Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-48779 | ws: Memory exhaustion DoS from tiny fragments and data… |
websockets |
ws |
2026-06-16T21:26:22.537Z | 2026-08-31T12:04:25.658Z | |
| cve-2026-6893 | 7.5 (v3.1) | Dracut: dracut: root code execution via dhcp options c… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-06-10T19:49:27.553Z | 2026-08-31T12:04:25.494Z |
| cve-2026-33814 | N/A | Infinite loop in HTTP/2 transport when given bad SETTI… |
golang.org/x/net |
golang.org/x/net/http2 |
2026-05-07T19:41:17.631Z | 2026-08-31T12:04:25.088Z |
| cve-2026-27145 | N/A | Inefficient candidate hostname parsing in crypto/x509 |
Go standard library |
crypto/x509 |
2026-06-02T22:01:36.954Z | 2026-08-31T12:04:24.661Z |
| cve-2026-9697 | 7.4 (v3.1) | undici vulnerable to TLS certificate validation bypass… |
undici |
undici |
2026-06-17T16:46:42.706Z | 2026-08-31T12:04:24.619Z |
| cve-2026-33811 | N/A | Crash when handling long CNAME response in net |
Go standard library |
net |
2026-05-07T19:41:19.285Z | 2026-08-31T12:04:24.596Z |
| cve-2025-62718 | Axios has a NO_PROXY Hostname Normalization Bypass tha… |
axios |
axios |
2026-04-09T14:31:46.067Z | 2026-08-31T12:04:24.482Z | |
| cve-2026-39830 | N/A | Invoking client can cause server deadlock on unexpect… |
golang.org/x/crypto |
golang.org/x/crypto/ssh |
2026-05-22T02:31:27.208Z | 2026-08-31T12:04:23.906Z |
| cve-2026-22029 | React Router vulnerable to XSS via Open Redirects |
remix-run |
react-router |
2026-01-10T02:42:32.736Z | 2026-08-31T12:04:23.788Z | |
| cve-2026-13676 | 7.5 (v3.1) | fast-uri vulnerable to host confusion via failed IDN c… |
fast-uri |
fast-uri |
2026-06-29T13:22:44.674Z | 2026-08-31T12:04:23.672Z |
| cve-2026-33895 | Forge has signature forgery in Ed25519 due to missing … |
digitalbazaar |
forge |
2026-03-27T20:47:54.492Z | 2026-08-31T12:04:23.261Z | |
| cve-2024-52011 | launch-editor vulnerable to command injection via the … |
vitejs |
launch-editor |
2026-06-01T17:17:43.792Z | 2026-08-31T12:04:23.153Z | |
| cve-2026-29181 | OpenTelemetry-Go multi-value `baggage` header extracti… |
open-telemetry |
opentelemetry-go |
2026-04-07T20:29:13.933Z | 2026-08-31T12:04:23.133Z | |
| cve-2026-21441 | urllib3 vulnerable to decompression-bomb safeguard byp… |
urllib3 |
urllib3 |
2026-01-07T22:09:01.936Z | 2026-08-31T12:04:22.928Z | |
| cve-2026-39821 | N/A | Invoking failure to reject ASCII-only Punycode-encoded… |
Go standard library |
net/http |
2026-05-22T15:01:21.462Z | 2026-08-31T12:04:22.512Z |
| cve-2026-40895 | follow-redirects: Custom Authentication Headers Leaked… |
follow-redirects |
follow-redirects |
2026-04-21T19:59:59.759Z | 2026-08-31T12:04:22.397Z | |
| cve-2026-43329 | netfilter: flowtable: strictly check for maximum numbe… |
Linux |
Linux |
2026-05-08T13:31:17.479Z | 2026-08-31T12:04:21.783Z | |
| cve-2026-27459 | pyOpenSSL DTLS cookie callback buffer overflow |
pyca |
pyopenssl |
2026-03-17T23:34:28.483Z | 2026-08-31T12:04:21.760Z | |
| cve-2026-32285 | N/A | Denial of service in github.com/buger/jsonparser |
github.com/buger/jsonparser |
github.com/buger/jsonparser |
2026-03-26T19:40:51.837Z | 2026-08-31T12:04:21.511Z |
