Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-2396 | List View Google Calendar <= 7.4.3 - Authenticated (Ad… |
kimipooh |
List View Google Calendar |
2026-04-14T23:26:07.293Z | 2026-04-16T13:24:58.936Z | |
| cve-2025-15470 | Eleganzo <= 1.2 - Authenticated (Subscriber+) Arbitrar… |
DesigningMedia |
Eleganzo |
2026-04-14T23:26:06.733Z | 2026-04-15T17:26:49.516Z | |
| cve-2026-39884 | MCP Server Kubernetes has Argument Injection in its po… |
Flux159 |
mcp-server-kubernetes |
2026-04-14T23:25:59.780Z | 2026-04-15T16:13:59.605Z | |
| cve-2026-39842 | OpenRemote is Vulnerable to Expression Injection |
openremote |
openremote |
2026-04-14T23:21:22.242Z | 2026-04-16T13:58:42.988Z | |
| cve-2026-39399 | NuGet Gallery: Arbitrary Blob Overwrite via Nuspec Con… |
NuGet |
NuGetGallery |
2026-04-14T23:01:38.176Z | 2026-04-15T14:42:02.662Z | |
| cve-2026-27297 | 7.8 (v3.1) | Adobe Framemaker | Integer Underflow (Wrap or Wraparou… |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:20.265Z | 2026-04-15T09:13:09.916Z |
| cve-2026-27300 | 5.5 (v3.1) | Adobe Framemaker | Access of Uninitialized Pointer (CWE-824) |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:18.661Z | 2026-04-15T17:29:10.177Z |
| cve-2026-27296 | 7.8 (v3.1) | Adobe Framemaker | Integer Underflow (Wrap or Wraparou… |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:17.850Z | 2026-04-15T09:13:10.081Z |
| cve-2026-27290 | 8.6 (v3.1) | Adobe Framemaker | Untrusted Search Path (CWE-426) |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:17.003Z | 2026-04-15T09:13:10.218Z |
| cve-2026-27298 | 7.8 (v3.1) | Adobe Framemaker | Access of Resource Using Incompatib… |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:16.131Z | 2026-04-15T09:13:10.357Z |
| cve-2026-27294 | 7.8 (v3.1) | Adobe Framemaker | Out-of-bounds Read (CWE-125) |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:15.307Z | 2026-04-15T09:13:10.507Z |
| cve-2026-27295 | 7.8 (v3.1) | Adobe Framemaker | Out-of-bounds Write (CWE-787) |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:14.461Z | 2026-04-15T09:13:10.635Z |
| cve-2026-27301 | 5.5 (v3.1) | Adobe Framemaker | Heap-based Buffer Overflow (CWE-122) |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:13.588Z | 2026-04-15T17:30:38.862Z |
| cve-2026-27299 | 6.3 (v3.1) | Adobe Framemaker | Improper Input Validation (CWE-20) |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:12.664Z | 2026-04-15T13:28:12.518Z |
| cve-2026-27293 | 7.8 (v3.1) | Adobe Framemaker | Heap-based Buffer Overflow (CWE-122) |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:11.812Z | 2026-04-15T09:13:10.769Z |
| cve-2026-27292 | 7.8 (v3.1) | Adobe Framemaker | Use After Free (CWE-416) |
Adobe |
Adobe Framemaker |
2026-04-14T22:58:10.867Z | 2026-04-15T09:13:10.924Z |
| cve-2026-39387 | BoidCMS: Local File Inclusion (LFI) leads to Remote Co… |
BoidCMS |
BoidCMS |
2026-04-14T22:56:20.935Z | 2026-04-15T13:42:26.866Z | |
| cve-2026-35589 | nanobot: Cross-Site WebSocket Hijacking in WhatsApp Br… |
HKUDS |
nanobot |
2026-04-14T22:47:32.837Z | 2026-04-15T16:14:06.128Z | |
| cve-2026-33414 | PowerShell Command Injection in Podman HyperV Machine |
