Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-66353 | 5.3 (v4.0) | Doggo vulnerable to cross-site scripting via unescaped… |
woylie |
doggo |
2026-08-27T16:44:59.553Z | 2026-08-28T14:13:54.861Z |
| cve-2026-59280 | N/A | Spring Framework Path Traversal via Backslash in Sprin… |
Spring |
Spring Framework |
2026-08-27T16:41:09.664Z | 2026-08-27T17:42:15.735Z |
| cve-2026-59272 | 6.8 (v3.1) | Log4j2 AmqpAppender disables TLS hostname verification… |
Spring |
Spring AMQP |
2026-08-27T16:41:08.650Z | 2026-08-28T03:55:35.123Z |
| cve-2026-79720 | 6.8 (v4.0) | Reflected XSS in Netron versions <=9.1.2 on deskt… |
Netron |
Netron |
2026-08-27T16:40:09.913Z | 2026-08-27T18:49:38.838Z |
| cve-2026-79719 | 6.8 (v4.0) | Reflected XSS in Netron versions <=9.1.2 on deskt… |
Netron |
Netron |
2026-08-27T16:39:10.117Z | 2026-08-27T18:52:39.505Z |
| cve-2026-79718 | 6.8 (v4.0) | Reflected XSS in Netron versions <=9.1.2 on deskt… |
Netron |
Netron |
2026-08-27T16:37:25.817Z | 2026-08-27T18:53:05.315Z |
| cve-2026-19854 | CVE-2026-19854 CVE Record |
Grafana |
Clickhouse Datasource |
2026-08-27T16:35:17.652Z | 2026-08-27T17:44:26.203Z | |
| cve-2026-75871 | 8.2 (v3.1) | Server-Side Request Forgery (SSRF) in GitLab AI Gateway |
GitLab |
GitLab AI Gateway |
2026-08-27T16:33:55.451Z | 2026-08-27T18:58:34.704Z |
| cve-2026-19889 | 8.2 (v3.1) | Server-Side Request Forgery (SSRF) in GitLab AI Gateway |
GitLab |
GitLab AI Gateway |
2026-08-27T16:33:50.570Z | 2026-08-27T19:00:15.667Z |
| cve-2026-5680 | 7.5 (v3.1) | Undertow-core: undertow: denial of service via websock… |
Red Hat |
Red Hat build of Apache Camel for Spring Boot 4 |
2026-08-27T16:25:29.103Z | 2026-08-31T18:15:13.552Z |
| cve-2026-78002 | 7.5 (v3.1) | Rsyslog: rsyslog: denial of service via heap buffer ov… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-08-27T16:12:59.102Z | 2026-08-29T22:06:44.190Z |
| cve-2026-75573 | 4.1 (v4.0) 4.4 (v3.1) | MongoDB Connector for BI mongodrdl Logs TLS Private-Ke… |
MongoDB |
BI Connector |
2026-08-27T16:01:55.302Z | 2026-08-27T18:46:12.847Z |
| cve-2026-75159 | 8.2 (v4.0) 5.9 (v3.1) | MongoDB BI Connector Improper Memory Handling During F… |
MongoDB |
BI Connector |
2026-08-27T15:58:38.517Z | 2026-08-27T19:29:27.529Z |
| cve-2026-34674 | 7.8 (v3.1) | Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122) |
Adobe |
Adobe Substance 3D Sampler |
2026-08-27T15:43:02.749Z | 2026-08-27T22:24:20.219Z |
| cve-2026-79988 | 8.7 (v4.0) | Authenticated RCE through Twig sandbox escape |
craftcms |
cms |
2026-08-27T15:36:18.188Z | 2026-08-28T16:51:38.368Z |
| cve-2026-71402 | 5.3 (v4.0) 5.4 (v3.1) | wicked: out-of-bounds read in the DHCPv4 option parser… |
SUSE |
wicked |
2026-08-27T15:09:41.984Z | 2026-08-27T19:30:42.063Z |
| cve-2026-71401 | 5.3 (v4.0) | wicked: integer underflow of the UDP length in ni_capt… |
SUSE |
wicked |
2026-08-27T15:01:27.342Z | 2026-08-27T19:31:06.894Z |
| cve-2026-81735 | 10 (v4.0) 10 (v3.1) | UI-TARS-desktop @agent-infra MCP Servers Bind Every In… |
bytedance |
UI-TARS-desktop |
2026-08-27T14:51:20.291Z | 2026-08-31T18:14:39.625Z |
| cve-2026-81727 | 6.9 (v4.0) 7.1 (v3.1) | NLTK before 3.10.3 Hardlink File Overwrite via downloader |
nltk |
nltk |
