Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-62249 | Weblate: Restricted-component change history leaked to… |
WeblateOrg |
weblate |
2026-08-26T20:29:49.207Z | 2026-08-27T14:32:50.121Z | |
| cve-2026-61792 | Weblate path traversal allows a project administrator … |
WeblateOrg |
weblate |
2026-08-26T20:26:27.810Z | 2026-08-29T02:51:38.553Z | |
| cve-2026-79921 | amqp091-go has a Potential Memory Exhaustion/Protocol … |
rabbitmq |
amqp091-go |
2026-08-26T20:24:58.115Z | 2026-08-29T02:50:25.822Z | |
| cve-2026-61790 | Weblate: Team-enforced 2FA is bypassed for global perm… |
WeblateOrg |
weblate |
2026-08-26T20:23:53.644Z | 2026-08-27T14:51:14.305Z | |
| cve-2026-55228 | Weblate:: WebIDOR in GroupViewSet allows authenticated… |
WeblateOrg |
weblate |
2026-08-26T20:14:02.713Z | 2026-08-27T15:20:40.892Z | |
| cve-2026-55227 | Observable object existence disclosure in private Webl… |
WeblateOrg |
weblate |
2026-08-26T20:10:39.333Z | 2026-08-27T13:51:40.681Z | |
| cve-2026-71054 | Vulnerability in Oracle Java SE (component: 2D). … |
Oracle Corporation |
Oracle Java SE |
2026-08-26T19:57:04.287Z | 2026-08-26T20:25:09.364Z | |
| cve-2026-77508 | Weblate: Unverified REST API email changes |
WeblateOrg |
weblate |
2026-08-26T19:56:59.825Z | 2026-08-27T14:32:57.362Z | |
| cve-2026-75601 | Static Web Server: Authentication bypass on /metrics e… |
static-web-server |
static-web-server |
2026-08-26T19:53:29.160Z | 2026-08-29T02:48:59.562Z | |
| cve-2026-60004 | 9.8 (v3.1) | Gitea before 1.27.1 allows remote code execution … |
Gitea |
Gitea |
2026-08-26T19:45:00.000Z | 2026-08-26T22:56:00.000Z |
| cve-2026-79938 | 7.6 (v3.1) | Dell PowerProtect Cyber Recovery, versions prior … |
Dell |
Power Protect Cyber Recovery |
2026-08-26T19:37:36.076Z | 2026-08-27T14:33:06.905Z |
| cve-2026-79939 | 5.8 (v3.1) | Dell PowerProtect Cyber Recovery, versions Prior … |
Dell |
Power Protect Cyber Recovery |
2026-08-26T19:32:57.153Z | 2026-08-27T15:21:36.311Z |
| cve-2026-46369 | Nimiq: Validity store off by one error |
nimiq |
core-rs-albatross |
2026-08-26T19:32:46.025Z | 2026-08-27T15:22:58.317Z | |
| cve-2026-66003 | Frappe: Access control bypass via REST API dot-notatio… |
frappe |
frappe |
2026-08-26T19:30:28.968Z | 2026-08-27T14:44:42.733Z | |
| cve-2026-49809 | 6.5 (v3.1) | Dell PowerProtect Cyber Recovery, versions 20.2 a… |
Dell |
Power Protect Cyber Recovery |
2026-08-26T19:28:34.851Z | 2026-08-28T18:35:57.350Z |
| cve-2026-47848 | 6.1 (v3.1) | Reactor Netty WebSocket Client Leaks Credentials On Redirect |
Spring |
Reactor Netty |
2026-08-26T19:22:26.712Z | 2026-08-26T19:44:38.993Z |
| cve-2026-47844 | 5.3 (v3.1) | Reactor Netty HTTP Server Leaks Exception Details |
Spring |
Reactor Netty |
2026-08-26T19:22:25.677Z | 2026-08-26T19:44:53.514Z |
| cve-2026-47843 | 3.7 (v3.1) | Reactor Netty may incorrectly route traffic due to DNS… |
Spring |
Reactor Netty |
2026-08-26T19:22:24.697Z | 2026-08-26T19:45:10.489Z |
| cve-2026-47842 | 6.5 (v3.1) | Deterministic AES/CBC Encryption in Spring Security Ae… |
Spring |
Spring Security |
2026-08-26T19:22:23.745Z | 2026-08-26T19:45:25.424Z |
| cve-2026-47834 | 4.8 (v3.1) | Spring Data JPA Sort expression validation bypass |
Spring |
Spring Data JPA |
2026-08-26T19:22:22.873Z | 2026-08-26T19:45:40.524Z |
| cve-2026-77652 | 7.8 (v3.1) | Dia: dia: heap buffer overflow in wpg colormap parser … |
GNOME |
Dia |
2026-08-26T19:21:39.936Z | 2026-08-27T14:43:23.737Z |
| cve-2026-74770 | 8.8 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:17:41.915Z | 2026-08-27T14:33:15.683Z |
| cve-2026-54245 | Fleet: SQL injection in Okta conditional access endpoi… |
fleetdm |
fleet |
2026-08-26T19:13:22.415Z | 2026-08-27T13:49:51.927Z | |
| cve-2026-74771 | 6.5 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:11:48.631Z | 2026-08-27T15:25:00.027Z |
| cve-2026-46371 | Fleet: Observer-level enrollment secret extraction via… |
fleetdm |
fleet |
2026-08-26T19:06:12.147Z | 2026-08-27T14:33:22.566Z | |
| cve-2026-74774 | 5.9 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:05:43.845Z | 2026-08-27T14:42:11.386Z |
| cve-2026-67275 | 5.3 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:01:27.487Z | 2026-08-27T14:33:32.218Z |
| cve-2026-56547 | 3.5 (v3.1) | An input reflection vulnerability affects HCL Traveler |
HCLSoftware |
Traveler |
2026-08-26T18:54:50.814Z | 2026-08-26T19:45:56.615Z |
| cve-2026-46370 | Fleet has observer-level enrollment secret extraction … |
fleetdm |
fleet |
2026-08-26T18:54:31.761Z | 2026-08-29T02:47:37.283Z | |
| cve-2026-68861 | 8.8 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T18:54:30.310Z | 2026-08-27T15:27:18.434Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2017-000187 | Installer of LhaForge may insecurely load Dynamic Link Libraries | 2017-07-27T14:31+09:00 | 2018-01-24T13:59+09:00 |
| jvndb-2017-000185 | Multiple vulnerabilities in I-O DATA WN-AX1167GR | 2017-07-27T14:26+09:00 | 2018-01-24T13:56+09:00 |
| jvndb-2017-000188 | I-O DATA WN-G300R31 uses hard-coded credentials | 2017-07-27T14:13+09:00 | 2018-01-24T14:03+09:00 |
| jvndb-2017-000184 | Installer of Tween may insecurely load Dynamic Link Libraries | 2017-07-24T15:08+09:00 | 2018-01-24T14:03+09:00 |
| jvndb-2017-000177 | RBB SPEED TEST App fails to verify SSL server certificates | 2017-07-24T15:08+09:00 | 2018-01-24T14:03+09:00 |
| jvndb-2017-000183 | Multiple cross-site scripting vulnerabilities in ScreenOS | 2017-07-24T13:52+09:00 | 2017-08-09T11:23+09:00 |
| jvndb-2017-000182 | WordPress plugin "Simple Custom CSS and JS" vulnerable to cross-site scripting | 2017-07-24T13:52+09:00 | 2018-02-14T11:58+09:00 |
| jvndb-2017-000181 | WordPress plugin "Popup Maker" vulnerable to cross-site scripting | 2017-07-24T13:52+09:00 | 2018-01-24T14:03+09:00 |
| jvndb-2017-005208 | gSOAP vulnerable to stack-based buffer overflow | 2017-07-21T13:39+09:00 | 2018-02-14T13:44+09:00 |
| jvndb-2017-000180 | Multiple vulnerabilities in multiple Buffalo wireless LAN routers | 2017-07-20T14:13+09:00 | 2018-01-24T12:34+09:00 |
| jvndb-2017-000179 | Multiple Buffalo wireless LAN access point devices do not properly perform authentication | 2017-07-20T14:12+09:00 | 2017-07-20T14:12+09:00 |
| jvndb-2017-005137 | Multiple Vulnerabilities in Hitachi Automation Director and Hitachi Infrastructure Analytics Advisor | 2017-07-19T15:44+09:00 | 2017-07-19T15:44+09:00 |
| jvndb-2017-000176 | SONY Portable Wireless Server WG-C10 fails to restrict access permissions | 2017-07-19T15:07+09:00 | 2018-02-14T12:02+09:00 |
| jvndb-2017-000175 | Multiple vulnerabilities SONY Portable Wireless Server WG-C10 | 2017-07-19T15:07+09:00 | 2018-01-24T12:34+09:00 |
| jvndb-2017-000174 | Self-Extracting Encrypted Files created by AttacheCase may insecurely load Dynamic Link Libraries | 2017-07-14T13:38+09:00 | 2022-03-31T17:43+09:00 |
| jvndb-2017-000172 | FileCapsule Deluxe Portable and Encrypted Files in Self-Decryption Format created by FileCapsule Deluxe Portable may insecurely load Dynamic Link Libraries | 2017-07-13T14:35+09:00 | 2018-02-07T16:48+09:00 |
| jvndb-2017-000173 | Installer of Yahoo! Toolbar (for Internet explorer) may insecurely load Dynamic Link Libraries | 2017-07-12T14:42+09:00 | 2018-02-07T16:48+09:00 |
| jvndb-2017-000171 | Installers of Mozilla Firefox and Thunderbird for Windows may insecurely load Dynamic Link Libraries | 2017-07-11T13:48+09:00 | 2018-08-30T18:03+09:00 |
| jvndb-2017-000170 | Self-Extracting Archives created by File Compact may insecurely load Dynamic Link Libraries | 2017-07-10T13:57+09:00 | 2018-02-16T13:26+09:00 |
| jvndb-2016-005802 | Microsoft IME may insecurely load Dynamic Link Libraries | 2017-07-07T15:47+09:00 | 2017-07-07T15:47+09:00 |
| jvndb-2017-000169 | Installers of Lhaz and Lhaz+, and Self-Extracting Archives created by Lhaz or Lhaz+ may insecurely load Dynamic Link Libraries | 2017-07-07T14:18+09:00 | 2018-02-07T12:19+09:00 |
| jvndb-2017-000164 | WordPress plugin "Shortcodes Ultimate" vulnerable to directory traversal | 2017-07-06T13:41+09:00 | 2018-02-07T11:52+09:00 |
| jvndb-2017-000162 | Installer of Douroshisetu Kihon Data Sakusei System may insecurely load Dynamic Link Libraries | 2017-07-04T14:43+09:00 | 2018-02-07T12:32+09:00 |
| jvndb-2017-000161 | Installer of Douro Kouji Kanseizutou Check Program may insecurely load Dynamic Link Libraries | 2017-07-04T14:43+09:00 | 2018-02-07T12:32+09:00 |
| jvndb-2017-000159 | WordPress plugin "Responsive Lightbox" vulnerable to cross-site scripting | 2017-07-04T14:02+09:00 | 2018-02-14T12:10+09:00 |
| jvndb-2017-000160 | MFC-J960DWN vulnerable to cross-site request forgery | 2017-07-04T13:59+09:00 | 2018-02-07T11:52+09:00 |
| jvndb-2017-000157 | Cybozu Garoon vulnerable to cross-site scripting | 2017-07-03T15:23+09:00 | 2018-02-07T11:52+09:00 |
| jvndb-2017-000156 | Cybozu Garoon vulnerable to session fixation | 2017-07-03T15:22+09:00 | 2018-02-14T11:54+09:00 |
| jvndb-2017-000155 | Cybozu Garoon fails to restrict access permission | 2017-07-03T15:22+09:00 | 2018-02-14T11:54+09:00 |
| jvndb-2017-000158 | Installer and self-extracting archive containing the installer of MLIT DenshiSeikabutsuSakuseiShienKensa system may insecurely load Dynamic Link Libraries | 2017-07-03T14:14+09:00 | 2018-02-07T12:20+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0679 | Multiples vulnérabilités dans les produits Fortinet | 2025-08-13T00:00:00.000000 | 2025-08-13T00:00:00.000000 |
| certfr-2025-avi-0678 | Multiples vulnérabilités dans les produits Adobe | 2025-08-13T00:00:00.000000 | 2025-08-13T00:00:00.000000 |
| certfr-2025-avi-0677 | Multiples vulnérabilités dans les produits Siemens | 2025-08-12T00:00:00.000000 | 2025-08-12T00:00:00.000000 |
| certfr-2025-avi-0676 | Multiples vulnérabilités dans les produits Schneider Electric | 2025-08-12T00:00:00.000000 | 2025-08-12T00:00:00.000000 |
| certfr-2025-avi-0675 | Vulnérabilité dans Liferay | 2025-08-12T00:00:00.000000 | 2025-08-12T00:00:00.000000 |
| certfr-2025-avi-0674 | Multiples vulnérabilités dans les produits SAP | 2025-08-12T00:00:00.000000 | 2025-08-12T00:00:00.000000 |
| certfr-2025-avi-0673 | Vulnérabilité dans Centreon Gorgone | 2025-08-12T00:00:00.000000 | 2025-08-12T00:00:00.000000 |
| certfr-2025-avi-0672 | Multiples vulnérabilités dans Liferay | 2025-08-11T00:00:00.000000 | 2025-08-11T00:00:00.000000 |
| certfr-2025-avi-0671 | Multiples vulnérabilités dans les produits IBM | 2025-08-08T00:00:00.000000 | 2025-08-08T00:00:00.000000 |
| certfr-2025-avi-0670 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-08-08T00:00:00.000000 | 2025-08-08T00:00:00.000000 |
| certfr-2025-avi-0669 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-08-08T00:00:00.000000 | 2025-08-08T00:00:00.000000 |
| certfr-2025-avi-0668 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-08-08T00:00:00.000000 | 2025-08-08T00:00:00.000000 |
| certfr-2025-avi-0667 | Multiples vulnérabilités dans Juniper Secure Analytics | 2025-08-08T00:00:00.000000 | 2025-08-08T00:00:00.000000 |
| certfr-2025-avi-0666 | Multiples vulnérabilités dans Microsoft Azure | 2025-08-08T00:00:00.000000 | 2025-08-08T00:00:00.000000 |
| certfr-2025-avi-0665 | Multiples vulnérabilités dans Microsoft Office | 2025-08-08T00:00:00.000000 | 2025-08-08T00:00:00.000000 |
| certfr-2025-avi-0664 | Multiples vulnérabilités dans Microsoft Edge | 2025-08-08T00:00:00.000000 | 2025-08-08T00:00:00.000000 |
| certfr-2025-avi-0663 | Multiples vulnérabilités dans GnuTLS | 2025-08-08T00:00:00.000000 | 2025-08-08T00:00:00.000000 |
| certfr-2025-avi-0662 | Multiples vulnérabilités dans les produits Centreon | 2025-08-07T00:00:00.000000 | 2025-08-07T00:00:00.000000 |
| certfr-2025-avi-0661 | Multiples vulnérabilités dans les produits Splunk | 2025-08-07T00:00:00.000000 | 2025-08-07T00:00:00.000000 |
| certfr-2025-avi-0660 | Vulnérabilité dans Tenable Identity Exposure | 2025-08-07T00:00:00.000000 | 2025-08-07T00:00:00.000000 |
| certfr-2025-avi-0659 | Vulnérabilité dans Microsoft Exchange Server | 2025-08-07T00:00:00.000000 | 2025-08-07T00:00:00.000000 |
| certfr-2025-avi-0658 | Multiples vulnérabilités dans Trend Micro Apex One | 2025-08-06T00:00:00.000000 | 2025-08-06T00:00:00.000000 |
| certfr-2025-avi-0657 | Multiples vulnérabilités dans Google Chrome | 2025-08-06T00:00:00.000000 | 2025-08-06T00:00:00.000000 |
| certfr-2025-avi-0656 | Vulnérabilité dans Google Pixel | 2025-08-06T00:00:00.000000 | 2025-08-06T00:00:00.000000 |
| certfr-2025-avi-0655 | Multiples vulnérabilités dans les produits Liferay | 2025-08-05T00:00:00.000000 | 2025-08-05T00:00:00.000000 |
| certfr-2025-avi-0654 | Multiples vulnérabilités dans les produits Netgate | 2025-08-05T00:00:00.000000 | 2025-08-05T00:00:00.000000 |
| certfr-2025-avi-0653 | Multiples vulnérabilités dans Google Android | 2025-08-05T00:00:00.000000 | 2025-08-05T00:00:00.000000 |
| certfr-2025-avi-0652 | Vulnérabilité dans le greffon "WASM Client" pour Traefik | 2025-08-04T00:00:00.000000 | 2025-08-04T00:00:00.000000 |
| certfr-2025-avi-0651 | Multiples vulnérabilités dans les produits IBM | 2025-08-01T00:00:00.000000 | 2025-08-01T00:00:00.000000 |
| certfr-2025-avi-0650 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-08-01T00:00:00.000000 | 2025-08-01T00:00:00.000000 |