Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-77438 | Trilium unauthenticated share-search discloses passwor… |
TriliumNext |
Trilium |
2026-08-27T19:52:55.731Z | 2026-08-28T15:35:12.098Z | |
| cve-2026-53580 | Trilium arbitrary file read and denial of service via … |
TriliumNext |
Trilium |
2026-08-27T19:46:12.357Z | 2026-08-28T14:55:56.996Z | |
| cve-2026-81833 | RooCodeInc Roo-Code CodeIndexManager helpers.ts optimi… |
RooCodeInc |
Roo-Code |
2026-08-27T19:45:10.936Z | 2026-08-27T19:45:10.936Z | |
| cve-2026-81934 | Redis TLS pending-data list use-after-free |
Redis |
Redis |
2026-08-27T19:40:15.141Z | 2026-08-28T15:14:13.092Z | |
| cve-2026-10036 | 8.7 (v4.0) 8.8 (v3.1) | SpeechBrain < 1.1.1 Arbitrary Code Execution via CKPT.… |
speechbrain |
speechbrain |
2026-08-27T19:36:57.357Z | 2026-08-29T11:47:29.345Z |
| cve-2026-81931 | 4.8 (v4.0) | Unrestricted upload of file with dangerous type in Pro… |
Roskus |
Prospero Flow CRM |
2026-08-27T19:33:27.288Z | 2026-08-28T15:36:24.352Z |
| cve-2026-53579 | Trilium: Note Import to RCE via Book Note |
TriliumNext |
Trilium |
2026-08-27T19:33:24.490Z | 2026-08-28T15:58:18.142Z | |
| cve-2026-53578 | Trilium: Note Import to RCE via Mind Elixir dangerousl… |
TriliumNext |
Trilium |
2026-08-27T19:21:21.331Z | 2026-08-27T19:21:21.331Z | |
| cve-2026-18374 | 4.9 (v3.1) | Passing an effectively empty string to the `,ccs=… |
The GNU C Library |
glibc |
2026-08-27T19:20:40.426Z | 2026-08-28T15:37:10.821Z |
| cve-2026-74820 | 10 (v4.0) | Unauthenticated SQL Injection via Dynamic Schema ORDER… |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T19:05:04.612Z | 2026-08-29T03:56:10.853Z |
| cve-2026-18886 | 10 (v4.0) | Unauthenticated Privilege Escalation via System Config… |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T19:00:01.715Z | 2026-08-29T03:56:09.659Z |
| cve-2026-18885 | 10 (v4.0) | Unauthenticated Remote Code Execution in GraphQL Compo… |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T18:54:14.827Z | 2026-08-29T03:56:08.287Z |
| cve-2026-6876 | 8.7 (v4.0) | Sandbox Escape in Now Platform |
ServiceNow |
ServiceNow AI Platform |
2026-08-27T18:46:04.798Z | 2026-08-31T15:36:54.164Z |
| cve-2026-81893 | 4.7 (v3.1) | Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc prof… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-08-27T18:34:03.016Z | 2026-08-28T14:29:06.460Z |
| cve-2026-34616 | 5.5 (v3.1) | DNG SDK | Out-of-bounds Read (CWE-125) |
Adobe |
Adobe DNG Software Development Kit (SDK) |
2026-08-27T18:33:58.874Z | 2026-08-28T15:42:40.150Z |
| cve-2026-34620 | 5.5 (v3.1) | DNG SDK | Out-of-bounds Write (CWE-787) |
Adobe |
Adobe DNG Software Development Kit (SDK) |
2026-08-27T18:33:58.189Z | 2026-08-27T22:15:57.269Z |
| cve-2026-81530 | 6.8 (v4.0) 5.6 (v3.1) | KMS master key exposure via unredacted credential seri… |
MongoDB |
C# Driver |
2026-08-27T18:32:32.877Z | 2026-08-28T15:44:10.176Z |
| cve-2026-81529 | 7.1 (v4.0) 7.1 (v3.1) | Connection-option injection via unescaped settings in … |
MongoDB |
C# Driver |
2026-08-27T18:32:31.650Z | 2026-08-28T16:37:37.138Z |
| cve-2026-81528 | 5.3 (v4.0) 5.4 (v3.1) | NoSQL injection via array replacement bypassing update… |
MongoDB |
C# Driver |
2026-08-27T18:32:30.215Z | 2026-08-28T15:45:22.840Z |
| cve-2026-81527 | 6.9 (v4.0) 6.5 (v3.1) | NoSQL injection via unquoted constant GroupBy keys in … |