| cve-2026-33896 | Forge has a basicConstraints bypass in its certificate… |
digitalbazaar |
forge |
2026-03-27T20:50:03.418Z | 2026-08-31T12:04:21.429Z | |
| cve-2026-39832 | N/A | Invoking agent constraints dropped when forwarding ke… |
golang.org/x/crypto |
golang.org/x/crypto/ssh/agent |
2026-05-22T02:31:26.660Z | 2026-08-31T12:04:21.398Z |
| cve-2026-12143 | 8.7 (v4.0) 7.5 (v3.1) | form-data does not escape CR/LF/quote in multipart fie… |
form-data |
form-data |
2026-06-12T18:01:30.362Z | 2026-08-31T12:04:21.369Z |
| cve-2026-4800 | 8.1 (v3.1) | lodash vulnerable to Code Injection via `_.template` i… |
lodash |
lodash |
2026-03-31T19:25:55.987Z | 2026-08-31T12:04:21.104Z |
| cve-2025-10263 | N/A | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neo… |
Arm |
C1-Ultra |
2026-06-09T09:23:18.802Z | 2026-08-31T12:04:20.920Z |
| cve-2026-39835 | N/A | Invoking server panic during CheckHostKey/Authenticat… |
golang.org/x/crypto |
golang.org/x/crypto/ssh |
2026-05-22T02:31:26.982Z | 2026-08-31T12:04:20.785Z |
| cve-2026-34986 | Go JOSE affect by a panic in JWE decryption |
go-jose |
go-jose |
2026-04-06T16:22:45.353Z | 2026-08-31T12:04:20.402Z | |
| cve-2026-42499 | N/A | Quadratic string concatenation in consumePhrase in net/mail |
Go standard library |
net/mail |
2026-05-07T19:41:18.615Z | 2026-08-31T12:04:20.306Z |
| cve-2026-33810 | N/A | Case-sensitive excludedSubtrees name constraints cause… |
Go standard library |
crypto/x509 |
2026-04-08T01:06:56.546Z | 2026-08-31T12:04:20.113Z |
| cve-2026-44605 | 5.5 (v3.1) | Rpm: heap buffer overflow in ndb slot table parsing |
Red Hat |
Red Hat Hardened Images |
2026-08-05T17:29:27.189Z | 2026-08-31T12:00:37.226Z |
| cve-2025-31104 | 7 (v3.1) | A improper neutralization of special elements use… |
Fortinet |
FortiADC |
2025-06-10T16:36:13.131Z | 2026-08-31T11:58:00.084Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2021-000012 | WordPress Plugin "Name Directory" vulnerable to cross-site request forgery | 2021-02-05T16:24+09:00 | 2021-02-05T16:24+09:00 |
| jvndb-2021-001017 | Trend Micro HouseCall for Home Networks (Windows Edition) may insecurely load Dynamic Link Libraries | 2021-02-04T15:42+09:00 | 2021-02-04T15:42+09:00 |
| jvndb-2021-000011 | Panasonic Video Insight VMS vulnerable to arbitrary code execution | 2021-02-04T15:39+09:00 | 2021-02-04T15:39+09:00 |
| jvndb-2021-000006 | Multiple vulnerabilities in Aterm WF800HP, Aterm WG2600HP, and Aterm WG2600HP2 | 2021-01-22T17:55+09:00 | 2021-02-03T12:05+09:00 |
| jvndb-2021-001014 | Vulnerability in JP1/VERITAS | 2021-02-01T16:49+09:00 | 2021-02-01T16:49+09:00 |
| jvndb-2021-000009 | Android App "ELECOM File Manager" vulnerable to directory traversal | 2021-01-27T17:38+09:00 | 2021-01-27T17:38+09:00 |
| jvndb-2021-000008 | Multiple vulnerabilities in multiple ELECOM products | 2021-01-26T16:33+09:00 | 2021-01-26T16:33+09:00 |
| jvndb-2021-000010 | Multiple vulnerabilities in multiple LOGITEC products | 2021-01-26T16:26+09:00 | 2021-01-26T16:26+09:00 |
| jvndb-2021-001010 | TP-Link TL-WR841N V13 (JP) vulnerable to OS command injection | 2021-01-25T16:21+09:00 | 2021-01-25T16:21+09:00 |