containers |
podman |
2026-04-14T22:42:19.822Z | 2026-04-16T13:57:28.317Z | |
| cve-2026-40688 | 6.7 (v3.1) | An out-of-bounds write vulnerability [CWE-787] vu… |
Fortinet |
FortiWeb |
2026-04-14T22:35:15.438Z | 2026-04-16T03:55:18.342Z |
| cve-2026-35034 | Jellyfin: Potential Application DoS from excessively l… |
jellyfin |
jellyfin |
2026-04-14T22:31:44.796Z | 2026-04-15T17:48:39.733Z | |
| cve-2026-35033 | Jellyfin: Potential SSRF + Arbitrary file read via str… |
jellyfin |
jellyfin |
2026-04-14T22:28:47.558Z | 2026-04-15T13:36:26.787Z | |
| cve-2026-35032 | Jellyfin: Potential SSRF + Arbitrary file read via Liv… |
jellyfin |
jellyfin |
2026-04-14T22:25:35.729Z | 2026-04-15T20:02:29.887Z | |
| cve-2026-35031 | Jellyfin: Potential RCE via subtitle upload path trave… |
jellyfin |
jellyfin |
2026-04-14T22:18:30.565Z | 2026-04-16T13:56:06.801Z | |
| cve-2026-34457 | OAuth2 Proxy: Health Check User-Agent Matching Bypasse… |
oauth2-proxy |
oauth2-proxy |
2026-04-14T22:14:38.937Z | 2026-04-15T17:43:30.711Z | |
| cve-2026-34454 | OAuth2 Proxy: Session cookie not cleared when renderin… |
oauth2-proxy |
oauth2-proxy |
2026-04-14T22:10:37.901Z | 2026-04-15T13:30:10.300Z | |
| cve-2026-33023 | libsixel: Use-after-free in load_with_gdkpixbuf() |
saitoha |
libsixel |
2026-04-14T22:05:31.493Z | 2026-04-15T20:02:36.839Z | |
| cve-2026-33021 | libsixel: Use-after-free in sixel_encoder_encode_bytes() |
saitoha |
libsixel |
2026-04-14T21:57:22.817Z | 2026-04-16T13:54:36.177Z | |
| cve-2026-34619 | 7.7 (v3.1) | ColdFusion | Improper Limitation of a Pathname to a Re… |
Adobe |
ColdFusion |
2026-04-14T21:53:59.589Z | 2026-04-15T17:42:57.834Z |
| cve-2026-27308 | 2.4 (v3.1) | ColdFusion | Uncontrolled Resource Consumption (CWE-400) |
Adobe |
ColdFusion |
2026-04-14T21:53:58.735Z | 2026-04-15T17:31:46.019Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2018-000005 | WordPress plugin "WP Retina 2x" vulnerable to cross-site scripting | 2018-01-30T12:30+09:00 | 2018-04-11T11:53+09:00 |
| jvndb-2018-000004 | The installer of "FLET'S VIRUS CLEAR Easy Setup & Application Tool" and "FLET'S VIRUS CLEAR v6 Easy Setup & Application Tool" may insecurely load Dynamic Link Libraries | 2018-01-22T14:17+09:00 | 2018-04-11T11:44+09:00 |
| jvndb-2018-000003 | GroupSession vulnerable to open redirect | 2018-01-19T14:19+09:00 | 2018-04-11T11:37+09:00 |
| jvndb-2018-000002 | Nootka App for Android vulnerable to OS command injection | 2018-01-19T14:19+09:00 | 2018-04-11T11:46+09:00 |
| jvndb-2017-005606 | Multiple vulnerabilities in Deep Discovery Email Inspector | 2018-01-17T16:15+09:00 | 2018-01-17T16:15+09:00 |
| jvndb-2017-002290 | Trend Micro Control Manager vulnerable to SQL injection | 2018-01-17T16:15+09:00 | 2018-01-17T16:15+09:00 |
| jvndb-2017-010584 | AssetView and AssetView PLATINUM contain multiple vulnerabilities | 2018-01-12T15:32+09:00 | 2018-01-12T15:32+09:00 |
| jvndb-2017-010236 | Cross-site Scripting Vulnerability in Fujitsu NetCOBOL | 2018-01-12T15:07+09:00 | 2018-01-12T15:07+09:00 |
| jvndb-2017-004687 | Cross-site Scripting Vulnerability in Fujitsu Interstage List Works | 2018-01-12T14:58+09:00 | 2018-01-12T14:58+09:00 |