2026-08-27T14:51:19.564Z | 2026-08-27T17:43:34.469Z |
| cve-2026-81726 | 8.3 (v4.0) 7 (v3.1) | NLTK through 3.10.3 Path Traversal via Model-Artifact APIs |
nltk |
nltk |
2026-08-27T14:51:18.838Z | 2026-08-27T19:29:23.489Z |
| cve-2026-81725 | 6.3 (v4.0) 3.7 (v3.1) | NLTK before 3.10.3 Regular Expression Denial of Servic… |
nltk |
nltk |
2026-08-27T14:51:18.082Z | 2026-08-28T15:58:35.166Z |
| cve-2026-81724 | 6.9 (v4.0) 5.3 (v3.1) | NLTK before 3.10.3 Denial of Service via Uncontrolled … |
nltk |
nltk |
2026-08-27T14:51:17.358Z | 2026-08-27T18:29:04.021Z |
| cve-2026-81723 | 6.3 (v4.0) 3.7 (v3.1) | NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCor… |
nltk |
nltk |
2026-08-27T14:51:16.614Z | 2026-08-31T18:12:57.437Z |
| cve-2026-81722 | 8.7 (v4.0) 7.5 (v3.1) | nltk PorterStemmer before 3.10.3 Quadratic-time DoS |
nltk |
nltk |
2026-08-27T14:51:15.857Z | 2026-08-27T17:49:54.623Z |
| cve-2026-81721 | 8.7 (v4.0) 7.5 (v3.1) | openssl_encrypt before 1.4.9 Denial of Service via KDF |
jahlives |
openssl_encrypt |
2026-08-27T14:51:15.109Z | 2026-08-27T19:28:47.802Z |
| cve-2026-81720 | 6.9 (v4.0) 6.2 (v3.1) | openssl_encrypt before 1.4.9 Denial of Service via Unb… |
jahlives |
openssl_encrypt |
2026-08-27T14:51:14.352Z | 2026-08-28T15:58:43.138Z |
| cve-2026-81719 | 9.3 (v4.0) 7.8 (v3.1) | openssl_encrypt before 1.4.9 Remote Code Execution via… |
jahlives |
openssl_encrypt |
2026-08-27T14:51:13.632Z | 2026-08-27T18:28:10.008Z |
| cve-2026-81718 | 8.7 (v4.0) 7.5 (v3.1) | openssl_encrypt before 1.4.9 Weak Cryptographic Parameters |
jahlives |
openssl_encrypt |
2026-08-27T14:51:12.898Z | 2026-08-31T18:01:42.800Z |
| cve-2026-81717 | 9.3 (v4.0) 3.5 (v3.1) | openssl_encrypt before 1.4.9 Integrity Bypass via Adde… |
jahlives |
openssl_encrypt |
2026-08-27T14:51:12.140Z | 2026-08-27T17:37:30.520Z |
| cve-2026-81716 | 8.7 (v4.0) 5.2 (v3.1) | openssl_encrypt before 1.4.9 Plugin Sandbox Path Traversal |
jahlives |
openssl_encrypt |
2026-08-27T14:51:11.331Z | 2026-08-27T19:28:26.155Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2020-000034 | Cybozu Desktop for Windows vulenerable to arbitrary code execution | 2020-05-25T15:09+09:00 | 2020-05-25T15:09+09:00 |
| jvndb-2020-000033 | WordPress Plugin "Paid Memberships Pro" vulnerable to SQL injection | 2020-05-19T16:07+09:00 | 2020-05-19T16:07+09:00 |
| jvndb-2020-000032 | Panasonic Video Insight VMS vulnerable to arbitrary code execution | 2020-05-19T16:04+09:00 | 2020-06-26T12:19+09:00 |
| jvndb-2020-004476 | DoS Vulnerability in JP1/Automatic Job Management System 3 and JP1/Automatic Job Management System 2 | 2020-05-19T10:38+09:00 | 2020-05-19T10:38+09:00 |
| jvndb-2020-004477 | Multiple Vulnerabilities in Hitachi Compute Systems Manager | 2020-05-19T10:33+09:00 | 2020-05-19T10:33+09:00 |
| jvndb-2020-000031 | BookStack vulnerable to cross-site scripting | 2020-05-13T18:06+09:00 | 2020-05-13T18:06+09:00 |
| jvndb-2020-000030 | Multiple vulnerabilities in Movable Type | 2020-05-13T17:59+09:00 | 2020-05-13T17:59+09:00 |
| jvndb-2020-000029 | PALLET CONTROL vulnerable to arbitrary code execution | 2020-05-11T15:16+09:00 | 2020-05-11T15:16+09:00 |
