Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-62568 | Vulnerability in the Oracle Hyperion Infrastructu… |
Oracle Corporation |
Oracle Hyperion Infrastructure Technology |
2026-08-18T21:00:31.349Z | 2026-08-25T18:03:32.758Z | |
| cve-2026-62571 | Vulnerability in the Oracle Hyperion Calculation … |
Oracle Corporation |
Oracle Hyperion Calculation Manager |
2026-08-18T21:00:32.327Z | 2026-08-25T18:03:32.594Z | |
| cve-2026-62572 | Vulnerability in the Oracle Hyperion Infrastructu… |
Oracle Corporation |
Oracle Hyperion Infrastructure Technology |
2026-08-18T21:00:32.636Z | 2026-08-25T18:03:32.433Z | |
| cve-2026-62628 | Vulnerability in the Oracle Reports Developer pro… |
Oracle Corporation |
Oracle Reports Developer |
2026-08-18T21:00:50.508Z | 2026-08-25T18:03:32.272Z | |
| cve-2026-62627 | Vulnerability in the Oracle Reports Developer pro… |
Oracle Corporation |
Oracle Reports Developer |
2026-08-18T21:00:50.185Z | 2026-08-25T18:03:32.107Z | |
| cve-2023-6610 | 7.1 (v3.1) | Kernel: oob access in smb2_dump_detail |
Linux |
kernel |
2023-12-08T16:58:09.963Z | 2026-08-25T18:02:54.627Z |
| cve-2026-72697 | 7.1 (v4.0) 6.5 (v3.1) | Grav CMS before 2.0.16 Path Traversal via media_directory |
getgrav |
grav |
2026-08-25T01:30:18.001Z | 2026-08-25T18:01:46.215Z |
| cve-2026-26211 | 4.8 (v4.0) 4.8 (v3.1) | Ekushey Project Manager CRM 5.0 Stored XSS via System … |
Creativeitem |
Ekushey Project Manager CRM |
2026-08-25T17:28:19.228Z | 2026-08-25T18:01:02.481Z |
| cve-2026-78887 | liketrek TREK Journey Photo Proxy validateShareTokenFo… |
liketrek |
TREK |
2026-08-25T12:45:10.723Z | 2026-08-25T17:59:31.339Z | |
| cve-2026-55571 | djust authentication bypass: a login_required / on_mou… |
djust-org |
djust |
2026-08-25T16:05:49.069Z | 2026-08-25T17:56:03.253Z | |
| cve-2026-59187 | OpenEXR: exrmetrics deep pixelmode heap buffer overflow |
AcademySoftwareFoundation |
openexr |
2026-08-25T16:38:51.404Z | 2026-08-25T17:52:03.356Z | |
| cve-2023-4010 | N/A | {'rejectedReasons': [{'lang': 'en', 'value': 'Rejected because the CVE description attributes a vulnerability to a non-existent Linux kernel function (usb_giveback_urb()) and the reported issue cannot be mapped to any valid codebase.'}], 'providerMetadata': {'orgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'shortName': 'redhat', 'dateUpdated': '2026-08-25T17:44:55.892Z'}, 'x_generator': {'engine': 'cvelib 1.8.0'}} | N/A | N/A | 2023-07-31T16:22:24.371Z | 2026-08-25T17:44:55.892Z |
| cve-2026-79771 | 6.9 (v4.0) 5.3 (v3.1) | Nokogiri before 1.19.3 Memory Leak via XSLT Transform |
sparklemotion |
nokogiri |
2026-08-25T15:16:03.736Z | 2026-08-25T17:44:08.629Z |
| cve-2026-62674 | Omnigent: Shared Agent Bundle Overwrite Leads to Authe… |
omnigent-ai |
omnigent |
2026-08-21T17:47:37.976Z | 2026-08-25T17:43:46.509Z | |
| cve-2026-69104 | 7.6 (v3.1) | Potential unauthorized repository migration in JFrog A… |
jfrog |
artifactory |
2026-08-25T15:09:29.369Z | 2026-08-25T17:43:24.784Z |
| cve-2026-79674 | 8.8 (v4.0) 8.2 (v3.1) | NLTK 3.10.2 Path Traversal via corpus-reader constructors |