| jvndb-2018-000001 | Lhaplus vulnerable to improper verification when expanding ZIP64 archives | 2018-01-11T14:18+09:00 | 2018-04-04T12:33+09:00 |
| jvndb-2017-000252 | MQTT.js issue in handling PUBLISH packets | 2017-12-25T14:00+09:00 | 2018-04-04T14:02+09:00 |
| jvndb-2017-000251 | The installer of Content Manager Assistant for PlayStation may insecurely load Dynamic Link Libraries | 2017-12-22T15:50+09:00 | 2018-04-04T14:04+09:00 |
| jvndb-2017-000250 | The installer of Music Center for PC may insecurely load Dynamic Link Libraries | 2017-12-22T15:50+09:00 | 2018-04-04T13:53+09:00 |
| jvndb-2017-000248 | OneThird CMS vulnerable to directory traversal | 2017-12-19T13:48+09:00 | 2018-04-04T13:58+09:00 |
| jvndb-2017-000249 | Multiple vulnerabilities in H2O | 2017-12-18T15:17+09:00 | 2018-04-04T13:49+09:00 |
| jvndb-2017-010280 | Fluentd vulenrable to escape sequence injection | 2017-12-11T14:13+09:00 | 2017-12-11T14:13+09:00 |
| jvndb-2017-000247 | Qt for Android environment variables alteration | 2017-12-11T13:40+09:00 | 2018-03-14T13:44+09:00 |
| jvndb-2017-000246 | Qt for Android vulnerable to OS command injection | 2017-12-11T13:40+09:00 | 2018-03-14T13:48+09:00 |
| jvndb-2017-010275 | Cross-site Scripting Vulnerability in JP1/Service Support and JP1/Integrated Management - Service Support | 2017-12-11T11:46+09:00 | 2017-12-20T11:09+09:00 |
| jvndb-2017-000245 | The installer of The Public Certification Service for Individuals "The JPKI user's software" may insecurely load Dynamic Link Libraries | 2017-12-06T14:42+09:00 | 2018-03-14T14:07+09:00 |
| jvndb-2017-000244 | Multiple vulnerabilities in multiple Buffalo broadband routers | 2017-12-01T16:17+09:00 | 2018-03-14T14:15+09:00 |
| jvndb-2017-010043 | Cross-site Scripting Vulnerability in JP1/Operations Analytics | 2017-12-01T14:59+09:00 | 2017-12-20T11:09+09:00 |
| jvndb-2017-000243 | Movable Type plugin A-Member and A-Reserve vulnerable to SQL injection | 2017-11-30T15:50+09:00 | 2018-03-14T14:20+09:00 |
| jvndb-2017-000241 | Multiple vulnerabilities in Wireless mobile storage "Digizo ShAirDisk" PTW-WMS1 | 2017-11-30T15:45+09:00 | 2018-03-14T14:13+09:00 |
| jvndb-2017-000242 | StreamRelay.net.exe and sDNSProxy.exe vulnerable to denial-of-service (DoS) | 2017-11-29T14:54+09:00 | 2018-03-14T14:26+09:00 |
| jvndb-2017-009884 | QND Advance/Standard vulnerable to directory traversal | 2017-11-28T11:26+09:00 | 2018-03-14T14:17+09:00 |
| jvndb-2017-000240 | PWR-Q200 vulnerable to DNS cache poisoning attacks | 2017-11-22T13:51+09:00 | 2018-03-14T14:19+09:00 |
| jvndb-2017-000239 | The installer of Media Go and Music Center for PC may insecurely load Dynamic Link Libraries | 2017-11-21T15:40+09:00 | 2018-03-14T14:25+09:00 |
| jvndb-2017-000238 | Robotic appliance COCOROBO vulnerable to session management | 2017-11-16T14:03+09:00 | 2018-03-14T14:09+09:00 |
| jvndb-2017-000237 | Multiple vulnerabilities in BOOK WALKER for Windows/Mac | 2017-11-14T15:19+09:00 | 2018-03-07T13:36+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0249 | Vulnérabilité dans StormShield Network Security | 2025-03-27T00:00:00.000000 | 2025-03-27T00:00:00.000000 |