| jvndb-2020-000028 | Sales Force Assistant vulnerable to cross-site scripting | 2020-04-28T15:49+09:00 | 2020-04-28T15:49+09:00 |
| jvndb-2020-000027 | Cybozu Garoon contains multiple vulnerabilities | 2020-04-28T14:48+09:00 | 2020-04-28T14:48+09:00 |
| jvndb-2020-003896 | Directory Permission Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2020-04-28T12:21+09:00 | 2020-04-28T12:21+09:00 |
| jvndb-2020-000026 | Multiple SHARP Android devices vulnerable to information disclosure | 2020-04-24T15:32+09:00 | 2020-04-24T15:32+09:00 |
| jvndb-2020-000025 | Toshiba Electronic Devices & Storage software registers unquoted service paths | 2020-04-20T17:13+09:00 | 2023-11-08T16:44+09:00 |
| jvndb-2020-000022 | Multiple vulnerabilities in EasyBlocks IPv6 | 2020-04-08T16:12+09:00 | 2020-04-08T16:12+09:00 |
| jvndb-2020-000024 | Joomla! plugin "AcyMailing" vulnerable to arbitrary file uploads | 2020-04-07T14:49+09:00 | 2020-04-07T14:49+09:00 |
| jvndb-2020-000021 | Multiple Yamaha network devices vulnerable to denial-of-service (DoS) | 2020-03-31T17:44+09:00 | 2020-04-01T18:38+09:00 |
| jvndb-2020-002958 | Denial-of-service (DoS) vulnerability in Mitsubishi Electric MELSOFT transmission port | 2020-03-31T13:37+09:00 | 2020-04-01T14:45+09:00 |
| jvndb-2020-000907 | WL-Enq (WEB Enquete) vulnerable to OS command injection | 2020-03-25T09:50+09:00 | 2020-03-25T09:50+09:00 |
| jvndb-2020-000906 | WL-Enq (WEB Enquete) vulnerable to cross-site scripting | 2020-03-24T18:29+09:00 | 2023-10-30T17:52+09:00 |
| jvndb-2020-000908 | Keijiban Tsumiki vulnerable to OS command injection | 2020-03-24T18:14+09:00 | 2020-03-24T18:14+09:00 |
| jvndb-2020-000900 | mailform vulnerable to cross-site scripting | 2020-03-24T18:05+09:00 | 2020-03-24T18:05+09:00 |
| jvndb-2020-000901 | mailform vulnerable to PHP code execution | 2020-03-24T17:59+09:00 | 2020-03-24T17:59+09:00 |
| jvndb-2020-000902 | Multiple vulnerabilities in Shihonkanri Plus GOOUT | 2020-03-24T17:53+09:00 | 2020-03-24T17:53+09:00 |
| jvndb-2020-000903 | Shihonkanri Plus GOOUT vulnerable to OS command injection | 2020-03-24T17:47+09:00 | 2020-03-24T17:47+09:00 |
| jvndb-2020-000904 | CuteNews vulnerable to cross-site scripting | 2020-03-24T17:42+09:00 | 2020-03-24T17:42+09:00 |
| jvndb-2020-000905 | Cute News vulnerable to PHP code execution | 2020-03-24T17:40+09:00 | 2020-03-24T17:40+09:00 |
| jvndb-2020-002278 | Cross-site Scripting Vulnerability in JP1/Performance Management - Manager [Web Console] | 2020-03-11T14:16+09:00 | 2020-03-11T14:16+09:00 |
| jvndb-2020-002219 | Multiple Vulnerabilities in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center | 2020-03-09T11:23+09:00 | 2020-03-09T11:23+09:00 |
| jvndb-2020-002220 | Improper LDAPS Certificate Validation in Hitachi Ops Center Common Services | 2020-03-09T11:21+09:00 | 2020-03-09T11:21+09:00 |
| jvndb-2020-000020 | Multiple vulnerabilities in OpenBlocks IoT VX2 | 2020-03-03T17:50+09:00 | 2020-03-03T17:50+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-1067 | Vulnérabilité dans Apache Struts | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1066 | Multiples vulnérabilités dans les produits Nextcloud | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1065 | Multiples vulnérabilités dans NetApp ONTAP | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1064 | Multiples vulnérabilités dans les produits Microsoft | 2025-12-04T00:00:00.000000 | 2025-12-04T00:00:00.000000 |
| certfr-2025-avi-1063 | Multiples vulnérabilités dans les produits Splunk | 2025-12-04T00:00:00.000000 | 2025-12-04T00:00:00.000000 |
| certfr-2025-avi-1062 | Multiples vulnérabilités dans Wireshark | 2025-12-04T00:00:00.000000 | 2025-12-04T00:00:00.000000 |
| certfr-2025-avi-1061 | Vulnérabilité dans PostgreSQL PgBouncer | 2025-12-04T00:00:00.000000 | 2025-12-04T00:00:00.000000 |
| certfr-2025-avi-1060 | Multiples vulnérabilités dans Python | 2025-12-03T00:00:00.000000 | 2025-12-03T00:00:00.000000 |
| certfr-2025-avi-1059 | Multiples vulnérabilités dans Google Pixel | 2025-12-03T00:00:00.000000 | 2025-12-03T00:00:00.000000 |
| certfr-2025-avi-1058 | Multiples vulnérabilités dans Google Chrome | 2025-12-03T00:00:00.000000 | 2025-12-03T00:00:00.000000 |
| certfr-2025-avi-1057 | Multiples vulnérabilités dans les produits VMware | 2025-12-02T00:00:00.000000 | 2025-12-02T00:00:00.000000 |
| certfr-2025-avi-1056 | Multiples vulnérabilités dans Google Android | 2025-12-02T00:00:00.000000 | 2025-12-02T00:00:00.000000 |
| certfr-2025-avi-1055 | Multiples vulnérabilités dans Zabbix | 2025-12-01T00:00:00.000000 | 2025-12-01T00:00:00.000000 |
| certfr-2025-avi-1054 | Multiples vulnérabilités dans les produits VMware | 2025-12-01T00:00:00.000000 | 2025-12-01T00:00:00.000000 |
| certfr-2025-avi-1053 | Vulnérabilité dans Stormshield Network VPN Client | 2025-12-01T00:00:00.000000 | 2025-12-01T00:00:00.000000 |
| certfr-2025-avi-1052 | Vulnérabilité dans Mattermost Server | 2025-12-01T00:00:00.000000 | 2025-12-01T00:00:00.000000 |
| certfr-2025-avi-1051 | Multiples vulnérabilités dans les produits IBM | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1050 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1049 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1048 | Multiples vulnérabilités dans le noyau Linux de Debian LTS | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1047 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1046 | Multiples vulnérabilités dans les produits Moxa | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1045 | Vulnérabilité dans MISP | 2025-11-27T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1044 | Vulnérabilité dans Mattermost Server | 2025-11-27T00:00:00.000000 | 2025-11-27T00:00:00.000000 |
| certfr-2025-avi-1043 | Multiples vulnérabilités dans les produits Splunk | 2025-11-27T00:00:00.000000 | 2025-11-27T00:00:00.000000 |
| certfr-2025-avi-1042 | Multiples vulnérabilités dans GitLab | 2025-11-27T00:00:00.000000 | 2025-11-27T00:00:00.000000 |
| certfr-2025-avi-1041 | Vulnérabilité dans Synology ActiveProtect Agent | 2025-11-26T00:00:00.000000 | 2025-11-26T00:00:00.000000 |
| certfr-2025-avi-1040 | Vulnérabilité dans Postfix | 2025-11-26T00:00:00.000000 | 2025-11-26T00:00:00.000000 |
| certfr-2025-avi-1039 | Vulnérabilité dans Kaspersky Security Center | 2025-11-25T00:00:00.000000 | 2025-11-25T00:00:00.000000 |
| certfr-2025-avi-1038 | Vulnérabilité dans les produits PrimX | 2025-11-25T00:00:00.000000 | 2025-11-25T00:00:00.000000 |