Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-59282 | N/A | Spring Framework Denial of Service via Unbounded List … |
Spring |
Spring Framework |
2026-08-27T17:57:38.575Z | 2026-08-28T18:30:40.789Z |
| cve-2026-59281 | N/A | Spring Framework Cross-site Scripting via EscapedErrors |
Spring |
Spring Framework |
2026-08-27T17:57:37.157Z | 2026-08-28T18:56:23.590Z |
| cve-2026-59277 | 3.7 (v3.1) | Spring Security InetAddressMatchers Incomplete Interna… |
Spring |
Spring Security |
2026-08-27T17:57:36.006Z | 2026-08-28T14:01:04.295Z |
| cve-2026-59276 | 5.9 (v3.1) | Timing Attack via Non-Constant-Time Comparison of Sens… |
Spring |
Spring Security |
2026-08-27T17:57:34.993Z | 2026-08-28T14:00:41.248Z |
| cve-2026-4398 | 5.4 (v3.1) | Authorization Bypass Through User-Controlled Key in GitLab |
GitLab |
GitLab |
2026-08-27T17:53:14.609Z | 2026-08-28T14:13:54.361Z |
| cve-2026-76640 | 7.7 (v4.0) 7.5 (v3.1) | Unitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisionin… |
Unitree Robotics |
G1 EDU |
2026-08-27T17:52:11.749Z | 2026-08-28T15:53:16.149Z |
| cve-2026-76639 | 8.7 (v4.0) 8.8 (v3.1) | Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridg… |
Unitree Robotics |
G1 EDU |
2026-08-27T17:51:46.346Z | 2026-08-31T18:56:06.235Z |
| cve-2026-65931 | 5.1 (v4.0) | LimeSurvey Community Edition 7.0.5 - Improper authoriz… |
LimeSurvey |
LimeSurvey |
2026-08-27T17:50:47.311Z | 2026-08-28T14:13:54.515Z |
| cve-2026-48996 | Trilium: Malicious import with GeoMap marker title XSS… |
TriliumNext |
Trilium |
2026-08-27T17:36:07.483Z | 2026-08-29T03:56:03.899Z | |
| cve-2026-75889 | CVE-2026-75889 CVE Record |
Grafana |
Alloy |
2026-08-27T17:22:22.328Z | 2026-08-28T16:55:05.074Z | |
| cve-2026-54732 | libreoffice-convert: path traversal / arbitrary file write |
elwerene |
libreoffice-convert |
2026-08-27T17:21:50.743Z | 2026-08-28T14:54:16.963Z | |
| cve-2026-54718 | Silverstripe Advanced Workflow: Remote code execution … |
silverstripe |
silverstripe-advancedworkflow |
2026-08-27T17:19:51.691Z | 2026-08-31T18:17:17.110Z | |
| cve-2026-55758 | CC: Tweaked: Incomplete fix for GHSA-5jh9-2h63-pw4q: R… |
cc-tweaked |
CC-Tweaked |
2026-08-27T17:11:00.307Z | 2026-08-28T18:04:09.124Z | |
| cve-2026-54687 | n8n-nodes-sqlite3: Path traversal via user-controlled … |
DangerBlack |
n8n-node-sqlite3 |
2026-08-27T17:06:40.278Z | 2026-08-28T18:05:12.764Z | |
| cve-2026-19092 | Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Arg… |
Unknown |
Tutor LMS |
2026-08-27T17:05:37.621Z | 2026-08-28T13:03:21.752Z | |
| cve-2026-54713 | CakePHP Queue: Incomplete Comparison in getUniqueId vu… |
cakephp |
queue |
2026-08-27T17:03:31.580Z | 2026-08-28T15:55:52.105Z | |
| cve-2026-25250 | 6 (v3.1) | EAZ EazyFix 12.9 allows a Security Feature Bypass… |
eazsolution |
EazyFix |
2026-08-27T16:55:27.336Z | 2026-08-28T14:11:20.298Z |
| cve-2026-54721 | Silverstripe UserForms: Remote code execution via user… |
silverstripe |
silverstripe-userforms |
2026-08-27T16:52:46.023Z | 2026-08-28T15:58:28.067Z | |
| cve-2026-47727 | Trilium: RCE via `shareTemplate` relation missing `isD… |
TriliumNext |
Trilium |
2026-08-27T16:51:35.090Z | 2026-08-29T03:56:00.591Z | |
