Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-33084 | DataEase has SQL Injection through its getFieldEnumObj… |
dataease |
dataease |
2026-04-16T18:14:07.316Z | 2026-04-18T02:40:47.771Z | |
| cve-2025-43937 | 6.6 (v3.1) | Dell PowerScale OneFS, versions prior to 9.12.0.0… |
Dell |
PowerScale OneFS |
2026-04-16T18:03:08.750Z | 2026-04-16T18:51:41.562Z |
| cve-2025-43935 | 4.4 (v3.1) | Dell PowerScale OneFS, versions prior to 9.12.0.0… |
Dell |
PowerScale OneFS |
2026-04-16T17:59:04.315Z | 2026-04-16T19:38:28.840Z |
| cve-2025-43883 | 4.1 (v3.1) | Dell PowerScale OneFS, versions prior to 9.12.0.0… |
Dell |
PowerScale OneFS |
2026-04-16T17:54:09.831Z | 2026-04-18T02:39:20.246Z |
| cve-2026-33083 | DataEase has SQL Injection in Order By Clause |
dataease |
dataease |
2026-04-16T17:52:37.255Z | 2026-04-16T19:39:25.443Z | |
| cve-2026-33082 | DataEase: SQL Injection in v2 Dataset Export |
dataease |
dataease |
2026-04-16T17:39:37.894Z | 2026-04-16T18:41:46.111Z | |
| cve-2026-41082 | 7.3 (v3.1) | In OCaml opam before 2.5.1, a .install field cont… |
OCaml |
opam |
2026-04-16T17:32:40.068Z | 2026-04-21T09:32:52.152Z |
| cve-2026-27820 | zlib: Buffer Overflow in Zlib::GzipReader ungetc via l… |
ruby |
zlib |
2026-04-16T17:27:48.944Z | 2026-04-16T18:20:21.451Z | |
| cve-2026-24749 | Silverstripe Assets Module has a DBFile::getURL() perm… |
silverstripe |
silverstripe-assets |
2026-04-16T17:08:59.133Z | 2026-04-18T02:36:26.887Z | |
| cve-2026-2336 | 8.7 (v4.0) | Weak webstax_auth Cookie Authentication Allows Privile… |
Microchip |
IStaX |
2026-04-16T17:02:06.352Z | 2026-04-16T17:34:39.672Z |
| cve-2026-41080 | 2.9 (v3.1) | libexpat before 2.7.6 uses insufficient entropy, … |
libexpat project |
libexpat |
2026-04-16T16:52:01.177Z | 2026-04-18T02:33:52.350Z |
| cve-2025-36579 | 5.1 (v3.1) | Dell Client Platform BIOS contains a Weak Passwor… |
Dell |
Dell Pro 14 Essential PV14250 |
2026-04-16T16:05:32.561Z | 2026-04-16T18:32:52.672Z |
| cve-2026-5426 | N/A | KnowledgeDeliver deployments before February 24, 2026 … |
Digital Knowledge |
KnowledgeDeliver |
2026-04-16T15:18:46.224Z | 2026-04-18T02:31:32.234Z |
| cve-2026-3324 | 8.2 (v3.1) | Authentication Bypass |
Zohocorp |
ManageEngine Log360 |
2026-04-16T14:30:55.130Z | 2026-04-16T15:21:19.911Z |
| cve-2026-6409 | 7.1 (v4.0) | Denial of Service (DoS) vulnerability exists in the Pr… |
Protocol Buffers |
Protobuf-php (Pecl) |
2026-04-16T14:30:51.568Z | 2026-04-16T15:24:43.164Z |
| cve-2026-2840 | Email Encoder – Protect Email Addresses and Phone Numb… |
onlineoptimisation |
Email Encoder – Protect Email Addresses and Phone Numbers |
2026-04-16T14:10:29.114Z | 2026-04-16T14:42:53.905Z | |
| cve-2026-33804 | 7.4 (v3.1) | @fastify/middie vulnerable to middleware bypass via de… |
@fastify/middie |
@fastify/middie |
2026-04-16T13:56:56.176Z | 2026-04-16T14:41:48.659Z |
| cve-2026-5785 | 8.1 (v3.1) | SQL Injection |
Zohocorp |
ManageEngine PAM360 |
2026-04-16T13:46:28.313Z | 2026-04-17T03:55:15.059Z |
| cve-2026-6270 | 9.1 (v3.1) | @fastify/middie vulnerable to middleware authenticatio… |
@fastify/middie |
@fastify/middie |
2026-04-16T13:44:46.322Z | 2026-04-16T14:24:26.764Z |
| cve-2026-31987 | Apache Airflow: JWT token appearing in logs |
Apache Software Foundation |
Apache Airflow |