nltk |
nltk |
2026-08-25T15:16:00.226Z | 2026-08-25T17:42:56.934Z |
| cve-2026-72714 | 6.8 (v4.0) 6.3 (v3.1) | Rocq Prover through 9.2.0 Universe Checking State Desy… |
rocq-prover |
rocq |
2026-08-24T20:08:33.917Z | 2026-08-25T17:41:24.594Z |
| cve-2026-72695 | 7.1 (v4.0) 8.1 (v3.1) | Grav before 2.0.16 Path Traversal via MediaUploadTrait… |
getgrav |
grav |
2026-08-25T01:30:11.868Z | 2026-08-25T17:38:09.024Z |
| cve-2026-63462 | Unleash: Unauthenticated single-request DoS via OpenAP… |
Unleash |
unleash |
2026-08-21T18:12:32.807Z | 2026-08-25T17:33:23.689Z | |
| cve-2026-34491 | 6.1 (v4.0) | Improper neutralization of input during web page … |
Johnson Controls |
Metasys 14 |
2026-08-24T17:24:25.732Z | 2026-08-25T17:33:18.447Z |
| cve-2026-54682 | DiscordChatExporter: Stored XSS in HTML export when ma… |
Tyrrrz |
DiscordChatExporter |
2026-08-21T18:40:05.196Z | 2026-08-25T17:31:36.280Z | |
| cve-2026-79670 | 4.8 (v4.0) 4.8 (v3.1) | Ech0 before 4.4.3 Stored XSS via SVG Upload |
lin-snow |
Ech0 |
2026-08-25T11:33:31.499Z | 2026-08-25T17:30:32.633Z |
| cve-2026-79781 | 6.9 (v4.0) 6.5 (v3.1) | rclone serve s3 Path Traversal via dot-dot object keys |
rclone |
rclone |
2026-08-25T15:16:10.471Z | 2026-08-25T17:29:20.262Z |
| cve-2026-30866 | Combodo iTop: Insecured access to uploaded images via … |
Combodo |
iTop |
2026-08-21T19:32:00.149Z | 2026-08-25T17:28:23.007Z | |
| cve-2026-79776 | 6.9 (v4.0) 5.3 (v3.1) | rclone before 1.75.0 Authentication Bypass via pprof |
rclone |
rclone |
2026-08-25T15:16:07.085Z | 2026-08-25T17:27:57.096Z |
| cve-2026-72700 | 8.7 (v4.0) 7.5 (v3.1) | Grav before 3.9.1 Timing Attack via Non-Constant-Time … |
getgrav |
grav |
2026-08-25T01:30:22.914Z | 2026-08-25T17:25:36.693Z |
| cve-2026-76876 | 8.2 (v4.0) 5.9 (v3.1) | Craftplan < 0.5.1 Broken Access Control Information Di… |
puemos |
craftplan |
2026-08-21T19:38:45.203Z | 2026-08-25T17:17:45.458Z |
| cve-2026-27490 | Combodo iTop: Weak secret generation for inline image |
Combodo |
iTop |
2026-08-21T19:59:29.384Z | 2026-08-25T17:16:32.291Z | |
| cve-2026-53572 | KEDA: PostgreSQL connection string parameter injection… |
kedacore |
keda |
2026-08-21T20:11:56.479Z | 2026-08-25T17:13:43.120Z | |
| cve-2026-71905 | 8.6 (v4.0) 7.2 (v3.1) | DrayTek VigorAP Multiple Models OS Command Injection v… |
DrayTek Corporation |
VigorAP 918R |
2026-08-24T17:07:40.253Z | 2026-08-25T17:12:38.113Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certa-2011-avi-553 | Vulnérabilité dans Windows Media Center | 2011-10-12T00:00:00.000000 | 2011-10-12T00:00:00.000000 |
| certa-2011-avi-552 | Vulnérabilité dans Microsoft Active Accessibility | 2011-10-12T00:00:00.000000 | 2011-10-12T00:00:00.000000 |
| certa-2011-avi-551 | Vulnérabilité dans CyrusIMAPd | 2011-10-07T00:00:00.000000 | 2011-10-07T00:00:00.000000 |
| certa-2011-avi-550 | Vulnérabilités dans Google Chrome | 2011-10-06T00:00:00.000000 | 2011-10-06T00:00:00.000000 |
| certa-2011-avi-549 | Vulnérabilités dans Novell Identity Manager | 2011-10-05T00:00:00.000000 | 2011-10-05T00:00:00.000000 |
