Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2019-25620 | 6.9 (v4.0) 6.2 (v3.1) | Tree Studio 2.17 Denial of Service via Malformed Input |
Pixarra |
Tree Studio |
2026-03-23T13:48:36.653Z | 2026-03-23T14:59:29.120Z |
| cve-2026-33297 | AVideo has an IDOR - Any Admin Can Set Another User's … |
WWBN |
AVideo |
2026-03-23T13:46:17.063Z | 2026-03-23T15:58:43.619Z | |
| cve-2026-4647 | 6.1 (v3.1) | Binutils: out-of-bounds read in xcoff relocation proce… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-03-23T13:37:44.413Z | 2026-04-09T16:33:30.743Z |
| cve-2026-4645 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': 'Duplicate of CVE-2026-32287'}], 'providerMetadata': {'orgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'shortName': 'redhat', 'dateUpdated': '2026-03-30T08:01:39.710Z'}} | N/A | N/A | 2026-03-23T13:35:22.985Z | 2026-03-30T08:01:39.710Z |
| cve-2026-4589 | kalcaddle kodbox fileGet Endpoint editor.class.php Pat… |
kalcaddle |
kodbox |
2026-03-23T13:32:42.266Z | 2026-04-18T03:36:21.562Z | |
| cve-2025-41008 | 9.3 (v4.0) | SQL Injection in Sinturno |
Sinturno |
Sinturno |
2026-03-23T12:59:02.417Z | 2026-03-23T13:46:46.627Z |
| cve-2026-4588 | kalcaddle kodbox Site-level API key shareOut.class.php… |
kalcaddle |
kodbox |
2026-03-23T12:46:51.056Z | 2026-03-25T14:06:30.268Z | |
| cve-2026-4587 | HybridAuth SSL Curl.php certificate validation |
n/a |
HybridAuth |
2026-03-23T12:46:46.054Z | 2026-03-23T13:46:08.559Z | |
| cve-2026-1958 | 8.7 (v4.0) | Hard-coded passwords in KlinikaXP |
BRI |
KlinikaXP Insertino |
2026-03-23T12:40:12.895Z | 2026-03-23T15:51:31.644Z |
| cve-2026-31851 | 7.7 (v4.0) | Lack of Rate Limiting Enables Brute-Force Attacks in N… |
Nexxt Solutions |
Nebula 300+ |
2026-03-23T12:21:54.907Z | 2026-03-26T10:47:04.841Z |
| cve-2026-31850 | 6.8 (v4.0) | Plaintext Storage of Credentials in Configuration Back… |
Nexxt Solutions |
Nebula 300+ |
2026-03-23T12:21:41.917Z | 2026-03-26T10:46:21.810Z |
| cve-2026-31849 | 7.2 (v4.0) | Missing CSRF Protection on Administrative Endpoints in… |
Nexxt Solutions |
Nebula 300+ |
2026-03-23T12:16:59.624Z | 2026-03-26T10:45:40.996Z |
| cve-2026-31848 | 8.7 (v4.0) | Reversible ecos_pw Cookie Allows Authentication Bypass… |
Nexxt Solutions |
Nebula 300+ |
2026-03-23T12:09:30.338Z | 2026-03-26T10:45:19.121Z |
| cve-2026-4586 | CodePhiliaX Chat2DB JDBC Driver Upload JdbcDriverContr… |
CodePhiliaX |
Chat2DB |
2026-03-23T12:08:23.956Z | 2026-03-23T16:00:39.682Z | |
| cve-2025-41007 | 9.3 (v4.0) | SQL Injection in Cuantis |
Cuantis |
Cuantis |
2026-03-23T12:08:17.388Z | 2026-03-23T15:52:09.342Z |
| cve-2026-31847 | 8.5 (v4.0) | Hidden Functionality Enables Remote Telnet Activation … |
Nexxt Solutions |
Nebula 300+ |
2026-03-23T12:07:05.062Z | 2026-03-26T10:52:50.115Z |
| cve-2026-31846 | 7.1 (v4.0) 6.5 (v3.1) 6.1 (v2.0) | Unauthenticated Credential Disclosure via /goform/ate … |
Nexxt Solutions |
Nebula 300+ / Tenda F3 V2.0 Firmware |
2026-03-23T12:00:42.158Z | 2026-03-26T10:44:33.160Z |