2026-04-16T13:31:52.336Z | 2026-04-18T02:28:44.770Z | |
| cve-2026-6410 | 5.3 (v3.1) | @fastify/static vulnerable to path traversal in direct… |
@fastify/static |
@fastify/static |
2026-04-16T13:29:08.120Z | 2026-04-16T14:19:36.780Z |
| cve-2026-4160 | Fluent Forms – Customizable Contact Forms, Survey, Qui… |
techjewel |
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder |
2026-04-16T13:27:09.207Z | 2026-04-16T14:12:35.951Z | |
| cve-2026-6414 | 5.9 (v3.1) | @fastify/static vulnerable to route guard bypass via e… |
@fastify/static |
@fastify/static |
2026-04-16T13:09:03.526Z | 2026-04-16T13:48:52.393Z |
| cve-2026-31843 | 10 (v4.0) 9.8 (v3.1) 10 (v2.0) | The goodoneuz/pay-uz Laravel package (<= 2.2.24) … |
goodoneuz |
pay-uz |
2026-04-16T13:02:55.701Z | 2026-04-16T19:30:21.203Z |
| cve-2025-15621 | 5.7 (v4.0) | Sparx Enterprise Architect Client does not verify the … |
Sparx Systems Pty Ltd. |
Sparx Enterprise Architect |
2026-04-16T12:40:08.962Z | 2026-04-16T12:51:51.633Z |
| cve-2026-3155 | OneSignal – Web Push Notifications <= 3.8.0 - Missing … |
onesignal |
OneSignal – Web Push Notifications |
2026-04-16T11:21:22.226Z | 2026-04-16T14:00:56.681Z | |
| cve-2026-3369 | Better Find and Replace – AI-Powered Suggestions <= 1.… |
codesolz |
Better Find and Replace – AI-Powered Suggestions |
2026-04-16T11:21:21.822Z | 2026-04-16T14:04:23.811Z | |
| cve-2026-3489 | DirectoryPress – Business Directory And Classified Ad … |
designinvento |
DirectoryPress – Business Directory And Classified Ad Listing |
2026-04-16T11:21:21.179Z | 2026-04-16T14:05:03.740Z | |
| cve-2025-12624 | 6 (v3.1) | Improper Token Invalidation in WSO2 Identity Server Al… |
WSO2 |
WSO2 Identity Server |
2026-04-16T10:25:19.789Z | 2026-04-16T12:30:14.886Z |
| cve-2025-6024 | 6.1 (v3.1) | Cross-Site Scripting via Authentication Endpoint in Mu… |
WSO2 |
WSO2 API Manager |
2026-04-16T09:48:45.244Z | 2026-04-16T12:30:22.824Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2020-000033 | WordPress Plugin "Paid Memberships Pro" vulnerable to SQL injection | 2020-05-19T16:07+09:00 | 2020-05-19T16:07+09:00 |
| jvndb-2020-000032 | Panasonic Video Insight VMS vulnerable to arbitrary code execution | 2020-05-19T16:04+09:00 | 2020-06-26T12:19+09:00 |
| jvndb-2020-004476 | DoS Vulnerability in JP1/Automatic Job Management System 3 and JP1/Automatic Job Management System 2 | 2020-05-19T10:38+09:00 | 2020-05-19T10:38+09:00 |
| jvndb-2020-004477 | Multiple Vulnerabilities in Hitachi Compute Systems Manager | 2020-05-19T10:33+09:00 | 2020-05-19T10:33+09:00 |
| jvndb-2020-000031 | BookStack vulnerable to cross-site scripting | 2020-05-13T18:06+09:00 | 2020-05-13T18:06+09:00 |
| jvndb-2020-000030 | Multiple vulnerabilities in Movable Type | 2020-05-13T17:59+09:00 | 2020-05-13T17:59+09:00 |
| jvndb-2020-000029 | PALLET CONTROL vulnerable to arbitrary code execution | 2020-05-11T15:16+09:00 | 2020-05-11T15:16+09:00 |
| jvndb-2020-000028 | Sales Force Assistant vulnerable to cross-site scripting | 2020-04-28T15:49+09:00 | 2020-04-28T15:49+09:00 |
| jvndb-2020-000027 | Cybozu Garoon contains multiple vulnerabilities | 2020-04-28T14:48+09:00 | 2020-04-28T14:48+09:00 |
| jvndb-2020-003896 | Directory Permission Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2020-04-28T12:21+09:00 | 2020-04-28T12:21+09:00 |
