Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-79108 | N/A | UI misrepresentation in Web Authentication (Passk… |
Google |
Chrome |
2026-08-25T20:10:54.601Z | 2026-08-27T15:19:44.940Z |
| cve-2026-77507 | Weblate: Object-scoped RSS feeds disclose private chan… |
WeblateOrg |
weblate |
2026-08-26T20:45:23.951Z | 2026-08-27T15:19:25.959Z | |
| cve-2026-55540 | PraisonAI: [Path Traversal] agent tools escape the con… |
MervinPraison |
PraisonAI |
2026-08-25T14:54:32.407Z | 2026-08-27T15:19:10.382Z | |
| cve-2026-81202 | itsourcecode Payroll System CRUD Operation ajax.php de… |
itsourcecode |
Payroll System |
2026-08-26T21:30:11.519Z | 2026-08-27T15:18:33.470Z | |
| cve-2026-78980 | N/A | Improper input validation in ReaderMode in Google… |
Google |
Chrome |
2026-08-25T20:10:55.151Z | 2026-08-27T15:18:26.804Z |
| cve-2026-55534 | PraisonAI serve agents --api-key is ignored, allowing … |
MervinPraison |
PraisonAI |
2026-08-25T14:41:13.869Z | 2026-08-27T15:18:13.151Z | |
| cve-2026-47665 | Penpot: Stored XSS via comment content, innerHTML rend… |
penpot |
penpot |
2026-08-26T22:50:34.362Z | 2026-08-27T15:16:47.257Z | |
| cve-2026-78947 | N/A | Incomplete cleanup in Chromium in Google Chrome p… |
Google |
Chrome |
2026-08-25T20:10:55.353Z | 2026-08-27T15:15:51.016Z |
| cve-2026-47850 | 4.3 (v3.1) | Spring Data REST allows mutation of the version proper… |
Spring |
Spring Data REST |
2026-08-26T23:28:40.729Z | 2026-08-27T15:15:43.277Z |
| cve-2026-55529 | PraisonAI: Origin validation bypass in MCP HTTP Stream… |
MervinPraison |
PraisonAI |
2026-08-25T14:26:30.692Z | 2026-08-27T15:15:14.217Z | |
| cve-2026-47851 | 7.5 (v3.1) | Unbounded recursion over attacker-controlled PDF outli… |
Spring |
Spring AI |
2026-08-26T23:28:41.732Z | 2026-08-27T15:14:42.087Z |
| cve-2026-79406 | macrozheng mall quantity OmsCartItemServiceImpl.update… |
macrozheng |
mall |
2026-08-25T13:00:09.821Z | 2026-08-27T15:14:14.547Z | |
| cve-2026-47852 | 7.5 (v3.1) | Predictable cache directory location allows local ONNX… |
Spring |
Spring AI |
2026-08-26T23:28:42.767Z | 2026-08-27T15:13:55.925Z |
| cve-2026-47856 | 6.3 (v3.1) | JsonToObjectTransformer resolves the json__TypeId__ me… |
Spring |
Spring Integration |
2026-08-26T23:28:43.829Z | 2026-08-27T15:12:42.355Z |
| cve-2026-79666 | 7.1 (v4.0) 6.5 (v3.1) | Ech0 before 4.4.3 Missing Authorization via dashboard … |
lin-snow |
Ech0 |
2026-08-25T11:33:28.747Z | 2026-08-27T15:11:56.193Z |
| cve-2026-79661 | 6.9 (v4.0) 6.5 (v3.1) | Ech0 before 4.7.3 Unauthenticated fav_count Modification |
lin-snow |
Ech0 |
2026-08-25T11:33:25.369Z | 2026-08-27T15:10:35.322Z |
| cve-2026-79021 | N/A | Missing authorization in InterestGroups in Google… |
Google |
Chrome |
2026-08-25T20:10:57.838Z | 2026-08-27T15:07:53.241Z |
| cve-2026-47857 | 5.9 (v3.1) | Reactor Core windowTimeout fair-backpressure stream ha… |
Spring |
Reactor Core |
2026-08-26T23:28:44.743Z | 2026-08-27T15:07:38.775Z |