| cve-2026-32969 | 7.5 (v3.1) | Pre-Auth Blind SQLi in userinfo Endpoint |
MB connect line |
MB connect line mbCONNECT24 |
2026-03-23T11:16:22.255Z | 2026-03-23T16:01:30.953Z |
| cve-2026-32968 | 9.8 (v3.1) | Unauthenticated RCE in com_mb24sysapi |
MB connect line |
MB connect line mbCONNECT24 |
2026-03-23T11:16:01.413Z | 2026-03-23T13:51:18.931Z |
| cve-2026-4585 | Tiandy Easy7 Integrated Management Platform Configurat… |
Tiandy |
Easy7 Integrated Management Platform |
2026-03-23T11:15:06.466Z | 2026-03-23T16:38:26.005Z | |
| cve-2026-4584 | Shenzhen HCC Technology MPOS M6 PLUS Cardholder Data c… |
Shenzhen HCC Technology |
MPOS M6 PLUS |
2026-03-23T11:14:52.147Z | 2026-03-23T13:52:24.305Z | |
| cve-2026-4633 | 3.7 (v3.1) | Keycloak: keycloak: user enumeration via differential … |
Red Hat |
Red Hat Build of Keycloak |
2026-03-23T10:53:35.655Z | 2026-04-01T14:38:10.321Z |
| cve-2026-4583 | Shenzhen HCC Technology MPOS M6 PLUS Bluetooth authent… |
Shenzhen HCC Technology |
MPOS M6 PLUS |
2026-03-23T10:31:32.192Z | 2026-03-25T14:04:39.752Z | |
| cve-2026-28809 | 6.3 (v4.0) | XXE in esaml SAML library allows local file read and p… |
dropbox |
esaml |
2026-03-23T10:09:29.233Z | 2026-04-07T14:38:07.406Z |
| cve-2026-4582 | Shenzhen HCC Technology MPOS M6 PLUS Bluetooth missing… |
Shenzhen HCC Technology |
MPOS M6 PLUS |
2026-03-23T09:33:21.271Z | 2026-04-18T03:37:10.133Z | |
| cve-2026-4581 | code-projects Simple Laundry System Parameters checklo… |
code-projects |
Simple Laundry System |
2026-03-23T09:33:18.596Z | 2026-04-18T03:37:53.025Z | |
| cve-2026-4580 | code-projects Simple Laundry System Parameters checkup… |
code-projects |
Simple Laundry System |
2026-03-23T08:48:35.672Z | 2026-03-23T16:38:39.630Z | |
| cve-2026-4628 | 4.3 (v3.1) | Keycloak: org.keycloak.authorization: keycloak: unauth… |
Red Hat |
Red Hat Build of Keycloak |
2026-03-23T08:09:22.123Z | 2026-03-25T14:03:04.463Z |
| cve-2026-3587 | 10 (v3.1) | Hidden CLI Function Allows Root Access |
WAGO |
Lean Managed Switch 852-1812 |
2026-03-23T07:49:17.325Z | 2026-03-24T07:38:36.602Z |
| cve-2026-4579 | code-projects Simple Laundry System Parameters viewdet… |
code-projects |
Simple Laundry System |
2026-03-23T07:36:28.260Z | 2026-03-23T13:54:29.710Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2014-avi-301 | Vulnérabilité dans Microsoft Windows | 2014-07-09T00:00:00.000000 | 2014-07-09T00:00:00.000000 |
| certfr-2014-avi-300 | Multiples vulnérabilités dans Microsoft Internet Explorer | 2014-07-09T00:00:00.000000 | 2014-07-09T00:00:00.000000 |
| certfr-2014-avi-299 | Vulnérabilité dans les produits Huawei | 2014-07-08T00:00:00.000000 | 2014-07-08T00:00:00.000000 |
| certfr-2014-avi-298 | Vulnérabilité dans le noyau Linux d'Ubuntu | 2014-07-07T00:00:00.000000 | 2014-07-07T00:00:00.000000 |
| certfr-2014-avi-297 | Multiples vulnérabilités dans Xen | 2014-07-04T00:00:00.000000 | 2014-07-04T00:00:00.000000 |
| certfr-2014-avi-296 | Multiples vulnérabilités dans PHP | 2014-07-04T00:00:00.000000 | 2014-07-04T00:00:00.000000 |
| certfr-2014-avi-295 | Multiples vulnérabilités dans Cisco Unified Communications Domain Manager | 2014-07-03T00:00:00.000000 | 2014-07-03T00:00:00.000000 |
| certfr-2014-avi-294 | Multiples vulnérabilités dans les produits EMC | 2014-07-01T00:00:00.000000 | 2014-07-01T00:00:00.000000 |
| certfr-2014-avi-293 | Multiples vulnérabilités dans les produits Apple | 2014-07-01T00:00:00.000000 | 2014-07-01T00:00:00.000000 |
| certfr-2014-avi-292 | Vulnérabilité dans RealNetworks RealPlayer | 2014-07-01T00:00:00.000000 | 2014-07-01T00:00:00.000000 |
| certfr-2014-avi-291 | Vulnérabilité dans les produits F5 | 2014-06-30T00:00:00.000000 | 2014-06-30T00:00:00.000000 |
| certfr-2014-avi-290 | Multiples vulnérabilités dans les produits Huawei | 2014-06-30T00:00:00.000000 | 2014-06-30T00:00:00.000000 |
| certfr-2014-avi-289 | Multiples vulnérabilités dans Asterisk | 2014-06-30T00:00:00.000000 | 2014-06-30T00:00:00.000000 |
| certfr-2014-avi-288 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2014-06-30T00:00:00.000000 | 2014-06-30T00:00:00.000000 |
| certfr-2014-avi-287 | Multiples vulnérabilités dans Samba | 2014-06-30T00:00:00.000000 | 2014-06-30T00:00:00.000000 |
| certfr-2014-avi-286 | Multiples vulnérabilités dans Solaris | 2014-06-30T00:00:00.000000 | 2014-06-30T00:00:00.000000 |
| certfr-2014-avi-285 | Vulnérabilité dans Wireshark | 2014-06-30T00:00:00.000000 | 2014-06-30T00:00:00.000000 |
| certfr-2014-avi-284 | Vulnérabilité dans Red Hat JBoss Web Framework Kit | 2014-06-27T00:00:00.000000 | 2014-06-27T00:00:00.000000 |
| certfr-2014-avi-283 | Vulnérabilité dans le noyau Linux de SUSE | 2014-06-26T00:00:00.000000 | 2014-06-26T00:00:00.000000 |
| certfr-2014-avi-282 | Multiples vulnérabilités dans VMware vCenter Operations Management Suite | 2014-06-25T00:00:00.000000 | 2014-06-25T00:00:00.000000 |
| certfr-2014-avi-281 | Multiples vulnérabilités dans phpMyAdmin | 2014-06-23T00:00:00.000000 | 2014-06-23T00:00:00.000000 |
| certfr-2014-avi-280 | Vulnérabilité dans Huawei eSap Platform | 2014-06-20T00:00:00.000000 | 2014-06-20T00:00:00.000000 |
| certfr-2014-avi-279 | Multiples vulnérabilités dans Juniper Junos OS | 2014-06-20T00:00:00.000000 | 2014-06-20T00:00:00.000000 |
| certfr-2014-avi-278 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2014-06-20T00:00:00.000000 | 2014-06-20T00:00:00.000000 |
| certfr-2014-avi-277 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2014-06-20T00:00:00.000000 | 2014-06-20T00:00:00.000000 |
| certfr-2014-avi-276 | Multiples vulnérabilités dans Xen | 2014-06-19T00:00:00.000000 | 2014-06-19T00:00:00.000000 |
| certfr-2014-avi-275 | Vulnérabilité dans F5 BIG-IP | 2014-06-18T00:00:00.000000 | 2014-06-18T00:00:00.000000 |
| certfr-2014-avi-274 | Multiples vulnérabilités dans les produits VMware | 2014-06-16T00:00:00.000000 | 2014-06-16T00:00:00.000000 |
| certfr-2014-avi-273 | Multiples vulnérabilités dans Puppet | 2014-06-13T00:00:00.000000 | 2014-06-13T00:00:00.000000 |
| certfr-2014-avi-272 | Vulnérabilité dans Cisco IOS XR | 2014-06-13T00:00:00.000000 | 2014-06-13T00:00:00.000000 |