| jvndb-2021-000005 | GROWI vulnerable to cross-site scripting | 2021-01-19T14:05+09:00 | 2021-01-19T14:05+09:00 |
| jvndb-2021-000004 | Multiple vulnerabilities in acmailer | 2021-01-14T16:22+09:00 | 2021-01-14T16:22+09:00 |
| jvndb-2021-000003 | The installer of SKYSEA Client View may insecurely load Dynamic Link Libraries | 2021-01-12T15:53+09:00 | 2021-01-12T15:53+09:00 |
| jvndb-2021-000002 | Multiple NEC Products vulnerable to authentication bypass | 2021-01-04T17:24+09:00 | 2021-01-08T12:22+09:00 |
| jvndb-2021-000001 | Multiple vulnerabilities in UNIVERGE SV9500/SV8500 series | 2021-01-04T14:37+09:00 | 2021-01-04T14:37+09:00 |
| jvndb-2020-009965 | Cleartext Transmission of Sensitive Information Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2020-12-21T17:48+09:00 | 2020-12-21T17:48+09:00 |
| jvndb-2020-009964 | Improper certificate validation vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2020-12-21T17:48+09:00 | 2020-12-21T17:48+09:00 |
| jvndb-2020-010072 | Cross-site Scripting Vulnerability in Hitachi Command Suite | 2020-12-21T14:20+09:00 | 2020-12-21T14:20+09:00 |
| jvndb-2020-000086 | Self-Extracting files created by multiple SEIKO EPSON products may insecurely load Dynamic Link Libraries | 2020-12-18T16:47+09:00 | 2020-12-18T16:47+09:00 |
| jvndb-2020-000083 | Multiple vulnerabilities in Aterm SA3500G | 2020-12-11T16:59+09:00 | 2020-12-11T16:59+09:00 |
| jvndb-2020-000082 | FileZen vulnerable to directory traversal | 2020-12-10T15:21+09:00 | 2020-12-10T15:21+09:00 |
| jvndb-2020-009771 | ServerProtect for Linux vulnerable to heap-based buffer overflow | 2020-12-08T12:34+09:00 | 2020-12-08T12:34+09:00 |
| jvndb-2020-000081 | Apache Cordova Plugin camera vulnerable to information exposure | 2020-12-07T16:34+09:00 | 2020-12-07T16:34+09:00 |
| jvndb-2020-000080 | Multiple vulnerabilities in EC-CUBE | 2020-12-03T18:15+09:00 | 2020-12-03T18:15+09:00 |
| jvndb-2020-000077 | Multiple vulnerabilities in GROWI | 2020-11-25T14:54+09:00 | 2020-11-25T14:54+09:00 |
| jvndb-2020-000076 | NETGEAR GS108Ev3 vulnerable to cross-site request forgery | 2020-11-24T14:32+09:00 | 2020-11-24T14:32+09:00 |
| jvndb-2020-000075 | The installers of multiple SEIKO EPSON products may insecurely load Dynamic Link Libraries | 2020-11-20T15:39+09:00 | 2020-11-20T15:39+09:00 |
| jvndb-2020-009590 | Trend Micro Security 2020 (Consumer) is vulnerable to arbitrary file deletion | 2020-11-19T18:03+09:00 | 2020-11-19T18:03+09:00 |
| jvndb-2020-000074 | Hibernate ORM vulnerable to SQL injection | 2020-11-19T14:33+09:00 | 2020-11-19T14:33+09:00 |
| jvndb-2020-009584 | Multiple vulnerabilities in KonaWiki3 | 2020-11-18T18:13+09:00 | 2020-11-18T18:13+09:00 |
