Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-78228 | 5.9 (v4.0) | Unbounded handle_error recursion enables denial of ser… |
ash-project |
ash_oban |
2026-08-30T11:51:49.621Z | 2026-08-31T14:56:07.859Z |
| cve-2026-6245 | 5.5 (v3.1) | Sssd: out-of-bounds read in the sssd |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-04-15T18:35:19.401Z | 2026-08-31T14:56:02.110Z |
| cve-2026-51694 | N/A | Incorrect access control in the setStaticDhcpRule… |
n/a |
n/a |
2026-08-31T00:00:00.000Z | 2026-08-31T14:55:54.621Z |
| cve-2026-5745 | 5.5 (v3.1) | Libarchive: a null pointer dereference vulnerability e… |
Red Hat |
Red Hat Hardened Images |
2026-04-07T14:57:31.587Z | 2026-08-31T14:55:52.966Z |
| cve-2026-51693 | N/A | Incorrect access control in the setVpnPassCfg fun… |
n/a |
n/a |
2026-08-31T00:00:00.000Z | 2026-08-31T14:55:22.902Z |
| cve-2026-78038 | 5.9 (v4.0) | Job argument injection via :args overrides primary_key… |
ash-project |
ash_oban |
2026-08-30T11:50:21.136Z | 2026-08-31T14:55:17.264Z |
| cve-2026-51692 | N/A | Incorrect access control in the setWiFiGuestCfg f… |
n/a |
n/a |
2026-08-31T00:00:00.000Z | 2026-08-31T14:54:55.303Z |
| cve-2026-77846 | 2.1 (v4.0) | JSON path injection via unescaped get_path segments in… |
ash-project |
ash_sqlite |
2026-08-30T02:52:12.562Z | 2026-08-31T14:54:22.261Z |
| cve-2026-51691 | N/A | Incorrect access control in the setUploadSetting … |
n/a |
n/a |
2026-08-31T00:00:00.000Z | 2026-08-31T14:54:03.926Z |
| cve-2026-71310 | rclone: Unbounded HTTP CONNECT Response Headers Can Ex… |
rclone |
rclone |
2026-08-05T20:17:14.858Z | 2026-08-31T14:53:51.616Z | |
| cve-2026-75759 | 7.6 (v4.0) | Encrypted ID token or JARM response accepted without a… |
erlef |
oidcc |
2026-08-30T01:12:43.435Z | 2026-08-31T14:53:35.902Z |
| cve-2026-63083 | N/A | {'providerMetadata': {'orgId': '83251b91-4cc7-4094-a5c7-464a1b83ea10', 'shortName': 'VulnCheck', 'dateUpdated': '2026-08-31T14:52:57.799Z'}, 'rejectedReasons': [{'lang': 'en', 'value': 'This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.'}]} | N/A | N/A | 2026-08-31T14:52:57.799Z | |
| cve-2026-77831 | 2.1 (v4.0) | Algorithmic-complexity denial of service in AshPaperTr… |
ash-project |
ash_paper_trail |
2026-08-30T00:18:38.078Z | 2026-08-31T14:52:45.550Z |
| cve-2026-77970 | 5.9 (v4.0) | Sensitive fields nested in embedded values are not red… |
ash-project |
ash_paper_trail |
2026-08-30T00:18:22.853Z | 2026-08-31T14:51:59.120Z |
| cve-2026-75757 | 8.3 (v4.0) | AshAdmin cookie reader matches names by substring, ena… |
ash-project |
ash_admin |
2026-08-31T02:20:17.985Z | 2026-08-31T14:50:59.043Z |
| cve-2026-82673 | 8.3 (v4.0) | Path traversal in AshAdmin file uploads via unsanitize… |
ash-project |
ash_admin |
2026-08-31T02:33:10.967Z | 2026-08-31T14:50:14.728Z |
| cve-2026-38468 | N/A | A SQL injection vulnerability in the country-code… |
n/a |
n/a |
2026-08-25T00:00:00.000Z | 2026-08-31T14:50:00.408Z |
| cve-2026-82727 | 2.3 (v4.0) | AshPhoenix Form.Auto leaks submitted params in an unkn… |
ash-project |
ash_phoenix |
2026-08-31T03:03:58.982Z | 2026-08-31T14:49:25.154Z |
| cve-2026-42010 | 7.1 (v3.1) | Gnutls: gnutls: authentication bypass via nul characte… |
|
|
