Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-54389 | 6.7 (v4.0) 5.5 (v3.1) | Ghidra < 12.1.3 PDB Parser Uncontrolled Heap Growth Do… |
NationalSecurityAgency |
ghidra |
2026-08-20T22:02:30.459Z | 2026-08-25T15:34:30.502Z |
| cve-2026-56706 | 6.1 (v4.0) 6.8 (v3.1) | Adminer before 5.4.3 CSRF Token Secret Recovery via XO… |
vrana |
adminer |
2026-08-25T01:30:05.474Z | 2026-08-25T15:34:21.769Z |
| cve-2026-49217 | Mailu missing authentication on PATCH /api/v1/token/<i… |
Mailu |
Mailu |
2026-08-20T22:01:41.588Z | 2026-08-25T15:33:28.286Z | |
| cve-2026-79660 | 6.9 (v4.0) 5.3 (v3.1) | Ech0 before 4.7.3 Email Disclosure via Public API |
lin-snow |
Ech0 |
2026-08-25T11:33:24.692Z | 2026-08-25T15:32:51.102Z |
| cve-2026-17060 | 8.1 (v3.1) | Vulnerabilities in IBM AIX and PowerVM VIOS |
IBM |
AIX |
2026-08-20T21:51:22.675Z | 2026-08-25T15:32:40.001Z |
| cve-2026-16964 | 6.5 (v3.1) | Vulnerabilities in IBM AIX and PowerVM VIOS |
IBM |
AIX |
2026-08-20T21:45:53.947Z | 2026-08-25T15:31:57.353Z |
| cve-2026-79665 | 8.7 (v4.0) 8.8 (v3.1) | Ech0 before 4.5.1 Authorization Bypass via Session Tokens |
lin-snow |
Ech0 |
2026-08-25T11:33:28.065Z | 2026-08-25T15:31:13.613Z |
| cve-2026-54505 | TREK: Stored cross-user HTML injection via trip title … |
mauriceboe |
TREK |
2026-08-20T21:44:50.337Z | 2026-08-25T15:30:48.581Z | |
| cve-2026-34967 | 5.3 (v4.0) 5.4 (v3.1) | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary F… |
vrana |
adminer |
2026-08-25T01:29:59.097Z | 2026-08-25T15:29:49.378Z |
| cve-2026-34968 | 7.2 (v4.0) 8.1 (v3.1) | Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop |
vrana |
adminer |
2026-08-25T01:29:59.711Z | 2026-08-25T15:29:34.632Z |
| cve-2026-66621 | 7.1 (v3.1) | WordPress Ultimate Dashboard Pro plugin <= 3.11.2 - Cr… |
MapSteps UG |
Ultimate Dashboard Pro |
2026-08-18T13:59:35.306Z | 2026-08-25T15:29:26.513Z |
| cve-2026-55765 | CloudNativePG: Cleartext role passwords recorded in pg… |
cloudnative-pg |
cloudnative-pg |
2026-08-20T21:38:47.952Z | 2026-08-25T15:29:20.264Z | |
| cve-2026-56705 | 9.3 (v4.0) 9.8 (v3.1) | Adminer before 5.4.3 Remote Code Execution via MSSQL P… |
vrana |
adminer |
2026-08-25T01:30:03.759Z | 2026-08-25T15:29:15.538Z |
| cve-2026-56710 | 9.3 (v4.0) 9.8 (v3.1) | Grav Login Plugin before 1.0.16 Privilege Escalation v… |
getgrav |
grav |
2026-08-25T01:30:11.042Z | 2026-08-25T15:28:35.494Z |
| cve-2026-72860 | 8.5 (v3.1) 6.3 (v4.0) | 9router Server-Side Request Forgery via /api/provider-… |
decolua |
9router |
2026-08-20T21:35:14.677Z | 2026-08-25T15:27:22.100Z |
| cve-2026-46355 | BigBlueButton: Unauthenticated Session Hijack via Expo… |
bigbluebutton |
bigbluebutton |
2026-08-20T21:34:40.529Z | 2026-08-25T15:26:14.221Z | |
| cve-2026-70651 | libvips: Possible integer overflow when reading multi-… |
libvips |
libvips |
2026-08-20T21:05:38.765Z | 2026-08-25T15:25:19.181Z | |
| cve-2026-78677 | 8.7 (v4.0) 7.5 (v3.1) | GitPython before 3.1.59 Path Traversal via separate-git-dir |
gitpython-developers |
GitPython |
2026-08-25T01:30:34.719Z | 2026-08-25T15:24:57.573Z |
| cve-2026-78682 | 8.7 (v4.0) 7.5 (v3.1) | NLTK before 3.10.3 SSRF Protection Bypass via Proxy |
nltk |
nltk |
2026-08-25T01:30:38.486Z | 2026-08-25T15:23:57.389Z |
| cve-2026-71485 | Centrifugo: Client-forgeable headers emulation lets an… |
centrifugal |
centrifugo |
2026-08-20T21:01:00.931Z | 2026-08-25T15:23:47.006Z | |
| cve-2026-78685 | 8.8 (v3.1) 8.6 (v4.0) | Le-yan|Medical Practice Management System - Remote Cod… |
Le-yan |
Medical Practice Management System |
2026-08-25T02:05:09.515Z | 2026-08-25T15:23:01.167Z |
| cve-2026-61241 | Vulnerability in the Oracle Internet Directory pr… |
Oracle Corporation |
Oracle Internet Directory |
2026-08-18T20:59:54.183Z | 2026-08-25T15:22:47.567Z | |
| cve-2026-70912 | Vulnerability in the Oracle Hyperion Financial Ma… |
Oracle Corporation |
Oracle Hyperion Financial Management |
2026-08-18T21:02:29.058Z | 2026-08-25T15:22:01.788Z | |
| cve-2026-53585 | libgit2: Unbounded Memory Allocation via Delta Object … |
libgit2 |
libgit2 |
2026-08-20T18:37:44.115Z | 2026-08-25T15:21:43.819Z | |
| cve-2026-75982 | LearnPress <= 4.4.4 - Missing Authorization to Authent… |
thimpress |
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses |
2026-08-25T02:26:48.639Z | 2026-08-25T15:20:51.772Z | |
| cve-2026-66001 | Frappe: Improper Authorization in OAuth2 Consent Endpoint |
frappe |
frappe |
