Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2025-46606 | 6.2 (v3.1) | Dell PowerProtect Data Domain with Data Domain Op… |
Dell |
PowerProtect Data Domain |
2026-04-17T11:36:54.469Z | 2026-04-18T03:55:33.318Z |
| cve-2026-4541 | janmojzis tinyssh Ed25519 Signature crypto_sign_ed2551… |
janmojzis |
tinyssh |
2026-03-22T08:35:03.623Z | 2026-04-18T03:39:33.191Z | |
| cve-2026-4542 | SSCMS layerImage Endpoint LayerImageController.Submit.… |
n/a |
SSCMS |
2026-03-22T08:35:10.929Z | 2026-04-18T03:38:56.405Z | |
| cve-2026-4568 | SourceCodester Sales and Inventory System HTTP GET Req… |
SourceCodester |
Sales and Inventory System |
2026-03-23T02:12:57.973Z | 2026-04-18T03:38:21.283Z | |
| cve-2026-4581 | code-projects Simple Laundry System Parameters checklo… |
code-projects |
Simple Laundry System |
2026-03-23T09:33:18.596Z | 2026-04-18T03:37:53.025Z | |
| cve-2026-4582 | Shenzhen HCC Technology MPOS M6 PLUS Bluetooth missing… |
Shenzhen HCC Technology |
MPOS M6 PLUS |
2026-03-23T09:33:21.271Z | 2026-04-18T03:37:10.133Z | |
| cve-2026-4589 | kalcaddle kodbox fileGet Endpoint editor.class.php Pat… |
kalcaddle |
kodbox |
2026-03-23T13:32:42.266Z | 2026-04-18T03:36:21.562Z | |
| cve-2026-4595 | code-projects Exam Form Submission update_s6.php cross… |
code-projects |
Exam Form Submission |
2026-03-23T18:37:03.375Z | 2026-04-18T03:35:36.342Z | |
| cve-2026-4597 | 648540858 wvp-GB28181-pro Stream Proxy Query StreamPro… |
648540858 |
wvp-GB28181-pro |
2026-03-23T20:15:04.976Z | 2026-04-18T03:34:43.190Z | |
| cve-2026-40302 | zrok has reflected XSS in GitHub OAuth callback via un… |
openziti |
zrok |
2026-04-17T20:56:08.368Z | 2026-04-18T03:07:10.092Z | |
| cve-2026-23500 | Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_P… |
Dolibarr |
dolibarr |
2026-04-17T20:25:49.843Z | 2026-04-18T03:06:20.406Z | |
| cve-2026-6491 | libvips nip2 vips7compat.c im_minpos_vec heap-based overflow |
n/a |
libvips |
2026-04-17T13:45:11.506Z | 2026-04-18T02:59:14.319Z | |
| cve-2026-6486 | classroombookings User Display Name layout.php read cr… |
n/a |
classroombookings |
2026-04-17T12:15:14.036Z | 2026-04-18T02:58:17.041Z | |
| cve-2026-28263 | 5.9 (v3.1) | Dell PowerProtect Data Domain with Data Domain Op… |
Dell |
PowerProtect Data Domain |
2026-04-17T11:44:12.943Z | 2026-04-18T02:57:02.616Z |
| cve-2026-6494 | 5.3 (v3.1) | Aap-mcp-server: aap mcp server: log injection allows s… |
Red Hat |
Red Hat Ansible Automation Platform 2 |
2026-04-17T08:18:50.757Z | 2026-04-18T02:53:52.696Z |
| cve-2026-40262 | Note Mark has Stored XSS via Unrestricted Asset Upload |
enchant97 |
note-mark |
2026-04-16T23:51:38.679Z | 2026-04-18T02:51:02.474Z | |
| cve-2026-40318 | SiYuan: Publish Reader Path Traversal Delete via `remo… |
siyuan-note |
siyuan |
2026-04-16T22:54:47.881Z | 2026-04-18T02:48:57.193Z | |
| cve-2026-40249 | free5gc UDR fail-open request handling in PolicyDataSu… |
free5gc |
free5gc |
2026-04-16T21:59:36.282Z | 2026-04-18T02:47:28.094Z | |
| cve-2026-40246 | free5gc UDR improper path validation allows unauthenti… |
free5gc |
free5gc |
2026-04-16T21:40:03.598Z | 2026-04-18T02:46:14.355Z | |
| cve-2026-34164 | Valtimo: Sensitive data exposure through inbox message… |
valtimo-platform |
valtimo |
2026-04-16T21:17:35.472Z | 2026-04-18T02:44:44.369Z | |
| cve-2026-40899 | DataEase has an Arbitrary File Read Vulnerability |
dataease |
dataease |
2026-04-16T19:48:44.201Z | 2026-04-18T02:43:14.720Z | |
| cve-2026-33084 | DataEase has SQL Injection through its getFieldEnumObj… |
dataease |
dataease |
2026-04-16T18:14:07.316Z | 2026-04-18T02:40:47.771Z | |
| cve-2025-43883 | 4.1 (v3.1) | Dell PowerScale OneFS, versions prior to 9.12.0.0… |
Dell |
PowerScale OneFS |
2026-04-16T17:54:09.831Z | 2026-04-18T02:39:20.246Z |
| cve-2026-24749 | Silverstripe Assets Module has a DBFile::getURL() perm… |
silverstripe |
silverstripe-assets |
2026-04-16T17:08:59.133Z | 2026-04-18T02:36:26.887Z | |
| cve-2026-41080 | 2.9 (v3.1) | libexpat before 2.7.6 uses insufficient entropy, … |
libexpat project |
libexpat |
2026-04-16T16:52:01.177Z | 2026-04-18T02:33:52.350Z |
| cve-2026-5426 | N/A | KnowledgeDeliver deployments before February 24, 2026 … |
Digital Knowledge |
KnowledgeDeliver |
2026-04-16T15:18:46.224Z | 2026-04-18T02:31:32.234Z |
| cve-2026-31987 | Apache Airflow: JWT token appearing in logs |
Apache Software Foundation |
Apache Airflow |
2026-04-16T13:31:52.336Z | 2026-04-18T02:28:44.770Z | |
| cve-2026-37100 | N/A | An issue in the Bluetooth Low Energy (BLE) contro… |
n/a |
n/a |
2026-04-16T00:00:00.000Z | 2026-04-18T02:26:33.302Z |
| cve-2026-37344 | N/A | SourceCodester Vehicle Parking Area Management Sy… |
n/a |
n/a |
2026-04-16T00:00:00.000Z | 2026-04-18T02:24:10.031Z |
| cve-2026-37343 | N/A | SourceCodester Vehicle Parking Area Management Sy… |
n/a |
n/a |
2026-04-16T00:00:00.000Z | 2026-04-18T02:21:26.859Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2011-000017 | IBM WebSphere Application Server vulnerable to denial-of-service (DoS) | 2011-03-04T19:29+09:00 | 2018-02-07T17:10+09:00 |
| jvndb-2011-000016 | IBM DB2 vulnerable to denial-of-service (DoS) | 2011-03-04T19:29+09:00 | 2018-02-07T17:10+09:00 |
| jvndb-2017-000173 | Installer of Yahoo! Toolbar (for Internet explorer) may insecurely load Dynamic Link Libraries | 2017-07-12T14:42+09:00 | 2018-02-07T16:48+09:00 |
| jvndb-2017-000172 | FileCapsule Deluxe Portable and Encrypted Files in Self-Decryption Format created by FileCapsule Deluxe Portable may insecurely load Dynamic Link Libraries | 2017-07-13T14:35+09:00 | 2018-02-07T16:48+09:00 |
| jvndb-2017-000145 | Installer of Setup file of advance preparation for e-Tax software (WEB version) may insecurely load Dynamic Link Libraries | 2017-06-28T16:40+09:00 | 2018-02-07T13:40+09:00 |
| jvndb-2017-000144 | Denshi Nyusatsu Check Tool provided by Ministry of Education, Culture, Sports, Science and Technology may insecurely load Dynamic Link Libraries | 2017-06-26T14:28+09:00 | 2018-02-07T13:40+09:00 |
| jvndb-2017-000162 | Installer of Douroshisetu Kihon Data Sakusei System may insecurely load Dynamic Link Libraries | 2017-07-04T14:43+09:00 | 2018-02-07T12:32+09:00 |
| jvndb-2017-000161 | Installer of Douro Kouji Kanseizutou Check Program may insecurely load Dynamic Link Libraries | 2017-07-04T14:43+09:00 | 2018-02-07T12:32+09:00 |
| jvndb-2017-000142 | Installer of Charamin OMP may insecurely load Dynamic Link Libraries | 2017-06-23T14:38+09:00 | 2018-02-07T12:32+09:00 |
| jvndb-2017-000152 | Installer of Shinseiyou Sougou Soft provided by The Ministry of Justice may insecurely load Dynamic Link Libraries | 2017-06-30T14:19+09:00 | 2018-02-07T12:22+09:00 |
| jvndb-2017-000153 | Installer of PDF Digital Signature Plugin provided by the Ministry of Justice may insecurely load Dynamic Link Libraries | 2017-06-30T14:18+09:00 | 2018-02-07T12:21+09:00 |
| jvndb-2017-000158 | Installer and self-extracting archive containing the installer of MLIT DenshiSeikabutsuSakuseiShienKensa system may insecurely load Dynamic Link Libraries | 2017-07-03T14:14+09:00 | 2018-02-07T12:20+09:00 |
| jvndb-2017-000169 | Installers of Lhaz and Lhaz+, and Self-Extracting Archives created by Lhaz or Lhaz+ may insecurely load Dynamic Link Libraries | 2017-07-07T14:18+09:00 | 2018-02-07T12:19+09:00 |
| jvndb-2017-000164 | WordPress plugin "Shortcodes Ultimate" vulnerable to directory traversal | 2017-07-06T13:41+09:00 | 2018-02-07T11:52+09:00 |
| jvndb-2017-000160 | MFC-J960DWN vulnerable to cross-site request forgery | 2017-07-04T13:59+09:00 | 2018-02-07T11:52+09:00 |
| jvndb-2017-000157 | Cybozu Garoon vulnerable to cross-site scripting | 2017-07-03T15:23+09:00 | 2018-02-07T11:52+09:00 |
| jvndb-2017-000146 | Marp vulnerable to improper access control in JavaScript execution | 2017-09-29T13:54+09:00 | 2018-02-07T11:52+09:00 |
| jvndb-2017-000132 | WordPress plugin "WP-Members" vulnerable to cross-site scripting | 2017-06-13T14:50+09:00 | 2018-02-07T11:52+09:00 |
| jvndb-2017-004607 | Deep Discovery Email Inspector vulnerable to arbitrary code execution | 2018-01-31T13:43+09:00 | 2018-01-31T13:43+09:00 |
| jvndb-2016-000121 | Apache Commons FileUpload vulnerable to denial-of-service (DoS) | 2016-06-30T13:53+09:00 | 2018-01-29T10:30+09:00 |
| jvndb-2017-000195 | Installer of Baidu IME may insecurely load Dynamic Link Libraries | 2017-08-03T12:28+09:00 | 2018-01-24T14:34+09:00 |
| jvndb-2017-000196 | Installer of IP Messenger may insecurely load Dynamic Link Libraries | 2017-08-03T14:35+09:00 | 2018-01-24T14:26+09:00 |
| jvndb-2017-000108 | Installer of Tera Term may insecurely load Dynamic Link Libraries | 2017-06-01T14:42+09:00 | 2018-01-24T14:20+09:00 |
| jvndb-2017-000106 | RW-5100 driver installer may insecurely load Dynamic Link Libraries | 2017-06-01T16:44+09:00 | 2018-01-24T14:15+09:00 |
| jvndb-2017-000189 | Installers of Sony PaSoRi related software may insecurely load Dynamic Link Libraries | 2017-07-27T15:38+09:00 | 2018-01-24T14:14+09:00 |
| jvndb-2017-000105 | RW-4040 tool to verify execution environment may insecurely load Dynamic Link Libraries | 2017-06-01T16:40+09:00 | 2018-01-24T14:05+09:00 |
| jvndb-2017-000188 | I-O DATA WN-G300R31 uses hard-coded credentials | 2017-07-27T14:13+09:00 | 2018-01-24T14:03+09:00 |
| jvndb-2017-000184 | Installer of Tween may insecurely load Dynamic Link Libraries | 2017-07-24T15:08+09:00 | 2018-01-24T14:03+09:00 |
| jvndb-2017-000181 | WordPress plugin "Popup Maker" vulnerable to cross-site scripting | 2017-07-24T13:52+09:00 | 2018-01-24T14:03+09:00 |
| jvndb-2017-000177 | RBB SPEED TEST App fails to verify SSL server certificates | 2017-07-24T15:08+09:00 | 2018-01-24T14:03+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0135 | Multiples vulnérabilités dans IBM QRadar Deployment Intelligence App | 2025-02-14T00:00:00.000000 | 2025-02-14T00:00:00.000000 |
| certfr-2025-avi-0134 | Multiples vulnérabilités dans le noyau Linux de Debian | 2025-02-14T00:00:00.000000 | 2025-02-14T00:00:00.000000 |
| certfr-2025-avi-0133 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-02-14T00:00:00.000000 | 2025-02-14T00:00:00.000000 |
| certfr-2025-avi-0132 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-02-14T00:00:00.000000 | 2025-02-14T00:00:00.000000 |
| certfr-2025-avi-0131 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-02-14T00:00:00.000000 | 2025-02-14T00:00:00.000000 |
| certfr-2025-avi-0130 | Vulnérabilité dans PostgreSQL | 2025-02-14T00:00:00.000000 | 2025-02-14T00:00:00.000000 |
| certfr-2025-avi-0128 | Multiples vulnérabilités dans les produits Palo Alto Networks | 2025-02-13T00:00:00.000000 | 2025-02-13T00:00:00.000000 |
| certfr-2025-avi-0127 | Multiples vulnérabilités dans Google Chrome | 2025-02-13T00:00:00.000000 | 2025-02-13T00:00:00.000000 |
| certfr-2025-avi-0123 | Multiples vulnérabilités dans GitLab | 2025-02-12T00:00:00.000000 | 2025-02-13T00:00:00.000000 |
| certfr-2025-avi-0063 | Multiples vulnérabilités dans GitLab | 2025-01-23T00:00:00.000000 | 2025-02-13T00:00:00.000000 |
| certfr-2025-avi-0126 | Vulnérabilité dans les produits Juniper Networks | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0125 | Multiples vulnérabilités dans les produits SolarWinds | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0124 | Vulnérabilité dans le greffon "Saisies pour formulaire" pour SPIP | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0122 | Multiples vulnérabilités dans les produits Adobe | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0121 | Multiples vulnérabilités dans les produits Ivanti | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0120 | Multiples vulnérabilités dans les produits Fortinet | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0119 | Multiples vulnérabilités dans les produits Intel | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0118 | Multiples vulnérabilités dans les produits Microsoft | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0117 | Vulnérabilité dans Microsoft Azure | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0116 | Multiples vulnérabilités dans Microsoft Windows | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0115 | Multiples vulnérabilités dans Microsoft Office | 2025-02-12T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0030 | Multiples vulnérabilités dans les produits Fortinet | 2025-01-14T00:00:00.000000 | 2025-02-12T00:00:00.000000 |
| certfr-2025-avi-0114 | Multiples vulnérabilités dans les produits SAP | 2025-02-11T00:00:00.000000 | 2025-02-11T00:00:00.000000 |
| certfr-2025-avi-0113 | Multiples vulnérabilités dans les produits Siemens | 2025-02-11T00:00:00.000000 | 2025-02-11T00:00:00.000000 |
| certfr-2025-avi-0112 | Vulnérabilité dans les produits Schneider Electric | 2025-02-11T00:00:00.000000 | 2025-02-11T00:00:00.000000 |
| certfr-2025-avi-0111 | Multiples vulnérabilités dans les produits SolarWinds | 2025-02-11T00:00:00.000000 | 2025-02-11T00:00:00.000000 |
| certfr-2025-avi-0110 | Vulnérabilité dans les produits Apple | 2025-02-11T00:00:00.000000 | 2025-02-11T00:00:00.000000 |
| certfr-2025-avi-0109 | Vulnérabilité dans Nginx | 2025-02-11T00:00:00.000000 | 2025-02-11T00:00:00.000000 |
| certfr-2025-avi-0102 | Multiples vulnérabilités dans les produits Tenable | 2025-02-07T00:00:00.000000 | 2025-02-10T00:00:00.000000 |
| certfr-2025-avi-0108 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-02-07T00:00:00.000000 | 2025-02-07T00:00:00.000000 |