| cve-2026-66353 | 5.3 (v4.0) | Doggo vulnerable to cross-site scripting via unescaped… |
woylie |
doggo |
2026-08-27T16:44:59.553Z | 2026-08-28T14:13:54.861Z |
| cve-2026-59280 | N/A | Spring Framework Path Traversal via Backslash in Sprin… |
Spring |
Spring Framework |
2026-08-27T16:41:09.664Z | 2026-08-27T17:42:15.735Z |
| cve-2026-59272 | 6.8 (v3.1) | Log4j2 AmqpAppender disables TLS hostname verification… |
Spring |
Spring AMQP |
2026-08-27T16:41:08.650Z | 2026-08-28T03:55:35.123Z |
| cve-2026-79720 | 6.8 (v4.0) | Reflected XSS in Netron versions <=9.1.2 on deskt… |
Netron |
Netron |
2026-08-27T16:40:09.913Z | 2026-08-27T18:49:38.838Z |
| cve-2026-79719 | 6.8 (v4.0) | Reflected XSS in Netron versions <=9.1.2 on deskt… |
Netron |
Netron |
2026-08-27T16:39:10.117Z | 2026-08-27T18:52:39.505Z |
| cve-2026-79718 | 6.8 (v4.0) | Reflected XSS in Netron versions <=9.1.2 on deskt… |
Netron |
Netron |
2026-08-27T16:37:25.817Z | 2026-08-27T18:53:05.315Z |
| cve-2026-19854 | CVE-2026-19854 CVE Record |
Grafana |
Clickhouse Datasource |
2026-08-27T16:35:17.652Z | 2026-08-27T17:44:26.203Z | |
| cve-2026-75871 | 8.2 (v3.1) | Server-Side Request Forgery (SSRF) in GitLab AI Gateway |
GitLab |
GitLab AI Gateway |
2026-08-27T16:33:55.451Z | 2026-08-27T18:58:34.704Z |
| cve-2026-19889 | 8.2 (v3.1) | Server-Side Request Forgery (SSRF) in GitLab AI Gateway |
GitLab |
GitLab AI Gateway |
2026-08-27T16:33:50.570Z | 2026-08-27T19:00:15.667Z |
| cve-2026-5680 | 7.5 (v3.1) | Undertow-core: undertow: denial of service via websock… |
Red Hat |
Red Hat build of Apache Camel for Spring Boot 4 |
2026-08-27T16:25:29.103Z | 2026-08-31T18:15:13.552Z |
| cve-2026-78002 | 7.5 (v3.1) | Rsyslog: rsyslog: denial of service via heap buffer ov… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-08-27T16:12:59.102Z | 2026-08-29T22:06:44.190Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2021-000015 | FileZen vulnerable to OS command injection | 2021-02-16T15:07+09:00 | 2021-03-05T17:31+09:00 |
| jvndb-2021-000014 | Calsos CSDJ fails to restrict access permissions | 2021-02-15T15:52+09:00 | 2021-02-15T15:52+09:00 |
| jvndb-2021-000013 | Wekan vulnerable to cross-site scripting | 2021-02-10T14:01+09:00 | 2021-02-10T14:01+09:00 |
| jvndb-2021-001022 | Cross-site Scripting Vulnerability in Hitachi Application Server Help | 2021-02-09T15:08+09:00 | 2021-02-09T15:08+09:00 |
| jvndb-2021-001021 | Improper access control vulnerability in JP1/IT Desktop Management 2 - Manager and JP1/NETM/Asset Information Manager | 2021-02-09T15:08+09:00 | 2021-02-09T15:08+09:00 |
| jvndb-2021-000012 | WordPress Plugin "Name Directory" vulnerable to cross-site request forgery | 2021-02-05T16:24+09:00 | 2021-02-05T16:24+09:00 |
| jvndb-2021-001017 | Trend Micro HouseCall for Home Networks (Windows Edition) may insecurely load Dynamic Link Libraries | 2021-02-04T15:42+09:00 | 2021-02-04T15:42+09:00 |
| jvndb-2021-000011 | Panasonic Video Insight VMS vulnerable to arbitrary code execution | 2021-02-04T15:39+09:00 | 2021-02-04T15:39+09:00 |
| jvndb-2021-001014 | Vulnerability in JP1/VERITAS | 2021-02-01T16:49+09:00 | 2021-02-01T16:49+09:00 |
| jvndb-2021-000007 | OS command injection vulnerability in multiple Infoscience Corporation log management tools | 2021-01-27T18:31+09:00 | 2022-07-26T15:53+09:00 |