2026-08-20T18:27:32.056Z | 2026-08-25T15:20:17.550Z | |
| cve-2026-75930 | FundEngine <= 1.8.1 - Missing Authorization to Authent… |
roxnor |
FundEngine – Donation and Crowdfunding Platform |
2026-08-25T03:27:05.464Z | 2026-08-25T15:19:49.192Z | |
| cve-2026-78683 | 9.4 (v4.0) 9.6 (v3.1) | NLTK before 3.10.0 Remote Code Execution via Unsafe Pi… |
nltk |
nltk |
2026-08-25T01:30:39.451Z | 2026-08-25T15:19:32.286Z |
| cve-2026-15023 | Events Manager <= 7.4.0 - Authenticated (Contributor+)… |
netweblogic |
Events Manager – Calendar, Bookings, Tickets, and more! |
2026-08-25T01:26:44.361Z | 2026-08-25T15:18:18.613Z | |
| cve-2026-72852 | 8.5 (v4.0) 7.8 (v3.1) | darknet Integer Overflow in Convolutional Layer Buffer… |
hank-ai |
darknet |
2026-08-20T18:19:23.554Z | 2026-08-25T15:18:13.753Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certa-2011-avi-416 | Vulnérabilités dans Samba (SWAT) | 2011-07-28T00:00:00.000000 | 2011-08-23T00:00:00.000000 |
| certa-2011-avi-316 | Vulnérabilité dans Dovecot | 2011-05-26T00:00:00.000000 | 2011-08-23T00:00:00.000000 |
| certa-2011-avi-463 | Vulnérabilité dans IBM Websphere Service Registry and Repository | 2011-08-22T00:00:00.000000 | 2011-08-22T00:00:00.000000 |
| certa-2011-avi-462 | Vulnérabilité dans EMC RSA Adaptive Authentication On-Premise | 2011-08-22T00:00:00.000000 | 2011-08-22T00:00:00.000000 |
| certa-2011-avi-460 | Vulnérabilités dans OTRS | 2011-08-22T00:00:00.000000 | 2011-08-22T00:00:00.000000 |
| certa-2011-avi-458 | Multiples vulnérabilités dans RealPlayer | 2011-08-18T00:00:00.000000 | 2011-08-18T00:00:00.000000 |
| certa-2011-avi-452 | Vulnérabilités dans ISC DHCP | 2011-08-11T00:00:00.000000 | 2011-08-18T00:00:00.000000 |
| certa-2011-avi-429 | Vulnérabilités dans Apple QuickTime | 2011-08-04T00:00:00.000000 | 2011-08-18T00:00:00.000000 |
| certa-2011-avi-456 | Vulnérabilité dans CA ARCserve D2D | 2011-08-17T00:00:00.000000 | 2011-08-17T00:00:00.000000 |
| certa-2011-avi-455 | Vulnérabilités dans Symantec Veritas Enterprise Administrator | 2011-08-16T00:00:00.000000 | 2011-08-16T00:00:00.000000 |
| certa-2011-avi-454 | Vulnérabilités dans Apache Tomcat | 2011-08-16T00:00:00.000000 | 2011-08-16T00:00:00.000000 |
| certa-2011-avi-453 | Vulnérabilités dans McAfee SaaS Endpoint Protection | 2011-08-12T00:00:00.000000 | 2011-08-12T00:00:00.000000 |
| certa-2011-avi-451 | Vulnérabilités dans Symantec Endpoint Protection Manager | 2011-08-11T00:00:00.000000 | 2011-08-11T00:00:00.000000 |
| certa-2011-avi-450 | Multiples vulnérabilités dans BlackBerry Enterprise Server | 2011-08-11T00:00:00.000000 | 2011-08-11T00:00:00.000000 |
| certa-2011-avi-449 | Vulnérabilité dans Adobe Photoshop CS5 | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-448 | Multiples vulnérabilités dans Adobe Flash Player | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-447 | Vulnérabilité dans Adobe Flash Media Server | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-446 | Multiples vulnérabilités dans Adobe Shockwave Player | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-445 | Vulnérabilité dans Microsoft .NET Framework | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-444 | Vulnérabilité dans le noyau Windows | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-443 | Vulnérabilité dans Microsoft Report Viewer | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-442 | Vulnérabilité dans les contrôles Chart ASP.NET de Microsoft | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-441 | Vulnérabilité dans la protocole RDP de Microsoft Windows | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-440 | Vulnérabilités dans la pile TCP/IP de Microsoft Windows | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-439 | Vulnérabilité dans le processus CSRSS de Microsoft Windows | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-438 | Vulnérabilité dans le pilote NDISTAPI du service d'accès à distance de Windows | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-437 | Vulnérabilité dans le service d'accès au bureau à distance Windows par le Web | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-436 | Vulnérabilités dans Microsoft Visio | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-435 | Vulnérabilité dans Data Access Components | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |
| certa-2011-avi-434 | Vulnérabilités dans le serveur Windows DNS | 2011-08-10T00:00:00.000000 | 2011-08-10T00:00:00.000000 |