| jvndb-2020-000026 | Multiple SHARP Android devices vulnerable to information disclosure | 2020-04-24T15:32+09:00 | 2020-04-24T15:32+09:00 |
| jvndb-2020-000025 | Toshiba Electronic Devices & Storage software registers unquoted service paths | 2020-04-20T17:13+09:00 | 2023-11-08T16:44+09:00 |
| jvndb-2020-000022 | Multiple vulnerabilities in EasyBlocks IPv6 | 2020-04-08T16:12+09:00 | 2020-04-08T16:12+09:00 |
| jvndb-2020-000024 | Joomla! plugin "AcyMailing" vulnerable to arbitrary file uploads | 2020-04-07T14:49+09:00 | 2020-04-07T14:49+09:00 |
| jvndb-2020-000021 | Multiple Yamaha network devices vulnerable to denial-of-service (DoS) | 2020-03-31T17:44+09:00 | 2020-04-01T18:38+09:00 |
| jvndb-2020-002958 | Denial-of-service (DoS) vulnerability in Mitsubishi Electric MELSOFT transmission port | 2020-03-31T13:37+09:00 | 2020-04-01T14:45+09:00 |
| jvndb-2020-000907 | WL-Enq (WEB Enquete) vulnerable to OS command injection | 2020-03-25T09:50+09:00 | 2020-03-25T09:50+09:00 |
| jvndb-2020-000906 | WL-Enq (WEB Enquete) vulnerable to cross-site scripting | 2020-03-24T18:29+09:00 | 2023-10-30T17:52+09:00 |
| jvndb-2020-000908 | Keijiban Tsumiki vulnerable to OS command injection | 2020-03-24T18:14+09:00 | 2020-03-24T18:14+09:00 |
| jvndb-2020-000900 | mailform vulnerable to cross-site scripting | 2020-03-24T18:05+09:00 | 2020-03-24T18:05+09:00 |
| jvndb-2020-000901 | mailform vulnerable to PHP code execution | 2020-03-24T17:59+09:00 | 2020-03-24T17:59+09:00 |
| jvndb-2020-000902 | Multiple vulnerabilities in Shihonkanri Plus GOOUT | 2020-03-24T17:53+09:00 | 2020-03-24T17:53+09:00 |
| jvndb-2020-000903 | Shihonkanri Plus GOOUT vulnerable to OS command injection | 2020-03-24T17:47+09:00 | 2020-03-24T17:47+09:00 |
| jvndb-2020-000904 | CuteNews vulnerable to cross-site scripting | 2020-03-24T17:42+09:00 | 2020-03-24T17:42+09:00 |
| jvndb-2020-000905 | Cute News vulnerable to PHP code execution | 2020-03-24T17:40+09:00 | 2020-03-24T17:40+09:00 |
| jvndb-2020-002278 | Cross-site Scripting Vulnerability in JP1/Performance Management - Manager [Web Console] | 2020-03-11T14:16+09:00 | 2020-03-11T14:16+09:00 |
| jvndb-2020-002219 | Multiple Vulnerabilities in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center | 2020-03-09T11:23+09:00 | 2020-03-09T11:23+09:00 |
| jvndb-2020-002220 | Improper LDAPS Certificate Validation in Hitachi Ops Center Common Services | 2020-03-09T11:21+09:00 | 2020-03-09T11:21+09:00 |
| jvndb-2020-000020 | Multiple vulnerabilities in OpenBlocks IoT VX2 | 2020-03-03T17:50+09:00 | 2020-03-03T17:50+09:00 |
| jvndb-2020-000019 | GRANDIT vulnerable to session management | 2020-03-02T14:39+09:00 | 2020-03-02T14:39+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0542 | Multiples vulnérabilités dans Microsoft Edge | 2025-06-27T00:00:00.000000 | 2025-06-27T00:00:00.000000 |
| certfr-2025-avi-0541 | Vulnérabilité dans Centreon Map | 2025-06-26T00:00:00.000000 | 2025-06-26T00:00:00.000000 |
| certfr-2025-avi-0540 | Multiples vulnérabilités dans les produits Citrix | 2025-06-26T00:00:00.000000 | 2025-06-26T00:00:00.000000 |
| certfr-2025-avi-0539 | Multiples vulnérabilités dans Cisco Identity Services Engine | 2025-06-26T00:00:00.000000 | 2025-08-01T00:00:00.000000 |
| certfr-2025-avi-0538 | Multiples vulnérabilités dans VMware Tanzu | 2025-06-26T00:00:00.000000 | 2025-06-26T00:00:00.000000 |
| certfr-2025-avi-0537 | Multiples vulnérabilités dans GitLab | 2025-06-25T00:00:00.000000 | 2025-06-25T00:00:00.000000 |
| certfr-2025-avi-0536 | Multiples vulnérabilités dans les produits Mozilla | 2025-06-25T00:00:00.000000 | 2025-06-25T00:00:00.000000 |
| certfr-2025-avi-0535 | Vulnérabilité dans VMware Tanzu | 2025-06-25T00:00:00.000000 | 2025-06-25T00:00:00.000000 |
| certfr-2025-avi-0534 | Multiples vulnérabilités dans Google Chrome | 2025-06-25T00:00:00.000000 | 2025-06-25T00:00:00.000000 |
| certfr-2025-avi-0533 | Multiples vulnérabilités dans Elastic Kibana | 2025-06-25T00:00:00.000000 | 2025-06-25T00:00:00.000000 |
| certfr-2025-avi-0532 | Multiples vulnérabilités dans les produits Splunk | 2025-06-24T00:00:00.000000 | 2025-06-24T00:00:00.000000 |
| certfr-2025-avi-0531 | Vulnérabilité dans Bitdefender SecurePass | 2025-06-23T00:00:00.000000 | 2025-06-23T00:00:00.000000 |
| certfr-2025-avi-0530 | Multiples vulnérabilités dans les produits IBM | 2025-06-20T00:00:00.000000 | 2025-06-20T00:00:00.000000 |
| certfr-2025-avi-0529 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-06-20T00:00:00.000000 | 2025-06-20T00:00:00.000000 |
| certfr-2025-avi-0528 | Multiples vulnérabilités dans les produits Citrix | 2025-06-20T00:00:00.000000 | 2025-06-20T00:00:00.000000 |
| certfr-2025-avi-0527 | Vulnérabilité dans les produits Microsoft | 2025-06-20T00:00:00.000000 | 2025-06-20T00:00:00.000000 |
| certfr-2025-avi-0526 | Multiples vulnérabilités dans Microsoft Edge | 2025-06-20T00:00:00.000000 | 2025-06-20T00:00:00.000000 |
| certfr-2025-avi-0525 | Multiples vulnérabilités dans Mattermost Server | 2025-06-19T00:00:00.000000 | 2025-08-19T00:00:00.000000 |
| certfr-2025-avi-0524 | Multiples vulnérabilités dans VMware Tanzu | 2025-06-19T00:00:00.000000 | 2025-06-19T00:00:00.000000 |
| certfr-2025-avi-0523 | Vulnérabilité dans Cisco Meraki MX | 2025-06-19T00:00:00.000000 | 2025-06-19T00:00:00.000000 |
| certfr-2025-avi-0522 | Multiples vulnérabilités dans ClamAV | 2025-06-19T00:00:00.000000 | 2025-06-19T00:00:00.000000 |
| certfr-2025-avi-0521 | Multiples vulnérabilités dans Synacor Zimbra Collaboration | 2025-06-18T00:00:00.000000 | 2025-06-18T00:00:00.000000 |
| certfr-2025-avi-0520 | Multiples vulnérabilités dans les produits Atlassian | 2025-06-18T00:00:00.000000 | 2025-06-18T00:00:00.000000 |
| certfr-2025-avi-0519 | Multiples vulnérabilités dans Moodle | 2025-06-18T00:00:00.000000 | 2025-06-18T00:00:00.000000 |
| certfr-2025-avi-0518 | Multiples vulnérabilités dans Google Chrome | 2025-06-18T00:00:00.000000 | 2025-06-18T00:00:00.000000 |
| certfr-2025-avi-0517 | Multiples vulnérabilités dans les produits Veeam | 2025-06-18T00:00:00.000000 | 2025-06-18T00:00:00.000000 |
| certfr-2025-avi-0516 | Multiples vulnérabilités dans Apache Tomcat | 2025-06-17T00:00:00.000000 | 2025-06-17T00:00:00.000000 |
| certfr-2025-avi-0515 | Vulnérabilité dans Grafana | 2025-06-16T00:00:00.000000 | 2025-06-16T00:00:00.000000 |
| certfr-2025-avi-0514 | Vulnérabilité dans PostgreSQL JDBC | 2025-06-16T00:00:00.000000 | 2025-06-16T00:00:00.000000 |
| certfr-2025-avi-0513 | Multiples vulnérabilités dans Microsoft Edge | 2025-06-16T00:00:00.000000 | 2025-06-16T00:00:00.000000 |