| jvndb-2021-000009 | Android App "ELECOM File Manager" vulnerable to directory traversal | 2021-01-27T17:38+09:00 | 2021-01-27T17:38+09:00 |
| jvndb-2021-000008 | Multiple vulnerabilities in multiple ELECOM products | 2021-01-26T16:33+09:00 | 2021-01-26T16:33+09:00 |
| jvndb-2021-000010 | Multiple vulnerabilities in multiple LOGITEC products | 2021-01-26T16:26+09:00 | 2021-01-26T16:26+09:00 |
| jvndb-2021-001010 | TP-Link TL-WR841N V13 (JP) vulnerable to OS command injection | 2021-01-25T16:21+09:00 | 2021-01-25T16:21+09:00 |
| jvndb-2021-000006 | Multiple vulnerabilities in Aterm WF800HP, Aterm WG2600HP, and Aterm WG2600HP2 | 2021-01-22T17:55+09:00 | 2021-02-03T12:05+09:00 |
| jvndb-2021-000005 | GROWI vulnerable to cross-site scripting | 2021-01-19T14:05+09:00 | 2021-01-19T14:05+09:00 |
| jvndb-2021-000004 | Multiple vulnerabilities in acmailer | 2021-01-14T16:22+09:00 | 2021-01-14T16:22+09:00 |
| jvndb-2021-000003 | The installer of SKYSEA Client View may insecurely load Dynamic Link Libraries | 2021-01-12T15:53+09:00 | 2021-01-12T15:53+09:00 |
| jvndb-2021-000002 | Multiple NEC Products vulnerable to authentication bypass | 2021-01-04T17:24+09:00 | 2021-01-08T12:22+09:00 |
| jvndb-2021-000001 | Multiple vulnerabilities in UNIVERGE SV9500/SV8500 series | 2021-01-04T14:37+09:00 | 2021-01-04T14:37+09:00 |
| jvndb-2020-009965 | Cleartext Transmission of Sensitive Information Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2020-12-21T17:48+09:00 | 2020-12-21T17:48+09:00 |
| jvndb-2020-009964 | Improper certificate validation vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2020-12-21T17:48+09:00 | 2020-12-21T17:48+09:00 |
| jvndb-2020-010072 | Cross-site Scripting Vulnerability in Hitachi Command Suite | 2020-12-21T14:20+09:00 | 2020-12-21T14:20+09:00 |
| jvndb-2020-000087 | Management software for NEC Storage disk array system vulnerable to improper server certificate verification | 2020-12-18T17:00+09:00 | 2021-07-21T16:21+09:00 |
| jvndb-2020-000086 | Self-Extracting files created by multiple SEIKO EPSON products may insecurely load Dynamic Link Libraries | 2020-12-18T16:47+09:00 | 2020-12-18T16:47+09:00 |
| jvndb-2020-000085 | Multiple vulnerabilities in GROWI | 2020-12-15T15:41+09:00 | 2021-08-30T16:29+09:00 |
| jvndb-2020-000083 | Multiple vulnerabilities in Aterm SA3500G | 2020-12-11T16:59+09:00 | 2020-12-11T16:59+09:00 |
| jvndb-2020-000084 | Apache Struts 2 vulnerable to remote code execution (S2-061) | 2020-12-11T15:09+09:00 | 2022-08-09T13:55+09:00 |
| jvndb-2020-000082 | FileZen vulnerable to directory traversal | 2020-12-10T15:21+09:00 | 2020-12-10T15:21+09:00 |
| jvndb-2020-009771 | ServerProtect for Linux vulnerable to heap-based buffer overflow | 2020-12-08T12:34+09:00 | 2020-12-08T12:34+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2026-avi-0015 | Multiples vulnérabilités dans les produits Centreon | 2026-01-08T00:00:00.000000 | 2026-01-08T00:00:00.000000 |
| certfr-2026-avi-0014 | Multiples vulnérabilités dans GitLab | 2026-01-08T00:00:00.000000 | 2026-01-08T00:00:00.000000 |
| certfr-2026-avi-0013 | Vulnérabilité dans Tenable Nessus Agent | 2026-01-08T00:00:00.000000 | 2026-01-08T00:00:00.000000 |