| cve-2026-18982 | 8.8 (v3.1) | Odh-training-operator-rhel9: rhoai fork aggregates tra… |
Red Hat |
Red Hat OpenShift AI 2.25 |
2026-08-10T20:45:19.349Z | 2026-08-27T15:07:01.477Z |
| cve-2026-18951 | 8.8 (v3.1) | Odh-training-operator-rhel9: [trainer v2 security] trn… |
Red Hat |
Red Hat OpenShift AI 3.3 |
2026-08-10T20:45:10.112Z | 2026-08-27T15:06:57.539Z |
| cve-2026-18948 | 9.9 (v3.1) | Feast: feast: unsafe dill deserialization of registry-… |
Red Hat |
Red Hat OpenShift AI 2.25 |
2026-08-10T20:44:56.502Z | 2026-08-27T15:06:49.889Z |
| cve-2026-19949 | All-in-One WP Migration and Backup <= 7.109 - Unauthen… |
servmask |
All-in-One WP Migration and Backup |
2026-08-25T11:27:11.038Z | 2026-08-27T15:06:46.926Z | |
| cve-2026-47880 | 5.4 (v3.1) | DefaultJmsHeaderMapper copies all JMS user properties … |
Spring |
Spring Integration |
2026-08-27T05:20:25.359Z | 2026-08-27T15:06:37.711Z |
| cve-2026-15467 | 8.1 (v3.1) | Trustyai-service-operator: trustyai-service-operator: … |
Red Hat |
Red Hat OpenShift AI 2.25 |
2026-08-10T20:44:12.686Z | 2026-08-27T15:06:18.175Z |
| cve-2026-78863 | liketrek TREK Pre-2FA mfa_token authService.ts loginUs… |
liketrek |
TREK |
2026-08-25T11:00:10.236Z | 2026-08-27T15:06:04.339Z | |
| cve-2026-14450 | 9.9 (v3.1) | Maas-billing: maas api: privilege escalation via forge… |
Red Hat |
Red Hat OpenShift AI 3.4 |
2026-08-10T20:44:06.818Z | 2026-08-27T15:06:04.247Z |
| cve-2026-13717 | 8.8 (v3.1) | Rhoai maas: llm-d: maas/llm-d inference gateway: defau… |
|
|
2026-08-10T20:44:01.309Z | 2026-08-27T15:06:00.355Z |
| cve-2026-63587 | 8.8 (v4.0) 8.6 (v3.1) | SMS Password Authorization Bypass via Failed Attempt Counter |
Weidmueller Interface |
IE-SR-2TX-WL-4G-EU |
2026-08-25T08:55:12.442Z | 2026-08-27T15:04:29.396Z |
| cve-2026-65641 | A vulnerability allowing an unauthenticated netwo… |
Veeam |
One |
2026-08-26T21:21:40.955Z | 2026-08-27T15:04:11.392Z | |
| cve-2026-58070 | A vulnerability that records guest OS processing … |
Veeam |
Backup and Replication |
2026-08-26T21:21:41.107Z | 2026-08-27T15:04:11.211Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2015-avi-504 | Vulnérabilité dans Blue Coat Unified Agent | 2015-11-25T00:00:00.000000 | 2015-11-25T00:00:00.000000 |
| certfr-2015-avi-503 | Vulnérabilité dans Cisco ASA | 2015-11-25T00:00:00.000000 | 2015-11-25T00:00:00.000000 |
| certfr-2015-avi-502 | Vulnérabilité dans Cisco Firepower 9000 Series Switch | 2015-11-24T00:00:00.000000 | 2015-11-24T00:00:00.000000 |
| certfr-2015-avi-501 | Vulnérabilité dans Cisco Virtual Topology System | 2015-11-24T00:00:00.000000 | 2015-11-24T00:00:00.000000 |
| certfr-2015-avi-500 | Vulnérabilité dans Cisco Networking Services | 2015-11-24T00:00:00.000000 | 2015-11-24T00:00:00.000000 |
| certfr-2015-avi-499 | Vulnérabilité dans Cisco TelePresence Video Communication Server | 2015-11-24T00:00:00.000000 | 2015-11-24T00:00:00.000000 |
| certfr-2015-avi-498 | Multiples vulnérabilités dans les noyaux Linux Red Hat | 2015-11-24T00:00:00.000000 | 2015-11-24T00:00:00.000000 |
| certfr-2015-avi-497 | Vulnérabilité dans Wireshark | 2015-11-24T00:00:00.000000 | 2015-11-24T00:00:00.000000 |
| certfr-2015-avi-496 | Vulnérabilité dans Vmware | 2015-11-19T00:00:00.000000 | 2015-11-19T00:00:00.000000 |
| certfr-2015-avi-495 | Multiples vulnérabilités dans les pilotes Nvidia | 2015-11-19T00:00:00.000000 | 2015-11-19T00:00:00.000000 |
| certfr-2015-avi-494 | Multiples vulnérabilités dans les produits Cisco | 2015-11-18T00:00:00.000000 | 2015-11-18T00:00:00.000000 |
| certfr-2015-avi-493 | Multiples vulnérabilités dans Adobe ColdFusion | 2015-11-18T00:00:00.000000 | 2015-11-18T00:00:00.000000 |
| certfr-2015-avi-492 | Multiples vulnérabilités dans les produits Cisco | 2015-11-17T00:00:00.000000 | 2015-11-17T00:00:00.000000 |
| certfr-2015-avi-491 | Vulnérabilité dans dovecot | 2015-11-17T00:00:00.000000 | 2015-11-17T00:00:00.000000 |
| certfr-2015-avi-490 | Vulnérabilité dans Drupal | 2015-11-17T00:00:00.000000 | 2015-11-17T00:00:00.000000 |
| certfr-2015-avi-489 | Multiples vulnérabilités dans les produits Cisco | 2015-11-16T00:00:00.000000 | 2015-11-16T00:00:00.000000 |
| certfr-2015-avi-488 | Multiples vulnérabilités dans libpng | 2015-11-16T00:00:00.000000 | 2015-11-16T00:00:00.000000 |
| certfr-2015-avi-487 | Vulnérabilité dans Huawei P7 | 2015-11-13T00:00:00.000000 | 2015-11-13T00:00:00.000000 |
| certfr-2015-avi-486 | Vulnérabilité dans Cisco IOS | 2015-11-13T00:00:00.000000 | 2015-11-13T00:00:00.000000 |
| certfr-2015-avi-485 | Multiples vulnérabilités dans Citrix NetScaler Service Delivery Appliance | 2015-11-13T00:00:00.000000 | 2015-11-13T00:00:00.000000 |
| certfr-2015-avi-484 | Multiples vulnérabilités dans Oracle WebLogic Server | 2015-11-13T00:00:00.000000 | 2015-11-13T00:00:00.000000 |
| certfr-2015-avi-483 | Vulnérabilité dans Cisco FireSIGHT Management Center | 2015-11-12T00:00:00.000000 | 2015-11-12T00:00:00.000000 |
| certfr-2015-avi-482 | Vulnérabilité dans Google Chrome | 2015-11-12T00:00:00.000000 | 2015-11-12T00:00:00.000000 |
| certfr-2015-avi-481 | Multiples vulnérabilités dans Adobe Flash Player | 2015-11-12T00:00:00.000000 | 2015-11-12T00:00:00.000000 |
| certfr-2015-avi-480 | Vulnérabilité dans Microsoft Skype | 2015-11-12T00:00:00.000000 | 2015-11-12T00:00:00.000000 |
| certfr-2015-avi-479 | Vulnérabilité dans Microsoft Windows | 2015-11-12T00:00:00.000000 | 2015-11-12T00:00:00.000000 |
| certfr-2015-avi-478 | Vulnérabilité dans Microsoft Windows | 2015-11-12T00:00:00.000000 | 2015-11-12T00:00:00.000000 |
| certfr-2015-avi-477 | Vulnérabilité dans Microsoft Windows | 2015-11-12T00:00:00.000000 | 2015-11-12T00:00:00.000000 |
| certfr-2015-avi-476 | Vulnérabilité dans Microsoft Windows | 2015-11-12T00:00:00.000000 | 2015-11-12T00:00:00.000000 |
| certfr-2015-avi-475 | Multiples vulnérabilités dans Microsoft .NET Framework | 2015-11-12T00:00:00.000000 | 2015-11-12T00:00:00.000000 |