| jvndb-2020-000073 | Movable Type Premium vulnerable to cross-site scripting | 2020-11-18T18:01+09:00 | 2020-11-18T18:01+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-1136 | Multiples vulnérabilités dans le noyau Linux de Debian LTS | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1135 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1134 | Multiples vulnérabilités dans MongoDB Server | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1133 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1132 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1131 | Multiples vulnérabilités dans les produits IBM | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1130 | Multiples vulnérabilités dans les produits Foxit | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1129 | Multiples vulnérabilités dans les produits VMware | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1128 | Multiples vulnérabilités dans Mozilla Firefox | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1127 | Multiples vulnérabilités dans Centreon Web | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1125 | Vulnérabilité dans les produits NetApp | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1124 | Multiples vulnérabilités dans Microsoft Edge | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1123 | Multiples vulnérabilités dans les produits Elastic | 2025-12-19T00:00:00.000000 | 2025-12-19T00:00:00.000000 |
| certfr-2025-avi-1121 | Vulnérabilité dans Sonicwall Secure Mobile Access | 2025-12-18T00:00:00.000000 | 2025-12-18T00:00:00.000000 |
| certfr-2025-avi-1120 | Vulnérabilité dans les produits Cisco | 2025-12-18T00:00:00.000000 | 2025-12-18T00:00:00.000000 |
| certfr-2025-avi-1119 | Multiples vulnérabilités dans les produits Synology | 2025-12-17T00:00:00.000000 | 2025-12-17T00:00:00.000000 |
| certfr-2025-avi-1118 | Vulnérabilité dans Mozilla Firefox | 2025-12-17T00:00:00.000000 | 2025-12-17T00:00:00.000000 |
| certfr-2025-avi-1117 | Multiples vulnérabilités dans GLPI | 2025-12-17T00:00:00.000000 | 2025-12-17T00:00:00.000000 |
| certfr-2025-avi-1116 | Multiples vulnérabilités dans Google Chrome | 2025-12-17T00:00:00.000000 | 2025-12-17T00:00:00.000000 |
| certfr-2025-avi-1115 | Vulnérabilité dans Trend Micro Apex One | 2025-12-16T00:00:00.000000 | 2025-12-16T00:00:00.000000 |
| certfr-2025-avi-1114 | Multiples vulnérabilités dans Tenable Nessus | 2025-12-16T00:00:00.000000 | 2025-12-16T00:00:00.000000 |
| certfr-2025-avi-1113 | Multiples vulnérabilités dans Moodle | 2025-12-16T00:00:00.000000 | 2025-12-16T00:00:00.000000 |
| certfr-2025-avi-1112 | Multiples vulnérabilités dans les produits Elastic | 2025-12-15T00:00:00.000000 | 2025-12-15T00:00:00.000000 |
| certfr-2025-avi-1110 | Multiples vulnérabilités dans les produits Apple | 2025-12-15T00:00:00.000000 | 2025-12-15T00:00:00.000000 |
| certfr-2025-avi-1109 | Vulnérabilité dans strongSwan | 2025-12-15T00:00:00.000000 | 2025-12-15T00:00:00.000000 |
| certfr-2025-avi-1103 | Multiples vulnérabilités dans Microsoft Edge | 2025-12-12T00:00:00.000000 | 2025-12-15T00:00:00.000000 |
| certfr-2025-avi-1096 | Multiples vulnérabilités dans Google Chrome | 2025-12-11T00:00:00.000000 | 2025-12-15T00:00:00.000000 |
| certfr-2025-avi-1108 | Multiples vulnérabilités dans les produits IBM | 2025-12-12T00:00:00.000000 | 2025-12-12T00:00:00.000000 |
| certfr-2025-avi-1107 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-12-12T00:00:00.000000 | 2025-12-12T00:00:00.000000 |
| certfr-2025-avi-1106 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-12-12T00:00:00.000000 | 2025-12-12T00:00:00.000000 |