| certfr-2025-avi-0248 | Multiples vulnérabilités dans GitLab | 2025-03-27T00:00:00.000000 | 2025-03-27T00:00:00.000000 |
| certfr-2025-avi-0247 | Vulnérabilité dans Microsoft Edge | 2025-03-27T00:00:00.000000 | 2025-03-27T00:00:00.000000 |
| certfr-2025-avi-0246 | Vulnérabilité dans Mitel MiContact Center Business | 2025-03-27T00:00:00.000000 | 2025-03-27T00:00:00.000000 |
| certfr-2025-avi-0245 | Multiples vulnérabilités dans les produits Splunk | 2025-03-27T00:00:00.000000 | 2025-03-27T00:00:00.000000 |
| certfr-2025-avi-0244 | Vulnérabilité dans Exim | 2025-03-27T00:00:00.000000 | 2025-03-27T00:00:00.000000 |
| certfr-2025-avi-0243 | Multiples vulnérabilités dans VMware Tanzu Gemfire | 2025-03-27T00:00:00.000000 | 2025-03-27T00:00:00.000000 |
| certfr-2025-avi-0242 | Multiples vulnérabilités dans Moodle | 2025-03-26T00:00:00.000000 | 2025-03-26T00:00:00.000000 |
| certfr-2025-avi-0241 | Vulnérabilité dans Google Chrome | 2025-03-26T00:00:00.000000 | 2025-03-26T00:00:00.000000 |
| certfr-2025-avi-0240 | Vulnérabilité dans les produits VMware | 2025-03-26T00:00:00.000000 | 2025-03-26T00:00:00.000000 |
| certfr-2025-avi-0239 | Multiples vulnérabilités dans Microsoft Azure Kubernetes Service | 2025-03-25T00:00:00.000000 | 2025-03-25T00:00:00.000000 |
| certfr-2025-avi-0238 | Multiples vulnérabilités dans Laravel | 2025-03-25T00:00:00.000000 | 2025-03-25T00:00:00.000000 |
| certfr-2025-avi-0237 | Multiples vulnérabilités dans Microsoft Edge | 2025-03-24T00:00:00.000000 | 2025-03-24T00:00:00.000000 |
| certfr-2025-avi-0236 | Vulnérabilité dans Qnap NAKIVO Backup & Replication | 2025-03-24T00:00:00.000000 | 2025-03-24T00:00:00.000000 |
| certfr-2025-avi-0235 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0234 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0233 | Multiples vulnérabilités dans les produits IBM | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0232 | Vulnérabilité dans Liferay | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0231 | Vulnérabilité dans Microsoft Office | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0230 | Vulnérabilité dans Tenable Nessus Agent | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0229 | Vulnérabilité dans Veeam Backup & Replication | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0228 | Multiples vulnérabilités dans Spring Security | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0227 | Vulnérabilité dans Liferay | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0226 | Vulnérabilité dans Google Chrome | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0225 | Vulnérabilité dans Drupal | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0224 | Multiples vulnérabilités dans les produits Synology | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0223 | Multiples vulnérabilités dans Suricata | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0222 | Vulnérabilité dans MongoDB C Driver | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0221 | Multiples vulnérabilités dans HPE Aruba Networking AOS-CX | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0220 | Vulnérabilité dans Mattermost Server | 2025-03-19T00:00:00.000000 | 2025-04-17T00:00:00.000000 |