Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-70419 | 9.1 (v3.1) | Dell Cloud Disaster Recovery, versions 20.2 and p… |
Dell |
Cloud Disaster Recovery |
2026-08-26T18:24:28.070Z | 2026-08-26T18:52:08.264Z |
| cve-2026-79940 | 5.9 (v3.1) | Dell iDRAC9, 14G versions prior to 7.00.00.182 an… |
Dell |
iDRAC9 |
2026-08-26T18:16:42.618Z | 2026-08-26T19:46:27.415Z |
| cve-2026-63179 | Winter: Local File Inclusion through @import directive… |
wintercms |
winter |
2026-08-26T18:06:14.103Z | 2026-08-26T18:51:15.095Z | |
| cve-2026-19485 | 9.3 (v4.0) | Bucket Squatting in Vertex AI Search for Commerce |
Google Cloud |
Vertex AI Search for Commerce |
2026-08-26T18:06:00.596Z | 2026-08-26T19:04:26.776Z |
| cve-2026-54256 | Winter: Authenticated IDOR in backend FileUpload widge… |
wintercms |
winter |
2026-08-26T17:53:36.237Z | 2026-08-27T14:33:39.110Z | |
| cve-2026-32639 | Winter: Broken access control in `Cms\Controllers\Inde… |
wintercms |
winter |
2026-08-26T17:50:32.102Z | 2026-08-29T02:46:44.275Z | |
| cve-2026-58474 | 8.6 (v4.0) 8.8 (v3.1) | whichllm < 0.5.16 Code Injection via run and snippet c… |
Andyyyy64 |
whichllm |
2026-08-26T17:49:04.041Z | 2026-08-29T11:47:31.365Z |
| cve-2026-76784 | 8.7 (v4.0) | Insufficient Cryptographic Protections in Local Device… |
TP-Link Systems Inc. |
HS103P3 / HS103P4 v5 |
2026-08-26T17:47:54.278Z | 2026-08-26T18:50:19.860Z |
| cve-2026-32593 | Winter: SQL Injection in Backend Filter Widget numberr… |
wintercms |
winter |
2026-08-26T17:27:07.836Z | 2026-08-26T18:29:20.480Z | |
| cve-2026-47841 | 7.4 (v3.1) | WebAuthn User Verification Bypass via Session Serialization |
Spring |
Spring Security |
2026-08-26T17:08:52.788Z | 2026-08-27T03:58:22.127Z |
| cve-2026-47837 | 6.8 (v3.1) | Spring Cloud Config Server Monitor Endpoint Does Not V… |
Spring |
Spring Cloud Config |
2026-08-26T17:08:51.832Z | 2026-08-26T18:50:49.428Z |
| cve-2026-47836 | 7.2 (v3.1) | Spring Cloud Config Server Susceptible To TOCTOU Attac… |
Spring |
Spring Cloud Config |
2026-08-26T17:05:21.979Z | 2026-08-27T03:58:24.390Z |
| cve-2026-32258 | Winter: Stored XSS through Editor Settings custom styles |
wintercms |
winter |
2026-08-26T16:49:06.852Z | 2026-08-26T17:35:11.529Z | |
| cve-2026-32257 | Winter: Stored XSS through Brand Settings custom styles |
wintercms |
winter |
2026-08-26T16:45:12.100Z | 2026-08-27T14:33:49.017Z | |
| cve-2026-35445 | Winter: Authenticated backend users can bypass Users c… |
wintercms |
winter |
2026-08-26T16:40:51.500Z | 2026-08-26T19:08:44.974Z | |
| cve-2026-81036 | 8.5 (v4.0) 8.1 (v3.1) | Stalwart Mail Server through 0.16.19 Authorization Cod… |
stalwartlabs |
stalwart |
2026-08-26T15:45:02.931Z | 2026-08-29T02:45:24.847Z |
| cve-2026-81035 | 7.2 (v4.0) 8.1 (v3.1) | Midday Missing Owner Check on Team Deletion |
midday-ai |
midday |
2026-08-26T15:45:02.234Z | 2026-08-26T16:06:39.105Z |
| cve-2026-81034 | 8.3 (v4.0) 6.5 (v3.1) | Netmaker through 1.6.0 Improper Certificate Validation… |
gravitl |
netmaker |
2026-08-26T15:45:01.529Z | 2026-08-26T18:31:47.883Z |
| cve-2026-81033 | 6.9 (v4.0) 5.3 (v3.1) | Automatisch through 0.15.0 User Enumeration via Forgot… |
automatisch |
automatisch |
2026-08-26T15:45:00.826Z | 2026-08-28T16:00:31.483Z |
| cve-2026-81032 | 9.3 (v4.0) 9.8 (v3.1) | NebulaGraph through 3.8.0 Unauthenticated Read and Mod… |
vesoft-inc |
nebula |
2026-08-26T15:45:00.144Z | 2026-08-26T17:10:45.206Z |
| cve-2026-81031 | 8.6 (v4.0) 7.2 (v3.1) | IDURAR ERP CRM through 4.1.1 Account Takeover via Unve… |
