Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-19758 | dromara lamp-cloud chunk-check endpoint FileChunkContr… |
dromara |
lamp-cloud |
2026-08-13T23:30:09.251Z | 2026-08-18T13:39:37.959Z | |
| cve-2026-19757 | Dromara lamp-cloud File-Upload Controller FileAnyoneCo… |
Dromara |
lamp-cloud |
2026-08-13T23:15:09.882Z | 2026-08-14T15:01:30.989Z | |
| cve-2026-19756 | Dromara lamp-cloud Code Generator DefGenProjectControl… |
Dromara |
lamp-cloud |
2026-08-13T22:30:10.915Z | 2026-08-18T01:47:18.235Z | |
| cve-2026-19753 | Model Context Protocol mcp-rdf-explorer MCP Server ser… |
Model Context Protocol |
mcp-rdf-explorer |
2026-08-13T22:15:11.712Z | 2026-08-14T15:54:55.170Z | |
| cve-2026-73305 | Budibase: Privilege escalation via public role assignm… |
Budibase |
budibase |
2026-08-13T22:05:02.972Z | 2026-08-18T01:46:32.727Z | |
| cve-2026-73304 | Budibase: SSO OAuth2 Token Leakage via User Metadata E… |
Budibase |
budibase |
2026-08-13T22:05:00.355Z | 2026-08-14T15:09:18.395Z | |
| cve-2026-73408 | Budibase: MySQL DESCRIBE Backtick Injection via multip… |
Budibase |
budibase |
2026-08-13T22:04:53.979Z | 2026-08-14T18:06:29.345Z | |
| cve-2026-73302 | Budibase: OIDC SSO account takeover: incoming identity… |
Budibase |
budibase |
2026-08-13T22:04:50.179Z | 2026-08-14T16:10:42.639Z | |
| cve-2026-73489 | Russh: Post-auth remote panic via pty-req with more th… |
Eugeny |
russh |
2026-08-13T22:04:44.470Z | 2026-08-17T19:50:33.126Z | |
| cve-2026-73421 | NextAuth.js: Configuration errors can cause existence-… |
nextauthjs |
next-auth |
2026-08-13T22:04:36.985Z | 2026-08-18T01:45:41.913Z | |
| cve-2026-73417 | JupyterLab: Cross-site scripting (XSS) via crafted set… |
jupyterlab |
jupyterlab |
2026-08-13T22:04:31.709Z | 2026-08-14T16:06:29.787Z | |
| cve-2026-73416 | jupyterlab: PyPI extension blocklist package-name cano… |
jupyterlab |
jupyterlab |
2026-08-13T22:04:26.603Z | 2026-08-17T17:17:59.508Z | |
| cve-2026-73428 | Trix: Stored XSS via HTMLParser attribute injection on paste |
basecamp |
trix |
2026-08-13T22:04:19.121Z | 2026-08-14T18:06:36.864Z | |
| cve-2026-73420 | NextAuth.js: Email normalizer validates the address be… |
nextauthjs |
next-auth |
2026-08-13T22:04:15.414Z | 2026-08-14T15:06:00.594Z | |
| cve-2026-73843 | OpenChoreo: Unauthenticated access to data-plane opera… |
openchoreo |
openchoreo |
2026-08-13T22:02:41.363Z | 2026-08-14T18:06:50.045Z | |
| cve-2026-19752 | EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts p… |
EnzoVezzaro |
mcp-dominican-layer |
2026-08-13T22:00:11.477Z | 2026-08-14T15:03:28.224Z | |
| cve-2026-73842 | OpenChoreo: cluster-gateway internal proxy performs no… |
openchoreo |
openchoreo |
2026-08-13T21:59:24.390Z | 2026-08-18T01:44:27.659Z | |
| cve-2026-56860 | N/A | Avoid quadratic complexity in resolvePath in net/url |
Go standard library |
net/url |
2026-08-13T21:58:53.731Z | 2026-08-14T16:14:39.166Z |
| cve-2026-56864 | N/A | Ignore unrelated, unauthenticated hashes in Lookup in … |
Go toolchain |
cmd/go |
2026-08-13T21:58:53.605Z | 2026-08-14T16:16:42.248Z |
| cve-2026-56865 | N/A | Fix transparency log tile verification bypass in golan… |
Go toolchain |
cmd/go |
2026-08-13T21:58:53.475Z | 2026-08-14T15:34:17.235Z |
| cve-2026-56858 | N/A | Fix Javascript regexp context tracking in html/template |
Go standard library |
html/template |
2026-08-13T21:58:53.354Z | 2026-08-14T15:32:29.852Z |
| cve-2026-56862 | N/A | Limit handshake messages we are willing to accept post… |
Go standard library |
crypto/tls |
2026-08-13T21:58:53.216Z | 2026-08-14T15:29:41.741Z |
| cve-2026-56853 | N/A | Apply ReadHeaderTimeout when doing unencrypted HTTP/2 … |
Go standard library |
net/http |
2026-08-13T21:58:53.092Z | 2026-08-14T15:23:18.680Z |
| cve-2026-56859 | N/A | Add recursion depth guard during decode in encoding/xml |
Go standard library |
encoding/xml |
2026-08-13T21:58:52.959Z | 2026-08-14T15:21:46.218Z |
| cve-2026-33818 | N/A | Enforce maximum recursion depth in encoding/asn1 |
Go standard library |
encoding/asn1 |
2026-08-13T21:58:52.821Z | 2026-09-10T16:34:27.711Z |
| cve-2026-73841 | OpenChoreo: Cross-project command execution and wirelo… |
openchoreo |
openchoreo |
2026-08-13T21:56:13.057Z | 2026-09-02T15:16:54.694Z | |
| cve-2026-72857 | 8.3 (v4.0) 7.7 (v3.1) | Budibase before 3.40.0 Credential Exposure via STRING Fields |
