Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-74774 | 5.9 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:05:43.845Z | 2026-08-27T14:42:11.386Z |
| cve-2026-67275 | 5.3 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:01:27.487Z | 2026-08-27T14:33:32.218Z |
| cve-2026-56547 | 3.5 (v3.1) | An input reflection vulnerability affects HCL Traveler |
HCLSoftware |
Traveler |
2026-08-26T18:54:50.814Z | 2026-08-26T19:45:56.615Z |
| cve-2026-46370 | Fleet has observer-level enrollment secret extraction … |
fleetdm |
fleet |
2026-08-26T18:54:31.761Z | 2026-08-29T02:47:37.283Z | |
| cve-2026-68861 | 8.8 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T18:54:30.310Z | 2026-08-27T15:27:18.434Z |
| cve-2026-68863 | 7.5 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T18:50:10.312Z | 2026-08-27T14:41:45.811Z |
| cve-2026-71172 | 4.3 (v3.1) | Dell Cloud Disaster Recovery, versions 20.2 and p… |
Dell |
Cloud Disaster Recovery |
2026-08-26T18:44:09.039Z | 2026-08-26T19:46:12.189Z |
| cve-2026-41262 | Fleet: Cross-Team Policy Data Exposure via Global Poli… |
fleetdm |
fleet |
2026-08-26T18:32:30.669Z | 2026-08-26T18:57:43.948Z | |
| cve-2026-71171 | 7.2 (v3.1) | Dell Cloud Disaster Recovery, versions 20.2 and p… |
Dell |
Cloud Disaster Recovery |
2026-08-26T18:30:52.487Z | 2026-08-26T18:48:27.558Z |
| cve-2026-48786 | Fleet: Observer-class users can view team enroll secre… |
fleetdm |
fleet |
2026-08-26T18:25:09.971Z | 2026-08-26T18:49:37.564Z | |
| cve-2026-70419 | 9.1 (v3.1) | Dell Cloud Disaster Recovery, versions 20.2 and p… |
Dell |
Cloud Disaster Recovery |
2026-08-26T18:24:28.070Z | 2026-08-26T18:52:08.264Z |
| cve-2026-79940 | 5.9 (v3.1) | Dell iDRAC9, 14G versions prior to 7.00.00.182 an… |
Dell |
iDRAC9 |
2026-08-26T18:16:42.618Z | 2026-08-26T19:46:27.415Z |
| cve-2026-63179 | Winter: Local File Inclusion through @import directive… |
wintercms |
winter |
2026-08-26T18:06:14.103Z | 2026-08-26T18:51:15.095Z | |
| cve-2026-19485 | 9.3 (v4.0) | Bucket Squatting in Vertex AI Search for Commerce |
Google Cloud |
Vertex AI Search for Commerce |
2026-08-26T18:06:00.596Z | 2026-08-26T19:04:26.776Z |
| cve-2026-54256 | Winter: Authenticated IDOR in backend FileUpload widge… |
wintercms |
winter |
2026-08-26T17:53:36.237Z | 2026-08-27T14:33:39.110Z | |
| cve-2026-32639 | Winter: Broken access control in `Cms\Controllers\Inde… |
wintercms |
winter |
2026-08-26T17:50:32.102Z | 2026-08-29T02:46:44.275Z | |
| cve-2026-58474 | 8.6 (v4.0) 8.8 (v3.1) | whichllm < 0.5.16 Code Injection via run and snippet c… |
Andyyyy64 |
whichllm |
2026-08-26T17:49:04.041Z | 2026-08-29T11:47:31.365Z |
| cve-2026-76784 | 8.7 (v4.0) | Insufficient Cryptographic Protections in Local Device… |
TP-Link Systems Inc. |
HS103P3 / HS103P4 v5 |
2026-08-26T17:47:54.278Z | 2026-08-26T18:50:19.860Z |
| cve-2026-32593 | Winter: SQL Injection in Backend Filter Widget numberr… |
wintercms |
winter |
2026-08-26T17:27:07.836Z | 2026-08-26T18:29:20.480Z | |
| cve-2026-47841 | 7.4 (v3.1) | WebAuthn User Verification Bypass via Session Serialization |
Spring |
Spring Security |
2026-08-26T17:08:52.788Z | 2026-08-27T03:58:22.127Z |
| cve-2026-47837 | 6.8 (v3.1) | Spring Cloud Config Server Monitor Endpoint Does Not V… |
Spring |
Spring Cloud Config |
2026-08-26T17:08:51.832Z | 2026-08-26T18:50:49.428Z |
| cve-2026-47836 | 7.2 (v3.1) | Spring Cloud Config Server Susceptible To TOCTOU Attac… |
Spring |
Spring Cloud Config |
2026-08-26T17:05:21.979Z | 2026-08-27T03:58:24.390Z |
| cve-2026-32258 | Winter: Stored XSS through Editor Settings custom styles |
wintercms |
winter |
2026-08-26T16:49:06.852Z | 2026-08-26T17:35:11.529Z | |
| cve-2026-32257 | Winter: Stored XSS through Brand Settings custom styles |
wintercms |
winter |
2026-08-26T16:45:12.100Z | 2026-08-27T14:33:49.017Z | |
| cve-2026-35445 | Winter: Authenticated backend users can bypass Users c… |
wintercms |
winter |
2026-08-26T16:40:51.500Z | 2026-08-26T19:08:44.974Z | |
| cve-2026-81036 | 8.5 (v4.0) 8.1 (v3.1) | Stalwart Mail Server through 0.16.19 Authorization Cod… |
stalwartlabs |
stalwart |
2026-08-26T15:45:02.931Z | 2026-08-29T02:45:24.847Z |
| cve-2026-81035 | 7.2 (v4.0) 8.1 (v3.1) | Midday Missing Owner Check on Team Deletion |
midday-ai |
midday |
2026-08-26T15:45:02.234Z | 2026-08-26T16:06:39.105Z |
| cve-2026-81034 | 8.3 (v4.0) 6.5 (v3.1) | Netmaker through 1.6.0 Improper Certificate Validation… |
gravitl |
netmaker |
2026-08-26T15:45:01.529Z | 2026-08-26T18:31:47.883Z |
| cve-2026-81033 | 6.9 (v4.0) 5.3 (v3.1) | Automatisch through 0.15.0 User Enumeration via Forgot… |
automatisch |
automatisch |
2026-08-26T15:45:00.826Z | 2026-08-28T16:00:31.483Z |
| cve-2026-81032 | 9.3 (v4.0) 9.8 (v3.1) | NebulaGraph through 3.8.0 Unauthenticated Read and Mod… |
vesoft-inc |
nebula |
2026-08-26T15:45:00.144Z | 2026-08-26T17:10:45.206Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2017-002225 | Cross-site Scripting Vulnerability in multiple Hitachi products | 2017-06-30T15:56+09:00 | 2017-06-30T15:56+09:00 |
| jvndb-2017-003108 | Multiple Vulnerabilities in Hitachi IT Operations Director and JP1/IT Desktop Management | 2017-06-30T15:55+09:00 | 2017-06-30T15:55+09:00 |
| jvndb-2016-008607 | Vulnerability in Cosminexus HTTP Server and Hitachi Web Server | 2017-06-30T15:55+09:00 | 2019-07-25T14:14+09:00 |
| jvndb-2017-000152 | Installer of Shinseiyou Sougou Soft provided by The Ministry of Justice may insecurely load Dynamic Link Libraries | 2017-06-30T14:19+09:00 | 2018-02-07T12:22+09:00 |
| jvndb-2017-000153 | Installer of PDF Digital Signature Plugin provided by the Ministry of Justice may insecurely load Dynamic Link Libraries | 2017-06-30T14:18+09:00 | 2018-02-07T12:21+09:00 |
| jvndb-2017-000145 | Installer of Setup file of advance preparation for e-Tax software (WEB version) may insecurely load Dynamic Link Libraries | 2017-06-28T16:40+09:00 | 2018-02-07T13:40+09:00 |
| jvndb-2017-000151 | Cross-site request forgery vulnerability in Toshiba Lighting & Technology Corporation Home gateway | 2017-06-28T10:28+09:00 | 2018-02-14T12:10+09:00 |
| jvndb-2017-000150 | OS command injection vulnerability in Toshiba Lighting & Technology Corporation Home gateway | 2017-06-28T10:28+09:00 | 2018-02-14T12:10+09:00 |
| jvndb-2017-000147 | Non-documented developer's screen in Toshiba Lighting & Technology Corporation Home gateway | 2017-06-28T10:28+09:00 | 2018-02-14T12:10+09:00 |
| jvndb-2017-000149 | Hard-coded credentials vulnerability in Toshiba Lighting & Technology Corporation Home gateway | 2017-06-28T10:23+09:00 | 2018-02-14T12:10+09:00 |
| jvndb-2017-000148 | Improper access control vulnerability in Toshiba Lighting & Technology Corporation Home gateway | 2017-06-28T10:23+09:00 | 2018-02-14T12:10+09:00 |
| jvndb-2017-000144 | Denshi Nyusatsu Check Tool provided by Ministry of Education, Culture, Sports, Science and Technology may insecurely load Dynamic Link Libraries | 2017-06-26T14:28+09:00 | 2018-02-07T13:40+09:00 |
| jvndb-2017-000142 | Installer of Charamin OMP may insecurely load Dynamic Link Libraries | 2017-06-23T14:38+09:00 | 2018-02-07T12:32+09:00 |
| jvndb-2017-000120 | [Simeji for Windows] installer may insecurely load Dynamic Link Libraries | 2017-06-21T18:15+09:00 | 2017-06-21T18:15+09:00 |
| jvndb-2017-000138 | HOME SPOT CUBE2 vulnerable to improper authentication in WebUI | 2017-06-21T13:45+09:00 | 2018-02-14T11:59+09:00 |
| jvndb-2017-000137 | HOME SPOT CUBE2 vulnerable to OS command injection in WebUI | 2017-06-21T13:45+09:00 | 2018-02-14T11:59+09:00 |
| jvndb-2017-000136 | HOME SPOT CUBE2 vulnerable to buffer overflow in WebUI | 2017-06-21T13:44+09:00 | 2018-02-14T11:59+09:00 |
| jvndb-2017-000135 | HOME SPOT CUBE2 vulnerable to OS command injection in clock settings | 2017-06-21T13:44+09:00 | 2018-02-14T11:54+09:00 |
| jvndb-2017-000141 | Multiple I-O DATA network camera products vulnerable to cross-site request forgery | 2017-06-20T13:59+09:00 | 2018-02-14T12:10+09:00 |
| jvndb-2017-000140 | WordPress plugin "Event Calendar WD" vulnerable to cross-site scripting | 2017-06-20T13:58+09:00 | 2018-02-14T12:10+09:00 |
| jvndb-2017-000139 | WordPress plugin "WP Job Manager" fails to restrict access permissions | 2017-06-15T14:32+09:00 | 2017-06-15T14:32+09:00 |
| jvndb-2017-000133 | Source code security studying tool iCodeChecker vulnerable to cross-site scripting | 2017-06-13T14:50+09:00 | 2018-02-14T13:48+09:00 |
| jvndb-2017-000132 | WordPress plugin "WP-Members" vulnerable to cross-site scripting | 2017-06-13T14:50+09:00 | 2018-02-07T11:52+09:00 |
| jvndb-2017-000128 | Open redirect vulnerability in WordPress plugin "WordPress Download Manager" | 2017-06-13T14:11+09:00 | 2018-01-24T12:21+09:00 |
| jvndb-2017-000127 | Cross-site scripting vulnerability in WordPress plugin "WordPress Download Manager" | 2017-06-13T14:11+09:00 | 2018-01-24T12:24+09:00 |
| jvndb-2017-000116 | Installer of QuickTime for Windows may insecurely load Dynamic Link Libraries | 2017-06-13T13:51+09:00 | 2018-02-14T11:58+09:00 |
| jvndb-2017-000130 | Installer of electronic tendering and bid opening system provided by Acquisition, Technology & Logistics Agency may insecurely invoke an executable file | 2017-06-12T14:49+09:00 | 2018-02-14T13:52+09:00 |
| jvndb-2017-000131 | Cybozu KUNAI for Android vulnerable to cross-site scripting | 2017-06-12T13:36+09:00 | 2018-01-24T12:34+09:00 |
| jvndb-2017-000129 | Installer of "Setup file of advance preparation" may insecurely load Dinamic Link Libraries | 2017-06-09T15:59+09:00 | 2018-02-14T13:55+09:00 |
| jvndb-2017-000126 | Installer of Denshinouhin Check System (for Ministry of Agriculture, Forestry and Fisheries Nouson Seibi Jigyou) may insecurely load Dynamic Link Libraries | 2017-06-09T15:48+09:00 | 2018-02-14T14:00+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0649 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-08-01T00:00:00.000000 | 2025-08-01T00:00:00.000000 |
| certfr-2025-avi-0648 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-08-01T00:00:00.000000 | 2025-08-01T00:00:00.000000 |
| certfr-2025-avi-0647 | Vulnérabilité dans Squid | 2025-08-01T00:00:00.000000 | 2025-08-01T00:00:00.000000 |
| certfr-2025-avi-0646 | Vulnérabilité dans Microsoft Edge | 2025-08-01T00:00:00.000000 | 2025-08-01T00:00:00.000000 |
| certfr-2025-avi-0645 | Multiples vulnérabilités dans Asterisk | 2025-08-01T00:00:00.000000 | 2025-08-01T00:00:00.000000 |
| certfr-2025-avi-0644 | Vulnérabilité dans Progress MOVEit Transfer | 2025-08-01T00:00:00.000000 | 2025-08-01T00:00:00.000000 |
| certfr-2025-avi-0643 | Vulnérabilité dans Mattermost Server | 2025-07-31T00:00:00.000000 | 2025-08-25T00:00:00.000000 |
| certfr-2025-avi-0642 | Multiples vulnérabilités dans Apple Safari | 2025-07-31T00:00:00.000000 | 2025-07-31T00:00:00.000000 |
| certfr-2025-avi-0641 | Multiples vulnérabilités dans les produits Splunk | 2025-07-31T00:00:00.000000 | 2025-07-31T00:00:00.000000 |
| certfr-2025-avi-0640 | Multiples vulnérabilités dans les produits Apple | 2025-07-30T00:00:00.000000 | 2025-07-31T00:00:00.000000 |
| certfr-2025-avi-0639 | Multiples vulnérabilités dans Google Chrome | 2025-07-30T00:00:00.000000 | 2025-07-30T00:00:00.000000 |
| certfr-2025-avi-0638 | Vulnérabilité dans les produits Sonicwall | 2025-07-30T00:00:00.000000 | 2025-07-30T00:00:00.000000 |
| certfr-2025-avi-0637 | Vulnérabilité dans SolarWinds Web Help Desk | 2025-07-30T00:00:00.000000 | 2025-07-30T00:00:00.000000 |
| certfr-2025-avi-0636 | Multiples vulnérabilités dans les produits Elastic | 2025-07-30T00:00:00.000000 | 2025-07-30T00:00:00.000000 |
| certfr-2025-avi-0635 | Vulnérabilité dans VMware vCenter | 2025-07-30T00:00:00.000000 | 2025-07-30T00:00:00.000000 |
| certfr-2025-avi-0634 | Vulnérabilité dans Python | 2025-07-30T00:00:00.000000 | 2025-07-30T00:00:00.000000 |
| certfr-2025-avi-0633 | Vulnérabilité dans Tenable Patch Management | 2025-07-30T00:00:00.000000 | 2025-07-30T00:00:00.000000 |
| certfr-2025-avi-0632 | Multiples vulnérabilités dans GLPI | 2025-07-30T00:00:00.000000 | 2025-07-30T00:00:00.000000 |
| certfr-2025-avi-0631 | Vulnérabilité dans SolarWinds SWOSH | 2025-07-29T00:00:00.000000 | 2025-07-29T00:00:00.000000 |
| certfr-2025-avi-0630 | Vulnérabilité dans Palo Alto Networks GlobalProtect App | 2025-07-29T00:00:00.000000 | 2025-07-29T00:00:00.000000 |
| certfr-2025-avi-0629 | Multiples vulnérabilités dans Microsoft Edge | 2025-07-28T00:00:00.000000 | 2025-07-28T00:00:00.000000 |
| certfr-2025-avi-0628 | Multiples vulnérabilités dans Synology BeeDrive | 2025-07-28T00:00:00.000000 | 2025-07-28T00:00:00.000000 |
| certfr-2025-avi-0627 | Multiples vulnérabilités dans les produits IBM | 2025-07-25T00:00:00.000000 | 2025-07-25T00:00:00.000000 |
| certfr-2025-avi-0626 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-07-25T00:00:00.000000 | 2025-07-25T00:00:00.000000 |
| certfr-2025-avi-0625 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-07-25T00:00:00.000000 | 2025-07-25T00:00:00.000000 |
| certfr-2025-avi-0624 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-07-25T00:00:00.000000 | 2025-07-25T00:00:00.000000 |
| certfr-2025-avi-0623 | Multiples vulnérabilités dans les produits ESET | 2025-07-25T00:00:00.000000 | 2025-07-25T00:00:00.000000 |
| certfr-2025-avi-0622 | Multiples vulnérabilités dans les produits VMware | 2025-07-25T00:00:00.000000 | 2025-07-25T00:00:00.000000 |
| certfr-2025-avi-0621 | Multiples vulnérabilités dans les produits Tenable | 2025-07-24T00:00:00.000000 | 2025-07-24T00:00:00.000000 |
| certfr-2025-avi-0620 | Vulnérabilité dans Apache HTTP Server | 2025-07-24T00:00:00.000000 | 2025-07-24T00:00:00.000000 |