idurar |
idurar-erp-crm |
2026-08-26T15:44:59.362Z | 2026-08-29T02:43:32.712Z |
| cve-2026-81030 | 7.1 (v4.0) 6.5 (v3.1) | Mage AI through 0.9.79 Arbitrary File Read via Unvalid… |
mage-ai |
mage-ai |
2026-08-26T15:44:58.663Z | 2026-08-26T16:05:12.110Z |
| cve-2026-81029 | 8.5 (v4.0) 8.1 (v3.1) | OpenMetadata before 2.0.0 JWT Disclosure via Unvalidat… |
open-metadata |
OpenMetadata |
2026-08-26T15:44:57.988Z | 2026-08-26T18:32:59.057Z |
| cve-2026-81028 | 6.9 (v4.0) 4.9 (v3.1) | ZLMediaKit downloadFile Root-Directory Confinement Byp… |
ZLMediaKit |
ZLMediaKit |
2026-08-26T15:44:57.303Z | 2026-08-28T16:00:38.893Z |
| cve-2026-81027 | 8.4 (v4.0) 8.5 (v3.1) | one-api through 0.6.10 Missing Authorization on URL-Pa… |
songquanpeng |
one-api |
2026-08-26T15:44:56.599Z | 2026-08-26T17:25:39.276Z |
| cve-2026-80428 | 9.3 (v4.0) 9.8 (v3.1) | ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP … |
ILIAS-eLearning e.V. |
ILIAS |
2026-08-26T15:44:55.917Z | 2026-08-29T02:41:40.892Z |
| cve-2026-80427 | 8.6 (v4.0) 8.4 (v3.1) | bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument I… |
nfriedly |
bestzip |
2026-08-26T15:44:55.220Z | 2026-08-29T11:48:06.751Z |
| cve-2026-80426 | 7 (v4.0) 7.1 (v3.1) | FiftyOne before 1.21.0 Stored Cross-Site Scripting via… |
voxel51 |
fiftyone |
2026-08-26T15:44:54.517Z | 2026-08-29T11:48:06.089Z |
| cve-2026-48549 | 6.9 (v4.0) 6.5 (v3.1) | Nagios Core / XI CSRF via cmd.cgi Double-Submit Cookie |
Nagios Enterprises, LLC. |
Nagios Core |
2026-08-26T15:37:20.083Z | 2026-08-28T16:00:44.978Z |
| cve-2026-48548 | 6.9 (v4.0) 6.5 (v3.1) | Nagios Core CSRF via cmd.cgi |
Nagios Enterprises, LLC. |
Nagios Core |
2026-08-26T15:33:59.685Z | 2026-08-26T17:29:31.213Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2017-000117 | Installer of CASL II simulator(self-extract format) may insecurely load Dynamic Link Libraries | 2017-06-09T13:49+09:00 | 2018-02-14T11:58+09:00 |
| jvndb-2017-000124 | The installer of SemiDynaEXE provided by Geospatial Information Authority of Japan (GSI) may insecurely load Dynamic Link Libraries | 2017-06-08T15:31+09:00 | 2018-01-24T12:15+09:00 |
| jvndb-2017-000123 | The installer of TKY2JGD provided by Geospatial Information Authority of Japan (GSI) may insecurely load Dynamic Link Libraries | 2017-06-08T15:31+09:00 | 2018-01-24T12:15+09:00 |
| jvndb-2017-000122 | The installer of PatchJGD(Hyoko) provided by Geospatial Information Authority of Japan (GSI) may insecurely load Dynamic Link Libraries | 2017-06-08T15:31+09:00 | 2018-01-24T12:15+09:00 |
| jvndb-2017-000121 | The installer of PatchJGD provided by Geospatial Information Authority of Japan (GSI) may insecurely load Dynamic Link Libraries | 2017-06-08T15:31+09:00 | 2018-01-24T12:15+09:00 |
| jvndb-2017-000125 | AppCheck may insecurely invoke an executable file | 2017-06-07T14:54+09:00 | 2018-01-24T12:15+09:00 |
| jvndb-2017-000115 | WordPress plugin "Multi Feed Reader" vulnerable to SQL injection | 2017-06-06T14:54+09:00 | 2018-01-17T13:58+09:00 |
| jvndb-2017-000113 | Hands-on Vulnerability Learning Tool "AppGoat" vulnerable to remote code execution | 2017-06-06T14:21+09:00 | 2017-11-27T17:22+09:00 |
| jvndb-2017-000112 | Hands-on Vulnerability Learning Tool "AppGoat" vulnerable to information disclosure | 2017-06-06T14:20+09:00 | 2017-11-27T17:22+09:00 |
| jvndb-2017-000114 | Hands-on Vulnerability Learning Tool "AppGoat" vulnerable to remote code execution | 2017-06-06T14:19+09:00 | 2017-11-27T17:22+09:00 |
| jvndb-2017-000111 | Hands-on Vulnerability Learning Tool "AppGoat" vulnerable to remote code execution | 2017-06-06T14:19+09:00 | 2017-11-27T17:22+09:00 |
| jvndb-2017-000102 | The installer of the Ministry of Justice [The electronic authentication system based on the commercial registration system "The CRCA user's Software"] may insecurely load Dynamic Link Libraries | 2017-06-06T11:19+09:00 | 2018-01-17T13:58+09:00 |
| jvndb-2017-000119 | Installer of Houkokusyo Sakusei Shien Tool provided by Ministry of the Environment may insecurely load Dynamic Link Libraries | 2017-06-05T13:47+09:00 | 2018-01-17T13:49+09:00 |
| jvndb-2017-000110 | Installer of SaAT Personal may insecurely load Dynamic Link Libraries | 2017-06-02T14:00+09:00 | 2018-01-17T12:25+09:00 |
| jvndb-2017-000109 | Installer of SaAT Netizen may insecurely load Dynamic Link Libraries | 2017-06-02T14:00+09:00 | 2018-01-17T12:29+09:00 |
| jvndb-2017-000107 | RW-5100 tool to verify execution environment may insecurely load Dynamic Link Libraries | 2017-06-01T16:47+09:00 | 2018-01-24T14:03+09:00 |
| jvndb-2017-000106 | RW-5100 driver installer may insecurely load Dynamic Link Libraries | 2017-06-01T16:44+09:00 | 2018-01-24T14:15+09:00 |
| jvndb-2017-000105 | RW-4040 tool to verify execution environment may insecurely load Dynamic Link Libraries | 2017-06-01T16:40+09:00 | 2018-01-24T14:05+09:00 |
| jvndb-2017-000104 | RW-4040 driver installer may insecurely load Dynamic Link Libraries | 2017-06-01T16:25+09:00 | 2018-01-24T13:57+09:00 |
| jvndb-2017-000108 | Installer of Tera Term may insecurely load Dynamic Link Libraries | 2017-06-01T14:42+09:00 | 2018-01-24T14:20+09:00 |
| jvndb-2017-000103 | WordPress plugin "WP Live Chat Support" vulnerable to cross-site scripting | 2017-06-01T14:06+09:00 | 2017-11-27T16:47+09:00 |
| jvndb-2017-000101 | Installers of the screensavers provided by JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE may insecurely load Dynamic Link Libraries | 2017-05-25T14:14+09:00 | 2018-02-15T15:30+09:00 |
| jvndb-2017-000100 | Installer of electronic tendering and bid opening system provided by Acquisition, Technology & Logistics Agency may insecurely load Dynamic Link Libraries | 2017-05-25T14:14+09:00 | 2018-01-17T13:58+09:00 |
| jvndb-2017-000089 | GroupSession fails to restrict access permissions | 2017-05-25T14:14+09:00 | 2018-01-24T11:59+09:00 |
| jvndb-2017-000099 | SSL Visibility Appliance may generate illegal RST packets | 2017-05-24T14:41+09:00 | 2017-05-31T19:27+09:00 |
| jvndb-2017-000098 | The installer of Empirical Project Monitor - eXtended may insecurely load Dynamic Link Libraries | 2017-05-19T14:57+09:00 | 2017-11-27T18:01+09:00 |
| jvndb-2017-000097 | Empirical Project Monitor - eXtended vulnerable to cross-site scripting | 2017-05-19T14:55+09:00 | 2017-11-27T18:01+09:00 |
| jvndb-2017-000096 | Empirical Project Monitor - eXtended vulnerable to cross-site scripting | 2017-05-19T14:53+09:00 | 2017-11-27T18:01+09:00 |
| jvndb-2017-000091 | FlashAir do not set credential information in PhotoShare | 2017-05-16T15:46+09:00 | 2017-12-21T19:16+09:00 |
| jvndb-2017-000090 | FlashAir fails to restrict access permissions in PhotoShare | 2017-05-16T15:34+09:00 | 2017-12-21T19:13+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0619 | Multiples vulnérabilités dans GitLab | 2025-07-24T00:00:00.000000 | 2025-07-24T00:00:00.000000 |
| certfr-2025-avi-0618 | Multiples vulnérabilités dans les produits Mitel | 2025-07-24T00:00:00.000000 | 2026-01-28T00:00:00.000000 |
| certfr-2025-avi-0617 | Vulnérabilité dans Sonicwall Secure Mobile Access | 2025-07-24T00:00:00.000000 | 2025-07-24T00:00:00.000000 |
| certfr-2025-avi-0616 | Multiples vulnérabilités dans Sonicwall Secure Mobile Access | 2025-07-23T00:00:00.000000 | 2025-07-23T00:00:00.000000 |
| certfr-2025-avi-0615 | Multiples vulnérabilités dans les produits Mozilla | 2025-07-23T00:00:00.000000 | 2025-07-23T00:00:00.000000 |
| certfr-2025-avi-0614 | Multiples vulnérabilités dans les produits Mattermost | 2025-07-23T00:00:00.000000 | 2025-08-21T00:00:00.000000 |
| certfr-2025-avi-0613 | Multiples vulnérabilités dans Google Chrome | 2025-07-23T00:00:00.000000 | 2025-07-23T00:00:00.000000 |
| certfr-2025-avi-0612 | Multiples vulnérabilités dans Sophos Firewall | 2025-07-22T00:00:00.000000 | 2025-07-22T00:00:00.000000 |
| certfr-2025-avi-0611 | Multiples vulnérabilités dans les produits Microsoft | 2025-07-21T00:00:00.000000 | 2025-07-22T00:00:00.000000 |
| certfr-2025-avi-0610 | Multiples vulnérabilités dans Microsoft Azure | 2025-07-21T00:00:00.000000 | 2025-07-21T00:00:00.000000 |
| certfr-2025-avi-0609 | Multiples vulnérabilités dans Synacor Zimbra Collaboration | 2025-07-21T00:00:00.000000 | 2025-07-23T00:00:00.000000 |
| certfr-2025-avi-0608 | Multiples vulnérabilités dans les produits IBM | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0607 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0606 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0605 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0604 | Multiples vulnérabilités dans Oracle Weblogic | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0603 | Multiples vulnérabilités dans Oracle Virtualization | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0602 | Multiples vulnérabilités dans Oracle PeopleSoft | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0601 | Multiples vulnérabilités dans Oracle MySQL | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0600 | Multiples vulnérabilités dans Oracle Java SE | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0599 | Multiples vulnérabilités dans Oracle Database Server | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0598 | Multiples vulnérabilités dans Sophos Intercept X | 2025-07-18T00:00:00.000000 | 2025-07-22T00:00:00.000000 |
| certfr-2025-avi-0597 | Multiples vulnérabilités dans Grafana | 2025-07-18T00:00:00.000000 | 2025-07-18T00:00:00.000000 |
| certfr-2025-avi-0596 | Multiples vulnérabilités dans ISC BIND | 2025-07-17T00:00:00.000000 | 2025-07-17T00:00:00.000000 |
| certfr-2025-avi-0595 | Vulnérabilité dans Cisco Unified Intelligence Center | 2025-07-17T00:00:00.000000 | 2025-07-17T00:00:00.000000 |
| certfr-2025-avi-0594 | Multiples vulnérabilités dans Microsoft Edge | 2025-07-17T00:00:00.000000 | 2025-07-17T00:00:00.000000 |
| certfr-2025-avi-0593 | Multiples vulnérabilités dans les produits Atlassian | 2025-07-16T00:00:00.000000 | 2025-07-16T00:00:00.000000 |
| certfr-2025-avi-0592 | Multiples vulnérabilités dans les produits VMware | 2025-07-16T00:00:00.000000 | 2025-07-16T00:00:00.000000 |
| certfr-2025-avi-0591 | Multiples vulnérabilités dans Google Chrome | 2025-07-16T00:00:00.000000 | 2025-07-16T00:00:00.000000 |
| certfr-2025-avi-0590 | Multiples vulnérabilités dans les produits IBM | 2025-07-11T00:00:00.000000 | 2025-07-11T00:00:00.000000 |