| certa-2011-avi-548 | Vulnérabilité dans Plone et Zope | 2011-10-05T00:00:00.000000 | 2011-10-05T00:00:00.000000 |
| certa-2011-avi-547 | Vulnérabilité dans VMWare | 2011-10-05T00:00:00.000000 | 2011-10-05T00:00:00.000000 |
| certa-2011-avi-546 | Vulnérabilités dans Joomla! | 2011-10-04T00:00:00.000000 | 2011-10-04T00:00:00.000000 |
| certa-2011-avi-545 | Vulnérabilité dans Cisco Unified Communications Manager | 2011-09-30T00:00:00.000000 | 2011-09-30T00:00:00.000000 |
| certa-2011-avi-544 | Multiples vulnérabilités dans la fonction NAT de CISCO IOS | 2011-09-30T00:00:00.000000 | 2011-09-30T00:00:00.000000 |
| certa-2011-avi-543 | Vulnérabilité dans CISCO IOS | 2011-09-30T00:00:00.000000 | 2011-09-30T00:00:00.000000 |
| certa-2011-avi-542 | Vulnérabilités dans Barracuda IM Firewall | 2011-09-30T00:00:00.000000 | 2011-09-30T00:00:00.000000 |
| certa-2011-avi-541 | Vulnérabilité dans les protocoles SSL/TLS dans Microsoft Windows | 2011-09-29T00:00:00.000000 | 2011-09-29T00:00:00.000000 |
| certa-2011-avi-540 | Vulnérabilité dans les commutateurs Cisco Catalyst et les routeurs Cisco Integrated Services | 2011-09-29T00:00:00.000000 | 2011-09-29T00:00:00.000000 |
| certa-2011-avi-539 | Vulnérabilité dans les routeurs Cisco 10 000 Series | 2011-09-29T00:00:00.000000 | 2011-09-29T00:00:00.000000 |
| certa-2011-avi-538 | Multiples vulnérabilités dans Novell GroupWise | 2011-09-29T00:00:00.000000 | 2011-09-29T00:00:00.000000 |
| certa-2011-avi-537 | Multiples vulnérabilités dans les produits Mozilla | 2011-09-29T00:00:00.000000 | 2011-09-29T00:00:00.000000 |
| certa-2011-avi-536 | Vulnérabilité dans IBM WebSphere | 2011-09-29T00:00:00.000000 | 2011-09-29T00:00:00.000000 |
| certa-2011-avi-535 | Vulnérabilité dans Opera | 2011-09-23T00:00:00.000000 | 2011-09-23T00:00:00.000000 |
| certa-2011-avi-534 | Vulnérabilités dans FFmpeg | 2011-09-23T00:00:00.000000 | 2011-09-23T00:00:00.000000 |
| certa-2011-avi-533 | Multiples vulnérabilités dans SPIP | 2011-09-23T00:00:00.000000 | 2011-09-23T00:00:00.000000 |
| certa-2011-avi-532 | HP Business Service Automation Essentials | 2011-09-23T00:00:00.000000 | 2011-09-23T00:00:00.000000 |
| certa-2011-avi-506 | Vulnérabilités dans MantisBT | 2011-09-13T00:00:00.000000 | 2011-09-23T00:00:00.000000 |
| certa-2011-avi-530 | Vulnérabilité dans les produits Oracle | 2011-09-21T00:00:00.000000 | 2011-09-21T00:00:00.000000 |
| certa-2011-avi-529 | Vulnérabilité dans Cisco Identity Services Engine | 2011-09-21T00:00:00.000000 | 2011-09-21T00:00:00.000000 |
| certa-2011-avi-488 | Vulnérabilité dans les produits Cisco | 2011-09-01T00:00:00.000000 | 2011-09-21T00:00:00.000000 |
| certa-2011-avi-528 | Vulnérabilités dans Google Chrome | 2011-09-20T00:00:00.000000 | 2011-09-20T00:00:00.000000 |
| certa-2011-avi-527 | Vulnérabilités dans IBM WebSphere Commerce Enterprise | 2011-09-20T00:00:00.000000 | 2011-09-20T00:00:00.000000 |
| certa-2011-avi-526 | Vulnérabilité dans EMC Ionix | 2011-09-20T00:00:00.000000 | 2011-09-20T00:00:00.000000 |
| certa-2011-avi-505 | Vulnérabilités dans Cyrus IMAPd | 2011-09-13T00:00:00.000000 | 2011-09-20T00:00:00.000000 |