Budibase |
budibase |
2026-08-13T21:54:45.984Z | 2026-08-14T16:12:55.091Z |
| cve-2026-72856 | 8.6 (v4.0) 8.1 (v3.1) | Budibase before 3.40.0 Authentication Bypass via Tenan… |
Budibase |
budibase |
2026-08-13T21:54:45.304Z | 2026-08-17T16:09:39.599Z |
| cve-2026-72855 | 8.4 (v4.0) 8.5 (v3.1) | Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI … |
budibase |
server |
2026-08-13T21:54:44.625Z | 2026-08-14T16:21:40.818Z |
| cve-2026-72853 | 8.8 (v4.0) 7.6 (v3.1) | Budibase before 3.40.0 SQL Injection via Oracle connector |
Budibase |
budibase |
2026-08-13T21:54:43.945Z | 2026-08-18T01:43:22.355Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certa-2009-avi-456 | Vulnérabilité dans ProFTPD | 2009-10-26T00:00:00.000000 | 2009-10-26T00:00:00.000000 |
| certa-2009-avi-455 | Vulnérabilité dans IBM OS/400 HTTP Server | 2009-10-26T00:00:00.000000 | 2009-10-26T00:00:00.000000 |
| certa-2009-avi-454 | Multiples vulnérabilités dans TYPO3 | 2009-10-26T00:00:00.000000 | 2009-10-26T00:00:00.000000 |
| certa-2009-avi-453 | Multiples vulnérabilités dans WordPress | 2009-10-21T00:00:00.000000 | 2009-10-21T00:00:00.000000 |
| certa-2009-avi-452 | Multiples vulnérabilités des produits Oracle | 2009-10-21T00:00:00.000000 | 2009-10-21T00:00:00.000000 |
| certa-2009-avi-451 | Multiples vulnérabiltés dans les produits VMware | 2009-10-20T00:00:00.000000 | 2009-10-20T00:00:00.000000 |
| certa-2009-avi-450 | Vulnérabilité dans ZFS pour Sun Solaris et Sun OpenSolaris | 2009-10-16T00:00:00.000000 | 2009-10-16T00:00:00.000000 |
| certa-2009-avi-449 | Multiples vulnérabilités dans Cisco Unified Presence | 2009-10-16T00:00:00.000000 | 2009-10-16T00:00:00.000000 |
| certa-2009-avi-448 | Vulnérabilités dans Xpdf et dérivés | 2009-10-16T00:00:00.000000 | 2010-04-07T00:00:00.000000 |
| certa-2009-avi-447 | Vulnérabilités dans phpMyAdmin | 2009-10-16T00:00:00.000000 | 2009-10-16T00:00:00.000000 |
| certa-2009-avi-446 | Vulnérabilités dans Symantec SecurityExpressions | 2009-10-16T00:00:00.000000 | 2009-10-16T00:00:00.000000 |
| certa-2009-avi-445 | Multiples vulnérabilités dans Adobe Reader et Acrobat | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-444 | Multiples vulnérabilités dans Microsoft Windows Media Runtime | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-443 | Multiples vulnérabilités de SMBv2 dans Microsoft Windows | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-442 | Multiples vulnérabilités des produits Microsoft utilisant GDI+ | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-441 | Multiples vulnérabilités dans Microsoft .NET Common Language Runtime | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-440 | Multiples vulnérabilités dans Microsoft ATL ActiveX controls pour Microsoft Office | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-439 | Vulnérabilité dans Local Security Authority Subsystem Service | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-438 | Vulnérabilité dans Microsoft Windows | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-437 | Vulnérabilité dans le service d'indexation de Windows | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-436 | Vulnérabilités dans Windows CryptoAPI | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-435 | Vulnérabilité des composants ActiveX utilisant la bibliothèque ATL | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-434 | Multiples vulnérabilités de Microsoft Internet Explorer | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-433 | Vulnérabilités du serveur FTP de Microsoft IIS | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-432 | Vulnérabilité dans Microsoft Windows Media Player | 2009-10-14T00:00:00.000000 | 2009-10-14T00:00:00.000000 |
| certa-2009-avi-431 | Vulnérabilités dans CA Anti-Virus | 2009-10-12T00:00:00.000000 | 2009-10-12T00:00:00.000000 |
| certa-2009-avi-430 | Vulnérabilité des systèmes IBM AIX et VIOS | 2009-10-09T00:00:00.000000 | 2009-10-09T00:00:00.000000 |
| certa-2009-avi-429 | Vulnérabilité dans Sun Solaris clsetup | 2009-10-08T00:00:00.000000 | 2009-10-08T00:00:00.000000 |
| certa-2009-avi-428 | Multiples vulnérabilités dans Kerberos sous HP-UX | 2009-10-08T00:00:00.000000 | 2009-10-08T00:00:00.000000 |
| certa-2009-avi-427 | Vulnérabilité dans HP Remote Graphics Software | 2009-10-07T00:00:00.000000 | 2009-10-07T00:00:00.000000 |