2026-05-07T12:00:05.433Z | 2026-08-31T14:49:09.010Z |
| cve-2026-42009 | 7.5 (v3.1) | Gnutls: gnutls: denial of service via dtls packet reor… |
|
|
2026-05-18T12:44:45.229Z | 2026-08-31T14:49:05.742Z |
| cve-2026-33846 | 7.5 (v3.1) | Gnutls: gnutls: denial of service via heap buffer over… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-05-04T09:08:51.710Z | 2026-08-31T14:48:54.599Z |
| cve-2026-33845 | 7.5 (v3.1) | Gnutls: gnutls: denial of service via dtls zero-length… |
|
|
2026-04-30T17:41:34.076Z | 2026-08-31T14:48:53.695Z |
| cve-2026-4878 | 6.7 (v3.1) | Libcap: libcap: privilege escalation via toctou race c… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-04-09T14:49:02.942Z | 2026-08-31T14:48:46.863Z |
| cve-2026-16443 | 7.4 (v3.1) | Keycloak-services: keycloak-services: saml broker meta… |
Red Hat |
Red Hat build of Keycloak 26.4 |
2026-08-05T13:44:09.557Z | 2026-08-31T14:47:51.247Z |
| cve-2026-16442 | 7.4 (v3.1) | Keycloak-services: keycloak-services: saml idp-initiat… |
Red Hat |
Red Hat build of Keycloak 26.4 |
2026-08-05T15:00:39.236Z | 2026-08-31T14:47:48.991Z |
| cve-2026-82726 | 6.3 (v4.0) | AshPhoenix get_subdomain maps a crafted or differently… |
ash-project |
ash_phoenix |
2026-08-31T03:05:38.612Z | 2026-08-31T14:47:35.274Z |
| cve-2026-82615 | itsourcecode Online Medicine Delivery System Password … |
itsourcecode |
Online Medicine Delivery System |
2026-08-31T04:30:10.673Z | 2026-08-31T14:46:41.746Z | |
| cve-2026-66047 | 9.2 (v4.0) 8.1 (v3.1) | ProfilePress WordPress Plugin < 4.17.2 Unauthenticated… |
Proper Fraction |
ProfilePress |
2026-08-31T14:46:41.174Z | 2026-08-31T14:46:41.174Z |
| cve-2026-82610 | itsourcecode Online Medicine Delivery System Login log… |
itsourcecode |
Online Medicine Delivery System |
2026-08-31T03:15:08.792Z | 2026-08-31T14:46:04.872Z | |
| cve-2026-82875 | 5.1 (v4.0) 5.5 (v3.1) | ToolJet before v3.16.208 Authorization Bypass via orga… |
ToolJet |
ToolJet |
2026-08-31T08:46:43.077Z | 2026-08-31T14:45:27.214Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2020-006617 | Cross-site Scripting Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2020-07-14T10:40+09:00 | 2020-07-14T10:40+09:00 |
| jvndb-2020-006586 | Server Side Request Forgery Vulnerability in Hitachi Ops Center Analyzer viewpoint | 2020-07-13T14:25+09:00 | 2020-07-13T14:25+09:00 |
| jvndb-2020-006469 | Multiple vulnerabilities in TCP/IP function on Mitsubishi Electric GOT2000 series | 2020-07-09T15:46+09:00 | 2020-07-09T15:46+09:00 |
| jvndb-2020-000045 | SHIRASAGI vulnerable to open redirect | 2020-07-09T15:08+09:00 | 2020-07-09T15:08+09:00 |
| jvndb-2020-000043 | Android App "Mercari" (Japan version) vulnerable to arbitrary method execution of the Java object | 2020-07-08T16:04+09:00 | 2020-07-08T16:04+09:00 |
| jvndb-2020-000042 | Multiple vulnerabilities in Cybozu Garoon | 2020-06-29T16:17+09:00 | 2020-06-29T16:17+09:00 |
| jvndb-2020-006031 | DoS Vulnerability in Hitachi Device Manager | 2020-06-29T12:25+09:00 | 2020-06-29T12:25+09:00 |
| jvndb-2019-000056 | Panasonic Video Insight VMS vulnerable to SQL injection | 2019-09-02T13:57+09:00 | 2020-06-26T12:27+09:00 |
| jvndb-2020-000032 | Panasonic Video Insight VMS vulnerable to arbitrary code execution | 2020-05-19T16:04+09:00 | 2020-06-26T12:19+09:00 |