| certfr-2026-avi-0012 | Multiples vulnérabilités dans Trend Micro Apex Central | 2026-01-08T00:00:00.000000 | 2026-01-08T00:00:00.000000 |
| certfr-2026-avi-0011 | Vulnérabilité dans Google Android | 2026-01-08T00:00:00.000000 | 2026-01-08T00:00:00.000000 |
| certfr-2026-avi-0010 | Multiples vulnérabilités dans Curl | 2026-01-07T00:00:00.000000 | 2026-01-07T00:00:00.000000 |
| certfr-2026-avi-0009 | Vulnérabilité dans Google Chrome | 2026-01-07T00:00:00.000000 | 2026-01-07T00:00:00.000000 |
| certfr-2026-avi-0008 | Multiples vulnérabilités dans Joomla! | 2026-01-07T00:00:00.000000 | 2026-01-07T00:00:00.000000 |
| certfr-2026-avi-0007 | Vulnérabilité dans Stormshield Network Security | 2026-01-06T00:00:00.000000 | 2026-01-06T00:00:00.000000 |
| certfr-2026-avi-0006 | Multiples vulnérabilités dans Veeam Backup & Replication | 2026-01-06T00:00:00.000000 | 2026-01-06T00:00:00.000000 |
| certfr-2026-avi-0005 | Multiples vulnérabilités dans Centreon Open Tickets | 2026-01-06T00:00:00.000000 | 2026-01-06T00:00:00.000000 |
| certfr-2026-avi-0004 | Vulnérabilité dans MariaDB | 2026-01-05T00:00:00.000000 | 2026-01-05T00:00:00.000000 |
| certfr-2026-avi-0003 | Multiples vulnérabilités dans les produits Qnap | 2026-01-05T00:00:00.000000 | 2026-01-05T00:00:00.000000 |
| certfr-2026-avi-0002 | Multiples vulnérabilités dans les produits IBM | 2026-01-02T00:00:00.000000 | 2026-01-02T00:00:00.000000 |
| certfr-2026-avi-0001 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2026-01-02T00:00:00.000000 | 2026-01-02T00:00:00.000000 |
| certfr-2025-avi-1142 | Multiples vulnérabilités dans Moxa NPort | 2025-12-31T00:00:00.000000 | 2025-12-31T00:00:00.000000 |
| certfr-2025-avi-1141 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-12-26T00:00:00.000000 | 2025-12-26T00:00:00.000000 |
| certfr-2025-avi-1140 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-12-26T00:00:00.000000 | 2025-12-26T00:00:00.000000 |
| certfr-2025-avi-1139 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-12-26T00:00:00.000000 | 2025-12-26T00:00:00.000000 |
| certfr-2025-avi-1138 | Multiples vulnérabilités dans VMware Tanzu Platform | 2025-12-26T00:00:00.000000 | 2025-12-26T00:00:00.000000 |
| certfr-2025-avi-1137 | Multiples vulnérabilités dans les produits IBM | 2025-12-26T00:00:00.000000 | 2025-12-26T00:00:00.000000 |
| certfr-2025-avi-1136 | Multiples vulnérabilités dans le noyau Linux de Debian LTS | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1135 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1134 | Multiples vulnérabilités dans MongoDB Server | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1133 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1132 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1131 | Multiples vulnérabilités dans les produits IBM | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1130 | Multiples vulnérabilités dans les produits Foxit | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1129 | Multiples vulnérabilités dans les produits VMware | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1128 | Multiples vulnérabilités dans Mozilla Firefox | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |