Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-47893 | N/A | Spring Framework Request Headers Included in Exception… |
Spring |
Spring Framework |
2026-08-27T05:21:41.124Z | 2026-08-28T19:12:43.970Z |
| cve-2026-47892 | N/A | Spring Framework Header Predicate Bypass in WebFlux Fu… |
Spring |
Spring Framework |
2026-08-27T05:21:40.168Z | 2026-08-28T19:11:09.411Z |
| cve-2026-47891 | N/A | Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder |
Spring |
Spring Framework |
2026-08-27T05:21:39.288Z | 2026-08-27T14:52:30.491Z |
| cve-2026-47890 | N/A | Spring Framework Server Sent Event stream corruption w… |
Spring |
Spring Framework |
2026-08-27T05:21:38.260Z | 2026-08-27T14:53:37.162Z |
| cve-2026-47889 | N/A | Spring Framework sameSite Attribute Dropped in JettyCo… |
Spring |
Spring Framework |
2026-08-27T05:21:37.305Z | 2026-08-27T14:57:20.579Z |
| cve-2026-47888 | N/A | Spring Framework Memory Leak via SETUP Frame in RSocke… |
Spring |
Spring Framework |
2026-08-27T05:21:36.474Z | 2026-08-27T14:58:08.080Z |
| cve-2026-47887 | N/A | Spring Framework Open Redirect in UrlFileNameViewController |
Spring |
Spring Framework |
2026-08-27T05:21:35.512Z | 2026-08-27T14:59:08.962Z |
| cve-2026-47886 | N/A | Spring Framework Denial of Service via Unbounded Expon… |
Spring |
Spring Framework |
2026-08-27T05:21:34.631Z | 2026-08-27T15:00:12.222Z |
| cve-2026-47885 | N/A | Spring Framework maxPartSize Ignored in PartEventHttpM… |
Spring |
Spring Framework |
2026-08-27T05:21:33.775Z | 2026-08-27T15:01:09.141Z |
| cve-2026-47884 | N/A | Spring Framework Improper Path Limitation in XsltView |
Spring |
Spring Framework |
2026-08-27T05:21:32.920Z | 2026-08-27T15:03:29.767Z |
| cve-2026-47883 | N/A | Spring Framework Open Redirect in UrlHandlerFilter |
Spring |
Spring Framework |
2026-08-27T05:21:32.084Z | 2026-08-27T15:02:25.563Z |
| cve-2026-59278 | 6.5 (v3.1) | In Spring for Apache Kafka, SSRF via DNS resolution tr… |
Spring |
Spring for Apache Kafka |
2026-08-27T05:20:36.841Z | 2026-08-27T12:37:42.585Z |
| cve-2026-59275 | 6.6 (v3.1) | Remote JVM termination: nested-array Java deserializat… |
Spring |
Spring AMQP |
2026-08-27T05:20:36.022Z | 2026-08-28T03:55:28.836Z |
| cve-2026-59274 | 6.5 (v3.1) | Unbounded decompression in UnZipTransformer enables zi… |
Spring |
Spring Integration |
2026-08-27T05:20:35.041Z | 2026-08-27T14:13:56.857Z |
| cve-2026-59271 | 5.3 (v3.1) | Admin password disclosed in BrokerNotAliveException message |
Spring |
Spring AMQP |
2026-08-27T05:20:34.133Z | 2026-08-27T14:15:39.893Z |
| cve-2026-59270 | 9.4 (v3.1) | Spring Security embedded UnboundID LDAP server exposes… |
Spring |
Spring Security |
2026-08-27T05:20:33.210Z | 2026-08-28T16:52:28.234Z |
| cve-2026-47894 | 4.9 (v3.1) | Spring Cloud Config Server Native Environment Reposito… |
Spring |
Spring Cloud Config |
2026-08-27T05:20:32.282Z | 2026-08-27T14:18:07.039Z |
| cve-2026-47881 | 5.9 (v3.1) | Denial of Service in Spring Batch FlatFileItemReader v… |
Spring |
Spring Batch |
2026-08-27T05:20:26.323Z | 2026-08-27T14:21:14.631Z |
| cve-2026-47880 | 5.4 (v3.1) | DefaultJmsHeaderMapper copies all JMS user properties … |
Spring |
Spring Integration |
2026-08-27T05:20:25.359Z | 2026-08-27T15:06:37.711Z |
| cve-2026-47879 | 7.7 (v3.1) | Spring Cloud Gateway SSRF and native file access with gRPC |
Spring |
Spring Cloud Gateway |
2026-08-27T05:20:24.412Z | 2026-08-27T14:28:03.681Z |
| cve-2026-47878 | 5.6 (v3.1) | Unsafe Java deserialization in DefaultExecutionContext… |
Spring |
Spring Batch |
2026-08-27T05:20:23.462Z | 2026-08-27T14:32:28.405Z |
| cve-2026-47877 | 8.2 (v3.1) | Spring Security Authorization Server Default Consent P… |
Spring |
Spring Security |
2026-08-27T05:20:22.523Z | 2026-08-27T14:43:11.105Z |
| cve-2026-47875 | 5.6 (v3.1) | JobParameterDeserializer bypasses the trusted-type allowlist |
Spring |
Spring Batch |
2026-08-27T05:20:21.578Z | 2026-08-28T16:52:00.046Z |
| cve-2026-47864 | 6.4 (v3.1) | Unsafe Java deserialization in SerializingHttpMessageC… |
Spring |
Spring Integration |
2026-08-27T05:06:24.914Z | 2026-08-28T16:51:52.633Z |
| cve-2026-47849 | 7.1 (v3.1) | Spring Data REST allows mutation of identifier and ver… |
Spring |
Spring Data REST |
2026-08-27T05:06:23.970Z | 2026-08-27T13:04:25.615Z |
| cve-2026-16895 | 5.1 (v4.0) | Authentication Bypass in Metasploit JSON-RPC Service W… |
Rapid7 |
Metasploit-framework |
2026-08-27T03:14:21.055Z | 2026-08-27T13:09:40.173Z |
| cve-2026-81491 | boxpositron with-context-mcp index.ts project_folder p… |
boxpositron |
with-context-mcp |
2026-08-27T02:15:09.570Z | 2026-08-27T14:44:51.974Z | |
| cve-2026-19398 | 6.8 (v4.0) | “unsupported-when-assigned.” An out-of-bounds wri… |
ASUS |
FA507NV |
2026-08-27T02:00:16.449Z | 2026-08-27T14:50:36.251Z |
| cve-2026-81486 | bsmi021 mcp-file-context-server Path Resolution index.… |
bsmi021 |
mcp-file-context-server |
2026-08-27T01:30:12.358Z | 2026-08-27T14:42:26.358Z | |
| cve-2026-81485 | danielpopamd linkedin-ads-mcp Media Upload campaign-ma… |
danielpopamd |
linkedin-ads-mcp |
2026-08-27T01:00:14.610Z | 2026-08-27T14:32:12.639Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2018-000055 | Multiple vulnerabilities in baserCMS | 2018-05-22T14:53+09:00 | 2019-12-27T18:10+09:00 |
| jvndb-2018-000053 | Multiple vulnerabilities in Cybozu Office | 2018-05-22T14:30+09:00 | 2018-08-30T16:03+09:00 |
| jvndb-2018-000052 | Nessus vulnerable to cross-site scripting | 2018-05-21T13:39+09:00 | 2018-08-30T13:47+09:00 |
| jvndb-2018-000049 | Multiple Microsoft Windows applications and installers may insecurely load Dynamic Link Libraries | 2018-05-17T15:18+09:00 | 2019-07-05T16:40+09:00 |
| jvndb-2018-000051 | The installer of Visual C++ Redistributable may insecurely load Dynamic Link Libraries | 2018-05-17T14:57+09:00 | 2019-07-05T16:41+09:00 |
| jvndb-2018-000050 | Self-Extracting Archive files created by IExpress may insecurely load Dynamic Link Libraries | 2018-05-17T14:57+09:00 | 2018-08-21T16:40+09:00 |
| jvndb-2018-000048 | KINEPASS App fails to verify SSL server certificates | 2018-05-11T14:34+09:00 | 2018-08-30T15:01+09:00 |
| jvndb-2018-000047 | IIJ SmartKey App for Android vulnerable to authentication bypass | 2018-05-11T14:34+09:00 | 2019-12-27T18:11+09:00 |
| jvndb-2018-003030 | Access Control Vulnerability in Hitachi Infrastructure Analytics Advisor | 2018-05-10T15:30+09:00 | 2018-07-31T12:12+09:00 |
| jvndb-2018-000045 | Multiple vulnerabilities in WordPress plugin "Ultimate Member" | 2018-05-10T13:44+09:00 | 2018-08-30T18:11+09:00 |
| jvndb-2018-000044 | RT-AC68U vulnerable to cross-site scripting | 2018-05-09T15:38+09:00 | 2018-08-30T12:20+09:00 |
| jvndb-2018-000043 | RT-AC1200HP vulnerable to cross-site scripting | 2018-05-09T15:37+09:00 | 2018-08-30T12:15+09:00 |
| jvndb-2018-000042 | RT-AC87U vulnerable to cross-site scripting | 2018-05-09T15:37+09:00 | 2018-08-30T12:32+09:00 |
| jvndb-2018-000041 | The installers of multiple CELSYS,Inc. software may insecurely load Dynamic Link Libraries | 2018-04-27T15:19+09:00 | 2018-08-30T14:12+09:00 |
| jvndb-2018-000040 | WordPress plugin "Open Graph for Facebook, Google+ and Twitter Card Tags" vulnerable to cross-site scripting | 2018-04-27T15:01+09:00 | 2018-08-30T13:54+09:00 |
| jvndb-2018-000039 | WordPress plugin "PixelYourSite" vulnerable to cross-site scripting | 2018-04-27T14:24+09:00 | 2018-08-30T11:55+09:00 |
| jvndb-2018-000038 | WordPress plugin "WP Google Map Plugin" vulnerable to cross-site scripting | 2018-04-27T14:15+09:00 | 2018-08-30T12:00+09:00 |
| jvndb-2018-000037 | WordPress plugin "Events Manager" vulnerable to cross-site scripting | 2018-04-27T14:00+09:00 | 2018-08-30T11:48+09:00 |
| jvndb-2018-000036 | Joruri Gw vulnerable to arbitrary file upload | 2018-04-26T15:19+09:00 | 2018-08-30T14:02+09:00 |
| jvndb-2018-000035 | EC-CUBE vulnerable to session fixation | 2018-04-17T13:39+09:00 | 2018-08-22T17:42+09:00 |
| jvndb-2018-000030 | Installer of SoundEngine Free may insecurely load Dynamic Link Libraries | 2018-04-13T13:52+09:00 | 2018-06-14T14:16+09:00 |
| jvndb-2018-000034 | Tenable Appliance vulnerable to cross-site scripting | 2018-04-12T14:33+09:00 | 2018-06-14T14:20+09:00 |
| jvndb-2018-000033 | The installer of PhishWall Client Internet Explorer edition may insecurely load Dynamic Link Libraries | 2018-04-12T14:27+09:00 | 2018-04-12T14:27+09:00 |
| jvndb-2018-000032 | Hatena Bookmark App for iOS contains an address bar spoofing vulnerability | 2018-04-10T13:39+09:00 | 2018-04-10T13:39+09:00 |
| jvndb-2018-000031 | Multiple vulnerabilities in Cybozu Garoon | 2018-04-09T14:27+09:00 | 2018-06-14T14:33+09:00 |
| jvndb-2018-002257 | DoS Vulnerability in JP1/ServerConductor/Deployment Manager and Hitachi Compute Systems Manager | 2018-04-05T10:22+09:00 | 2018-04-10T10:55+09:00 |
| jvndb-2018-000029 | Safari vulnerable to script injection | 2018-03-30T13:39+09:00 | 2018-06-14T14:02+09:00 |
| jvndb-2018-000028 | LXR vulnerable to OS command injection | 2018-03-29T14:00+09:00 | 2018-06-14T14:08+09:00 |
| jvndb-2018-000027 | Multiple vulnerabilities in WZR-1750DHP2 | 2018-03-29T13:52+09:00 | 2018-06-14T14:12+09:00 |
| jvndb-2018-000026 | iRemoconWiFi App for Android fails to verify SSL server certificates | 2018-03-27T13:40+09:00 | 2018-06-14T14:29+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0829 | Vulnérabilité dans Apereo CAS | 2025-09-29T00:00:00.000000 | 2025-09-29T00:00:00.000000 |
| certfr-2025-avi-0828 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-09-26T00:00:00.000000 | 2025-09-26T00:00:00.000000 |
| certfr-2025-avi-0827 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-09-26T00:00:00.000000 | 2025-09-26T00:00:00.000000 |
| certfr-2025-avi-0826 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-09-26T00:00:00.000000 | 2025-09-26T00:00:00.000000 |
| certfr-2025-avi-0825 | Multiples vulnérabilités dans le noyau Linux de Debian | 2025-09-26T00:00:00.000000 | 2025-09-26T00:00:00.000000 |