| jvndb-2020-000040 | Chrome Extension for e-Tax Reception System vulnerable to arbitrary command execution | 2020-06-24T14:25+09:00 | 2020-06-24T14:25+09:00 |
| jvndb-2020-005854 | Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series vulnerable to cleartext transmission of sensitive information | 2020-06-24T10:32+09:00 | 2020-06-24T10:32+09:00 |
| jvndb-2020-005743 | Vulnerability in Cosminexus HTTP Server | 2020-06-22T15:40+09:00 | 2020-06-22T15:40+09:00 |
| jvndb-2020-000039 | EC-CUBE vulnerable to directory traversal | 2020-06-18T13:48+09:00 | 2020-06-18T13:48+09:00 |
| jvndb-2020-005443 | Path Traversal Vulnerability in Hitachi Automation Director and Hitachi Ops Center Automator | 2020-06-15T16:29+09:00 | 2020-06-15T16:29+09:00 |
| jvndb-2020-000038 | Multiple vulnerabilities in Zenphoto | 2020-06-11T17:17+09:00 | 2020-06-11T17:17+09:00 |
| jvndb-2020-000037 | Multiple SONY Wireless Headphones allow improper Bluetooth pairing | 2020-06-09T15:49+09:00 | 2020-06-09T15:49+09:00 |
| jvndb-2020-000036 | XACK DNS vulnerable to denial-of-service (DoS) | 2020-06-05T15:16+09:00 | 2020-06-05T15:16+09:00 |
| jvndb-2020-000035 | Multiples security updates for multiple Cybozu products | 2020-05-29T15:40+09:00 | 2020-05-29T15:40+09:00 |
| jvndb-2020-004667 | Privilege escalation vulnerability in Hitachi Ops Center Common Services | 2020-05-25T16:17+09:00 | 2020-05-25T16:17+09:00 |
| jvndb-2020-000034 | Cybozu Desktop for Windows vulenerable to arbitrary code execution | 2020-05-25T15:09+09:00 | 2020-05-25T15:09+09:00 |
| jvndb-2020-000033 | WordPress Plugin "Paid Memberships Pro" vulnerable to SQL injection | 2020-05-19T16:07+09:00 | 2020-05-19T16:07+09:00 |
| jvndb-2020-004476 | DoS Vulnerability in JP1/Automatic Job Management System 3 and JP1/Automatic Job Management System 2 | 2020-05-19T10:38+09:00 | 2020-05-19T10:38+09:00 |
| jvndb-2020-004477 | Multiple Vulnerabilities in Hitachi Compute Systems Manager | 2020-05-19T10:33+09:00 | 2020-05-19T10:33+09:00 |
| jvndb-2020-000031 | BookStack vulnerable to cross-site scripting | 2020-05-13T18:06+09:00 | 2020-05-13T18:06+09:00 |
| jvndb-2020-000030 | Multiple vulnerabilities in Movable Type | 2020-05-13T17:59+09:00 | 2020-05-13T17:59+09:00 |
| jvndb-2020-000029 | PALLET CONTROL vulnerable to arbitrary code execution | 2020-05-11T15:16+09:00 | 2020-05-11T15:16+09:00 |
| jvndb-2020-000028 | Sales Force Assistant vulnerable to cross-site scripting | 2020-04-28T15:49+09:00 | 2020-04-28T15:49+09:00 |
| jvndb-2020-000027 | Cybozu Garoon contains multiple vulnerabilities | 2020-04-28T14:48+09:00 | 2020-04-28T14:48+09:00 |
| jvndb-2020-003896 | Directory Permission Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer | 2020-04-28T12:21+09:00 | 2020-04-28T12:21+09:00 |
| jvndb-2020-000026 | Multiple SHARP Android devices vulnerable to information disclosure | 2020-04-24T15:32+09:00 | 2020-04-24T15:32+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-1072 | Multiples vulnérabilités dans les produits IBM | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1071 | Multiples vulnérabilités dans Apache HTTP Server | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1070 | Multiples vulnérabilités dans Microsoft CBL Mariner | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1069 | Multiples vulnérabilités dans Microsoft Edge | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1068 | Vulnérabilité dans Python | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1067 | Vulnérabilité dans Apache Struts | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1066 | Multiples vulnérabilités dans les produits Nextcloud | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1065 | Multiples vulnérabilités dans NetApp ONTAP | 2025-12-05T00:00:00.000000 | 2025-12-05T00:00:00.000000 |
| certfr-2025-avi-1064 | Multiples vulnérabilités dans les produits Microsoft | 2025-12-04T00:00:00.000000 | 2025-12-04T00:00:00.000000 |
| certfr-2025-avi-1063 | Multiples vulnérabilités dans les produits Splunk | 2025-12-04T00:00:00.000000 | 2025-12-04T00:00:00.000000 |
| certfr-2025-avi-1062 | Multiples vulnérabilités dans Wireshark | 2025-12-04T00:00:00.000000 | 2025-12-04T00:00:00.000000 |
| certfr-2025-avi-1061 | Vulnérabilité dans PostgreSQL PgBouncer | 2025-12-04T00:00:00.000000 | 2025-12-04T00:00:00.000000 |
| certfr-2024-avi-1090 | Multiples vulnérabilités dans Synacor Zimbra Collaboration | 2024-12-18T00:00:00.000000 | 2025-12-04T00:00:00.000000 |
| certfr-2025-avi-1060 | Multiples vulnérabilités dans Python | 2025-12-03T00:00:00.000000 | 2025-12-03T00:00:00.000000 |
| certfr-2025-avi-1059 | Multiples vulnérabilités dans Google Pixel | 2025-12-03T00:00:00.000000 | 2025-12-03T00:00:00.000000 |
| certfr-2025-avi-1058 | Multiples vulnérabilités dans Google Chrome | 2025-12-03T00:00:00.000000 | 2025-12-03T00:00:00.000000 |
| certfr-2025-avi-1057 | Multiples vulnérabilités dans les produits VMware | 2025-12-02T00:00:00.000000 | 2025-12-02T00:00:00.000000 |
| certfr-2025-avi-1056 | Multiples vulnérabilités dans Google Android | 2025-12-02T00:00:00.000000 | 2025-12-02T00:00:00.000000 |
| certfr-2025-avi-1055 | Multiples vulnérabilités dans Zabbix | 2025-12-01T00:00:00.000000 | 2025-12-01T00:00:00.000000 |
| certfr-2025-avi-1054 | Multiples vulnérabilités dans les produits VMware | 2025-12-01T00:00:00.000000 | 2025-12-01T00:00:00.000000 |
| certfr-2025-avi-1053 | Vulnérabilité dans Stormshield Network VPN Client | 2025-12-01T00:00:00.000000 | 2025-12-01T00:00:00.000000 |
| certfr-2025-avi-1052 | Vulnérabilité dans Mattermost Server | 2025-12-01T00:00:00.000000 | 2025-12-01T00:00:00.000000 |
| certfr-2025-avi-0936 | Multiples vulnérabilités dans Mattermost Server | 2025-10-29T00:00:00.000000 | 2025-12-01T00:00:00.000000 |
| certfr-2025-avi-1051 | Multiples vulnérabilités dans les produits IBM | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1050 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1049 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1048 | Multiples vulnérabilités dans le noyau Linux de Debian LTS | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1047 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1046 | Multiples vulnérabilités dans les produits Moxa | 2025-11-28T00:00:00.000000 | 2025-11-28T00:00:00.000000 |
| certfr-2025-avi-1045 | Vulnérabilité dans MISP | 2025-11-27T00:00:00.000000 | 2025-11-28T00:00:00.000000 |