Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-59293 | 6.6 (v3.1) | SMB minimum protocol dialect defaults to SMB1 |
Spring |
Spring Integration |
2026-08-27T17:57:51.016Z | 2026-08-28T18:36:46.105Z |
| cve-2026-59292 | 3.2 (v3.1) | World-readable metadata file in PropertiesPersistingMe… |
Spring |
Spring Integration |
2026-08-27T17:57:50.029Z | 2026-08-28T18:37:24.514Z |
| cve-2026-59291 | 2 (v3.1) | Potential arbitrary file read and SSRF vulnerability i… |
Spring |
Spring Cloud Function |
2026-08-27T17:57:48.943Z | 2026-08-28T18:38:29.352Z |
| cve-2026-59289 | N/A | Spring for GraphQL Denial of Service via pagination support |
Spring |
Spring for GraphQL |
2026-08-27T17:57:47.944Z | 2026-08-27T17:57:47.944Z |
| cve-2026-59288 | N/A | Spring for GraphQL Information Exposure in GraphiQL support |
Spring |
Spring for GraphQL |
2026-08-27T17:57:46.990Z | 2026-08-27T17:57:46.990Z |
| cve-2026-59287 | N/A | Spring for GraphQL WebSocket Client Denial of Service |
Spring |
Spring for GraphQL |
2026-08-27T17:57:45.951Z | 2026-08-27T17:57:45.951Z |
| cve-2026-59286 | N/A | Spring for GraphQL loads Untrusted Resources in Graphi… |
Spring |
Spring for GraphQL |
2026-08-27T17:57:44.958Z | 2026-08-27T17:57:44.958Z |
| cve-2026-59285 | N/A | Spring for GraphQL Unsafe Deserialization in paginatio… |
Spring |
Spring for GraphQL |
2026-08-27T17:57:43.851Z | 2026-08-27T17:57:43.851Z |
| cve-2026-59284 | 6.6 (v3.1) | Spring Cloud Commons no allow list for writable env ac… |
Spring |
Spring Cloud Commons |
2026-08-27T17:57:42.527Z | 2026-08-28T18:32:18.345Z |
| cve-2026-59283 | N/A | Spring Framework Safety Guard Bypass via SpEL Expressi… |
Spring |
Spring Framework |
2026-08-27T17:57:40.065Z | 2026-08-28T18:40:46.456Z |
| cve-2026-59282 | N/A | Spring Framework Denial of Service via Unbounded List … |
Spring |
Spring Framework |
2026-08-27T17:57:38.575Z | 2026-08-28T18:30:40.789Z |
| cve-2026-59281 | N/A | Spring Framework Cross-site Scripting via EscapedErrors |
Spring |
Spring Framework |
2026-08-27T17:57:37.157Z | 2026-08-28T18:56:23.590Z |
| cve-2026-59277 | 3.7 (v3.1) | Spring Security InetAddressMatchers Incomplete Interna… |
Spring |
Spring Security |
2026-08-27T17:57:36.006Z | 2026-08-28T14:01:04.295Z |
| cve-2026-59276 | 5.9 (v3.1) | Timing Attack via Non-Constant-Time Comparison of Sens… |
Spring |
Spring Security |
2026-08-27T17:57:34.993Z | 2026-08-28T14:00:41.248Z |
| cve-2026-4398 | 5.4 (v3.1) | Authorization Bypass Through User-Controlled Key in GitLab |
GitLab |
GitLab |
2026-08-27T17:53:14.609Z | 2026-08-28T14:13:54.361Z |
| cve-2026-76640 | 7.7 (v4.0) 7.5 (v3.1) | Unitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisionin… |
Unitree Robotics |
G1 EDU |
2026-08-27T17:52:11.749Z | 2026-08-28T15:53:16.149Z |
| cve-2026-76639 | 8.7 (v4.0) 8.8 (v3.1) | Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridg… |
Unitree Robotics |
G1 EDU |
2026-08-27T17:51:46.346Z | 2026-08-31T18:56:06.235Z |
| cve-2026-65931 | 5.1 (v4.0) | LimeSurvey Community Edition 7.0.5 - Improper authoriz… |
LimeSurvey |
LimeSurvey |
2026-08-27T17:50:47.311Z | 2026-08-28T14:13:54.515Z |
| cve-2026-48996 | Trilium: Malicious import with GeoMap marker title XSS… |
TriliumNext |
Trilium |
2026-08-27T17:36:07.483Z | 2026-08-29T03:56:03.899Z | |
| cve-2026-75889 | CVE-2026-75889 CVE Record |
Grafana |
Alloy |
2026-08-27T17:22:22.328Z | 2026-08-28T16:55:05.074Z | |
| cve-2026-54732 | libreoffice-convert: path traversal / arbitrary file write |
elwerene |
libreoffice-convert |
2026-08-27T17:21:50.743Z | 2026-08-28T14:54:16.963Z | |
| cve-2026-54718 | Silverstripe Advanced Workflow: Remote code execution … |
silverstripe |
silverstripe-advancedworkflow |
2026-08-27T17:19:51.691Z | 2026-08-31T18:17:17.110Z | |
| cve-2026-55758 | CC: Tweaked: Incomplete fix for GHSA-5jh9-2h63-pw4q: R… |
cc-tweaked |
CC-Tweaked |
2026-08-27T17:11:00.307Z | 2026-08-28T18:04:09.124Z | |
| cve-2026-54687 | n8n-nodes-sqlite3: Path traversal via user-controlled … |
DangerBlack |
n8n-node-sqlite3 |
2026-08-27T17:06:40.278Z | 2026-08-28T18:05:12.764Z | |
| cve-2026-19092 | Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Arg… |
Unknown |
Tutor LMS |
2026-08-27T17:05:37.621Z | 2026-08-28T13:03:21.752Z | |
| cve-2026-54713 | CakePHP Queue: Incomplete Comparison in getUniqueId vu… |
cakephp |
queue |
2026-08-27T17:03:31.580Z | 2026-08-28T15:55:52.105Z | |
| cve-2026-25250 | 6 (v3.1) | EAZ EazyFix 12.9 allows a Security Feature Bypass… |
eazsolution |
EazyFix |
2026-08-27T16:55:27.336Z | 2026-08-28T14:11:20.298Z |
| cve-2026-54721 | Silverstripe UserForms: Remote code execution via user… |
silverstripe |
silverstripe-userforms |
2026-08-27T16:52:46.023Z | 2026-08-28T15:58:28.067Z | |
| cve-2026-47727 | Trilium: RCE via `shareTemplate` relation missing `isD… |
TriliumNext |
Trilium |
2026-08-27T16:51:35.090Z | 2026-08-29T03:56:00.591Z | |
| cve-2026-66353 | 5.3 (v4.0) | Doggo vulnerable to cross-site scripting via unescaped… |
woylie |
doggo |
2026-08-27T16:44:59.553Z | 2026-08-28T14:13:54.861Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2020-000057 | NITORI App fails to restrict access permissions | 2020-08-26T15:34+09:00 | 2020-08-26T15:34+09:00 |
| jvndb-2020-000055 | Apache Struts 2 vulnerable to denial-of-service (DoS) | 2020-08-25T13:59+09:00 | 2022-08-09T13:57+09:00 |
| jvndb-2020-000054 | Multiple cross-site scripting vulnerabilities in Exment | 2020-08-21T14:34+09:00 | 2020-08-21T14:34+09:00 |
| jvndb-2020-000053 | Multiple vulnerabilities in CyberMail | 2020-08-11T14:20+09:00 | 2020-08-11T14:20+09:00 |
| jvndb-2020-007128 | DoS Vulnerability in HiRDB | 2020-08-03T16:37+09:00 | 2020-08-03T16:37+09:00 |
| jvndb-2020-007127 | Multiple Vulnerabilities in Hitachi Command Suite, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center | 2020-08-03T16:36+09:00 | 2020-08-03T16:36+09:00 |
| jvndb-2020-000052 | SKYSEA Client View vulnerable to privilege escalation | 2020-08-03T14:59+09:00 | 2020-08-03T14:59+09:00 |
| jvndb-2020-000051 | Multiple vulnerabilities in multiple PHP Factory products | 2020-07-31T16:29+09:00 | 2020-07-31T16:29+09:00 |
| jvndb-2020-000050 | FANUC i Series CNC vulnerable to denial-of-service (DoS) | 2020-07-31T14:29+09:00 | 2020-07-31T14:29+09:00 |