MongoDB |
C# Driver |
2026-08-27T18:32:28.926Z | 2026-08-28T15:46:55.682Z |
| cve-2026-81526 | 7.1 (v4.0) 6.5 (v3.1) | Cross-database write redirection via unvalidated dotte… |
MongoDB |
Rust Driver |
2026-08-27T18:32:27.704Z | 2026-08-28T15:48:02.435Z |
| cve-2026-81525 | 8.6 (v4.0) 8.1 (v3.1) | Cross-tenant database retargeting via dot/NUL injectio… |
MongoDB |
PHP Library |
2026-08-27T18:32:26.493Z | 2026-08-28T15:49:03.964Z |
| cve-2026-81524 | 5.3 (v4.0) 5.4 (v3.1) | Cross-tenant database retargeting via dot/NUL injectio… |
MongoDB |
C Driver |
2026-08-27T18:32:25.355Z | 2026-08-28T15:50:10.011Z |
| cve-2026-81523 | 2 (v4.0) 4.4 (v3.1) | Cross-tenant database retargeting via dot/NUL injectio… |
MongoDB |
libmongocrypt |
2026-08-27T18:32:24.206Z | 2026-08-28T15:51:12.001Z |
| cve-2026-81522 | 8.6 (v4.0) 8.1 (v3.1) | Cross-tenant database retargeting via dot/NUL injectio… |
MongoDB |
C++ Driver |
2026-08-27T18:32:23.151Z | 2026-08-29T03:55:54.810Z |
| cve-2026-81521 | 7.1 (v4.0) 6.5 (v3.1) | Cross-database write retargeting via unvalidated dotte… |
MongoDB |
GO Driver |
2026-08-27T18:31:45.450Z | 2026-08-28T15:52:13.039Z |
| cve-2026-59324 | 8.2 (v3.1) | fluxTransform shared RequestMessageHolder causes cross… |
Spring |
Spring Integration |
2026-08-27T18:04:51.595Z | 2026-08-28T22:46:33.636Z |
| cve-2026-59322 | 6.3 (v3.1) | EmbeddedHeadersJsonMessageMapper default gives wire pe… |
Spring |
Spring Integration |
2026-08-27T18:04:50.137Z | 2026-08-28T22:46:40.016Z |
| cve-2026-59321 | 4.2 (v3.1) | Shared JSR-223 ScriptEngine evaluated concurrently wit… |
Spring |
Spring Integration |
2026-08-27T18:04:49.035Z | 2026-08-28T22:46:47.321Z |
| cve-2026-59320 | 6.5 (v3.1) | In Spring AMQP the link credit never replenished on li… |
Spring |
Spring AMQP |
2026-08-27T18:04:47.999Z | 2026-08-28T22:46:54.662Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2021-000103 | WordPress Plugin "Push Notifications for WordPress (Lite)" vulnerable to cross-site request forgery | 2021-11-16T13:42+09:00 | 2021-11-16T13:42+09:00 |
| jvndb-2021-000102 | rwtxt vulnerable to cross-site scripting | 2021-11-16T13:38+09:00 | 2021-11-16T13:38+09:00 |
| jvndb-2021-000101 | Unlimited Sitemap Generator vulnerable to cross-site request forgery | 2021-11-12T15:07+09:00 | 2021-11-12T15:07+09:00 |
| jvndb-2021-003840 | Cross-site Scripting Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2021-11-12T11:41+09:00 | 2021-11-12T11:41+09:00 |
| jvndb-2021-000100 | Multiple vulnerabilities in EC-CUBE 2 series | 2021-11-11T15:09+09:00 | 2021-11-11T15:09+09:00 |
| jvndb-2021-000094 | WordPress Plugin "Booking Package - Appointment Booking Calendar System" vulnerable to cross-site scripting | 2021-11-10T14:26+09:00 | 2021-11-10T14:26+09:00 |
| jvndb-2021-003811 | File Permission Vulnerability in Hitachi Automation Director, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center | 2021-11-05T15:04+09:00 | 2021-11-05T15:04+09:00 |
| jvndb-2021-003660 | Authentication Bypass Vulnerability in Hitachi Device Manager | 2021-11-01T15:56+09:00 | 2021-11-01T15:56+09:00 |
| jvndb-2021-000097 | Multiple vulnerabilities in CLUSTERPRO X and EXPRESSCLUSTER X | 2021-10-29T15:22+09:00 | 2022-04-20T14:03+09:00 |