| certfr-2025-avi-0824 | Multiples vulnérabilités dans les produits FoxIT | 2025-09-26T00:00:00.000000 | 2025-09-26T00:00:00.000000 |
| certfr-2025-avi-0823 | Vulnérabilité dans Liferay | 2025-09-26T00:00:00.000000 | 2025-09-26T00:00:00.000000 |
| certfr-2025-avi-0822 | Multiples vulnérabilités dans Tenable Security Center | 2025-09-26T00:00:00.000000 | 2025-09-26T00:00:00.000000 |
| certfr-2025-avi-0821 | Multiples vulnérabilités dans Microsoft Edge | 2025-09-26T00:00:00.000000 | 2025-09-26T00:00:00.000000 |
| certfr-2025-avi-0820 | Multiples vulnérabilités dans GitLab | 2025-09-26T00:00:00.000000 | 2025-09-26T00:00:00.000000 |
| certfr-2025-avi-0819 | Multiples vulnérabilités dans les produits Cisco | 2025-09-25T00:00:00.000000 | 2025-09-25T00:00:00.000000 |
| certfr-2025-avi-0818 | Multiples vulnérabilités dans Cisco IOS et IOS XE | 2025-09-25T00:00:00.000000 | 2025-09-25T00:00:00.000000 |
| certfr-2025-avi-0817 | Vulnérabilité dans Microsoft OmniParser | 2025-09-25T00:00:00.000000 | 2025-09-25T00:00:00.000000 |
| certfr-2025-avi-0816 | Vulnérabilité dans StormShield Network Security | 2025-09-25T00:00:00.000000 | 2025-09-25T00:00:00.000000 |
| certfr-2025-avi-0815 | Vulnérabilité dans Liferay | 2025-09-24T00:00:00.000000 | 2025-09-24T00:00:00.000000 |
| certfr-2025-avi-0814 | Multiples vulnérabilités dans Google Chrome | 2025-09-24T00:00:00.000000 | 2025-09-24T00:00:00.000000 |
| certfr-2025-avi-0813 | Vulnérabilité dans SolarWinds Web Help Desk | 2025-09-23T00:00:00.000000 | 2025-09-23T00:00:00.000000 |
| certfr-2025-avi-0812 | Vulnérabilité dans Synology Safe Access pour SRM | 2025-09-23T00:00:00.000000 | 2025-09-23T00:00:00.000000 |
| certfr-2025-avi-0811 | Multiples vulnérabilités dans Liferay | 2025-09-23T00:00:00.000000 | 2025-09-23T00:00:00.000000 |
| certfr-2025-avi-0810 | Vulnérabilité dans Liferay | 2025-09-22T00:00:00.000000 | 2025-09-22T00:00:00.000000 |
| certfr-2025-avi-0809 | Multiples vulnérabilités dans Microsoft Edge | 2025-09-22T00:00:00.000000 | 2025-09-22T00:00:00.000000 |
| certfr-2025-avi-0808 | Multiples vulnérabilités dans les produits IBM | 2025-09-19T00:00:00.000000 | 2025-09-19T00:00:00.000000 |
| certfr-2025-avi-0807 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-09-19T00:00:00.000000 | 2025-09-19T00:00:00.000000 |
| certfr-2025-avi-0806 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-09-19T00:00:00.000000 | 2025-09-19T00:00:00.000000 |
| certfr-2025-avi-0805 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-09-19T00:00:00.000000 | 2025-09-19T00:00:00.000000 |
| certfr-2025-avi-0804 | Multiples vulnérabilités dans Microsoft Windows | 2025-09-19T00:00:00.000000 | 2025-09-19T00:00:00.000000 |
| certfr-2025-avi-0803 | Vulnérabilité dans HPE Aruba Networking ClearPass Policy Manager | 2025-09-18T00:00:00.000000 | 2025-09-18T00:00:00.000000 |
| certfr-2025-avi-0802 | Multiples vulnérabilités dans Google Chrome | 2025-09-18T00:00:00.000000 | 2025-09-18T00:00:00.000000 |
| certfr-2025-avi-0801 | Multiples vulnérabilités dans les produits Mattermost | 2025-09-17T00:00:00.000000 | 2025-10-16T00:00:00.000000 |
| certfr-2025-avi-0800 | Multiples vulnérabilités dans Liferay | 2025-09-17T00:00:00.000000 | 2025-09-17T00:00:00.000000 |