| jvndb-2020-000049 | TOYOTA MOTOR's Global TechStream vulnerable to buffer overflow | 2020-07-29T14:48+09:00 | 2020-10-08T18:08+09:00 |
| jvndb-2020-000047 | JavaFX WebEngine does not properly restrict Java method execution | 2020-07-28T15:47+09:00 | 2020-07-28T15:47+09:00 |
| jvndb-2020-000048 | Multiple vulnerabilities in KonaWiki2 and KonaWiki3 | 2020-07-28T15:38+09:00 | 2020-07-28T15:38+09:00 |
| jvndb-2020-000046 | WordPress Plugin "Social Sharing Plugin" vulnerable to cross-site request forgery | 2020-07-22T14:24+09:00 | 2020-07-22T14:24+09:00 |
| jvndb-2020-006617 | Cross-site Scripting Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2020-07-14T10:40+09:00 | 2020-07-14T10:40+09:00 |
| jvndb-2020-006586 | Server Side Request Forgery Vulnerability in Hitachi Ops Center Analyzer viewpoint | 2020-07-13T14:25+09:00 | 2020-07-13T14:25+09:00 |
| jvndb-2020-006469 | Multiple vulnerabilities in TCP/IP function on Mitsubishi Electric GOT2000 series | 2020-07-09T15:46+09:00 | 2020-07-09T15:46+09:00 |
| jvndb-2020-000045 | SHIRASAGI vulnerable to open redirect | 2020-07-09T15:08+09:00 | 2020-07-09T15:08+09:00 |
| jvndb-2020-000043 | Android App "Mercari" (Japan version) vulnerable to arbitrary method execution of the Java object | 2020-07-08T16:04+09:00 | 2020-07-08T16:04+09:00 |
| jvndb-2020-000042 | Multiple vulnerabilities in Cybozu Garoon | 2020-06-29T16:17+09:00 | 2020-06-29T16:17+09:00 |
| jvndb-2020-006031 | DoS Vulnerability in Hitachi Device Manager | 2020-06-29T12:25+09:00 | 2020-06-29T12:25+09:00 |
| jvndb-2020-000040 | Chrome Extension for e-Tax Reception System vulnerable to arbitrary command execution | 2020-06-24T14:25+09:00 | 2020-06-24T14:25+09:00 |
| jvndb-2020-005854 | Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series vulnerable to cleartext transmission of sensitive information | 2020-06-24T10:32+09:00 | 2020-06-24T10:32+09:00 |
| jvndb-2020-005743 | Vulnerability in Cosminexus HTTP Server | 2020-06-22T15:40+09:00 | 2020-06-22T15:40+09:00 |
| jvndb-2020-000039 | EC-CUBE vulnerable to directory traversal | 2020-06-18T13:48+09:00 | 2020-06-18T13:48+09:00 |
| jvndb-2020-005443 | Path Traversal Vulnerability in Hitachi Automation Director and Hitachi Ops Center Automator | 2020-06-15T16:29+09:00 | 2020-06-15T16:29+09:00 |
| jvndb-2020-000038 | Multiple vulnerabilities in Zenphoto | 2020-06-11T17:17+09:00 | 2020-06-11T17:17+09:00 |
| jvndb-2020-000037 | Multiple SONY Wireless Headphones allow improper Bluetooth pairing | 2020-06-09T15:49+09:00 | 2020-06-09T15:49+09:00 |
| jvndb-2020-000036 | XACK DNS vulnerable to denial-of-service (DoS) | 2020-06-05T15:16+09:00 | 2020-06-05T15:16+09:00 |
| jvndb-2020-000035 | Multiples security updates for multiple Cybozu products | 2020-05-29T15:40+09:00 | 2020-05-29T15:40+09:00 |
| jvndb-2020-004667 | Privilege escalation vulnerability in Hitachi Ops Center Common Services | 2020-05-25T16:17+09:00 | 2020-05-25T16:17+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-1097 | Vulnérabilité dans les produits Mitel | 2025-12-11T00:00:00.000000 | 2026-01-06T00:00:00.000000 |
| certfr-2025-avi-1096 | Multiples vulnérabilités dans Google Chrome | 2025-12-11T00:00:00.000000 | 2025-12-15T00:00:00.000000 |