| jvndb-2021-000096 | Android App "Mercari (Merpay) - Marketplace and Mobile Payments App" (Japan version) vulnerable to improper handling of Intent | 2021-10-29T15:11+09:00 | 2021-10-29T15:11+09:00 |
| jvndb-2021-000098 | ESET Cyber Security and ESET Endpoint series vulnerable to denial-of-service (DoS) | 2021-10-29T14:58+09:00 | 2021-10-29T14:58+09:00 |
| jvndb-2021-000095 | Multiple improper restriction of XML external entity reference (XXE) vulnerabilities in Office Server Document Converter | 2021-10-28T15:03+09:00 | 2021-10-28T15:03+09:00 |
| jvndb-2021-003385 | Trend Micro Endpoint security products for enterprises vulnerable to privilege escalation | 2021-10-26T12:35+09:00 | 2021-10-26T12:35+09:00 |
| jvndb-2021-000093 | Movable Type XMLRPC API vulnerable to OS command injection | 2021-10-20T17:38+09:00 | 2021-12-17T17:36+09:00 |
| jvndb-2021-003080 | OMRON CX-Supervisor vulnerable to out-of-bounds read | 2021-10-18T15:26+09:00 | 2021-11-01T15:37+09:00 |
| jvndb-2021-000091 | 128 Technology Session Smart Router vulnerable to authentication bypass | 2021-10-18T14:58+09:00 | 2021-10-18T14:58+09:00 |
| jvndb-2021-000090 | Apache HTTP Server vulnerable to directory traversal | 2021-10-11T18:07+09:00 | 2021-10-11T18:07+09:00 |
| jvndb-2021-000089 | Nike App fails to restrict custom URL schemes properly | 2021-10-08T14:32+09:00 | 2021-10-08T14:32+09:00 |
| jvndb-2021-002810 | Information Disclosure Vulnerability in Hitachi Tuning Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2021-10-05T15:37+09:00 | 2021-10-05T15:37+09:00 |
| jvndb-2021-002774 | Trend Micro ServerProtect family vulnerable to authentication bypass | 2021-10-01T14:42+09:00 | 2021-10-01T14:42+09:00 |
| jvndb-2021-000088 | Multiple vulnerabilities in Cybozu Remote Service | 2021-09-30T16:03+09:00 | 2024-04-08T18:09+09:00 |
| jvndb-2021-002752 | Trend Micro HouseCall for Home Networks vulnerable to privilege escalation | 2021-09-30T13:56+09:00 | 2021-09-30T13:56+09:00 |
| jvndb-2021-000085 | SNKRDUNK Market Place App for iOS vulnerable to improper server certificate verification | 2021-09-28T15:18+09:00 | 2021-09-28T15:18+09:00 |
| jvndb-2021-000086 | WordPress Plugin "OG Tags" vulnerable to cross-site request forgery | 2021-09-28T15:11+09:00 | 2021-09-28T15:11+09:00 |
| jvndb-2021-000084 | InBody App vulnerable to information disclosure | 2021-09-28T14:27+09:00 | 2021-09-28T14:27+09:00 |
| jvndb-2021-000081 | Multiple vulnerabilities in Sharp NEC Display Solutions' public displays | 2021-09-17T15:13+09:00 | 2025-12-10T10:24+09:00 |
| jvndb-2021-000083 | EC-CUBE plugin "Order Status Batch Change Plug-in" vulnerable to cross-site scripting | 2021-09-16T14:33+09:00 | 2021-09-16T14:33+09:00 |
| jvndb-2021-000082 | EC-CUBE plugin "List (order management) item change plug-in" vulnerable to cross-site scripting | 2021-09-13T14:24+09:00 | 2021-09-13T14:24+09:00 |
| jvndb-2021-000074 | Multiple vulnerabilities in RevoWorks Browser | 2021-09-10T15:44+09:00 | 2021-09-10T15:44+09:00 |
| jvndb-2021-002342 | Trend Micro Security family vulnerable to improper handling of Directory Junction | 2021-09-03T16:10+09:00 | 2021-09-03T16:10+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2026-avi-0135 | Vulnérabilité dans GitLab AI Gateway | 2026-02-09T00:00:00.000000 | 2026-02-09T00:00:00.000000 |
| certfr-2026-avi-0134 | Vulnérabilité dans Microsoft Edge | 2026-02-09T00:00:00.000000 | 2026-02-09T00:00:00.000000 |
| certfr-2026-avi-0133 | Multiples vulnérabilités dans Roundcube | 2026-02-09T00:00:00.000000 | 2026-03-27T00:00:00.000000 |
| certfr-2026-avi-0132 | Multiples vulnérabilités dans VMware Tanzu Greenplum | 2026-02-09T00:00:00.000000 | 2026-02-09T00:00:00.000000 |
| certfr-2026-avi-0131 | Multiples vulnérabilités dans les produits IBM | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0130 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0129 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0128 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0127 | Vulnérabilité dans NetApp ONTAP 9 | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0126 | Vulnérabilité dans ESET Management Agent | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0125 | Multiples vulnérabilités dans les produits Moxa | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0124 | Multiples vulnérabilités dans Microsoft Edge | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0123 | Multiples vulnérabilités dans Asterisk | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0122 | Multiples vulnérabilités dans Tenable Nessus | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0121 | Vulnérabilité dans les produits Juniper Networks | 2026-02-06T00:00:00.000000 | 2026-02-06T00:00:00.000000 |
| certfr-2026-avi-0120 | Multiples vulnérabilités dans les produits F5 | 2026-02-05T00:00:00.000000 | 2026-02-05T00:00:00.000000 |
| certfr-2026-avi-0119 | Multiples vulnérabilités dans les produits Cisco | 2026-02-05T00:00:00.000000 | 2026-02-05T00:00:00.000000 |
| certfr-2026-avi-0118 | Multiples vulnérabilités dans les produits Splunk | 2026-02-05T00:00:00.000000 | 2026-02-05T00:00:00.000000 |
| certfr-2026-avi-0117 | Multiples vulnérabilités dans GLPI | 2026-02-04T00:00:00.000000 | 2026-02-04T00:00:00.000000 |
| certfr-2026-avi-0116 | Vulnérabilité dans les produits Moxa | 2026-02-04T00:00:00.000000 | 2026-02-04T00:00:00.000000 |
| certfr-2026-avi-0115 | Multiples vulnérabilités dans Tenable Identity Exposure | 2026-02-04T00:00:00.000000 | 2026-02-04T00:00:00.000000 |
| certfr-2026-avi-0114 | Multiples vulnérabilités dans Google Chrome | 2026-02-04T00:00:00.000000 | 2026-02-04T00:00:00.000000 |
| certfr-2026-avi-0113 | Vulnérabilité dans Google Pixel | 2026-02-04T00:00:00.000000 | 2026-02-04T00:00:00.000000 |
| certfr-2026-avi-0112 | Multiples vulnérabilités dans les produits VMware | 2026-02-02T00:00:00.000000 | 2026-02-02T00:00:00.000000 |
| certfr-2026-avi-0111 | Vulnérabilité dans ESET Inspect Connector | 2026-02-02T00:00:00.000000 | 2026-02-02T00:00:00.000000 |
| certfr-2026-avi-0110 | Multiples vulnérabilités Ivanti Endpoint Manager Mobile (EPMM) | 2026-01-30T00:00:00.000000 | 2026-01-30T00:00:00.000000 |
| certfr-2026-avi-0109 | Multiples vulnérabilités dans les produits IBM | 2026-01-30T00:00:00.000000 | 2026-01-30T00:00:00.000000 |
| certfr-2026-avi-0108 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-01-30T00:00:00.000000 | 2026-01-30T00:00:00.000000 |
| certfr-2026-avi-0107 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2026-01-30T00:00:00.000000 | 2026-01-30T00:00:00.000000 |
| certfr-2026-avi-0106 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2026-01-30T00:00:00.000000 | 2026-01-30T00:00:00.000000 |