnérabilité dans Google Chrome | 2026-02-16T00:00:00.000000 | 2026-02-16T00:00:00.000000 |
| certfr-2026-avi-0171 | Multiples vulnérabilités dans les produits IBM | 2026-02-13T00:00:00.000000 | 2026-02-13T00:00:00.000000 |
| certfr-2026-avi-0170 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-02-13T00:00:00.000000 | 2026-02-13T00:00:00.000000 |
| certfr-2026-avi-0169 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2026-02-13T00:00:00.000000 | 2026-02-13T00:00:00.000000 |
| certfr-2026-avi-0168 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2026-02-13T00:00:00.000000 | 2026-02-13T00:00:00.000000 |
| certfr-2026-avi-0167 | Multiples vulnérabilités dans le noyau Linux de Debian LTS | 2026-02-13T00:00:00.000000 | 2026-02-13T00:00:00.000000 |
| certfr-2026-avi-0166 | Multiples vulnérabilités dans le noyau Linux de Debian | 2026-02-13T00:00:00.000000 | 2026-02-13T00:00:00.000000 |