| certfr-2025-avi-1095 | Multiples vulnérabilités dans GitLab | 2025-12-11T00:00:00.000000 | 2025-12-11T00:00:00.000000 |
| certfr-2025-avi-1094 | Multiples vulnérabilités dans les produits Microsoft | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1093 | Vulnérabilité dans Microsoft Azure Monitor Agent | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1092 | Multiples vulnérabilités dans Microsoft Windows | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1091 | Multiples vulnérabilités dans Microsoft Office | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1090 | Vulnérabilité dans les produits Moxa | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1089 | Vulnérabilité dans les produits Bitdefender | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1088 | Multiples vulnérabilités dans Ivanti Endpoint Manager (EPM) | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1087 | Multiples vulnérabilités dans les produits Mozilla | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1086 | Multiples vulnérabilités dans les produits Intel | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1085 | Multiples vulnérabilités dans les produits Adobe | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1084 | Multiples vulnérabilités dans les produits Fortinet | 2025-12-10T00:00:00.000000 | 2025-12-10T00:00:00.000000 |
| certfr-2025-avi-1083 | Multiples vulnérabilités dans les produits Siemens | 2025-12-09T00:00:00.000000 | 2025-12-09T00:00:00.000000 |
| certfr-2025-avi-1082 | Multiples vulnérabilités dans les produits Microsoft | 2025-12-09T00:00:00.000000 | 2025-12-09T00:00:00.000000 |
| certfr-2025-avi-1081 | Vulnérabilité dans Citrix XenServer | 2025-12-09T00:00:00.000000 | 2025-12-09T00:00:00.000000 |
| certfr-2025-avi-1080 | Multiples vulnérabilités dans VMware Tanzu RabbitMQ | 2025-12-09T00:00:00.000000 | 2025-12-09T00:00:00.000000 |
| certfr-2025-avi-1079 | Multiples vulnérabilités dans les produits SAP | 2025-12-09T00:00:00.000000 | 2025-12-09T00:00:00.000000 |
| certfr-2025-avi-1078 | Multiples vulnérabilités dans les produits Microsoft | 2025-12-08T00:00:00.000000 | 2025-12-08T00:00:00.000000 |
| certfr-2025-avi-1077 | Multiples vulnérabilités dans Traefik | 2025-12-08T00:00:00.000000 | 2025-12-08T00:00:00.000000 |
| certfr-2025-avi-1076 | Multiples vulnérabilités dans MISP | 2025-12-08T00:00:00.000000 | 2025-12-24T00:00:00.000000 |
| certfr-2025-avi-1075 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1074 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1073 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1072 | Multiples vulnérabilités dans les produits IBM | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1071 | Multiples vulnérabilités dans Apache HTTP Server | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1070 | Multiples vulnérabilités dans Microsoft CBL Mariner | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1069 | Multiples vulnérabilités dans Microsoft Edge | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1068 | Vulnérabilité dans Python | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |