Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2025-61886 | 4.9 (v3.1) | An Improper Neutralization of Input During Web Pa… |
Fortinet |
FortiSandbox PaaS |
2026-04-14T15:38:21.587Z | 2026-04-14T16:46:15.066Z |
| cve-2026-39810 | 5.2 (v3.1) | A use of hard-coded cryptographic key vulnerabili… |
Fortinet |
FortiClientEMS |
2026-04-14T15:38:21.194Z | 2026-04-14T17:41:54.082Z |
| cve-2026-39811 | 4.4 (v3.1) | A integer overflow or wraparound vulnerability in… |
Fortinet |
FortiWeb |
2026-04-14T15:38:20.186Z | 2026-04-14T16:46:15.353Z |
| cve-2024-23104 | 5.4 (v3.1) | An exposure of sensitive information to an unauth… |
Fortinet |
FortiVoice |
2026-04-14T15:38:18.540Z | 2026-04-14T16:46:15.501Z |
| cve-2026-39812 | 4.3 (v3.1) | A improper neutralization of input during web pag… |
Fortinet |
FortiSandbox |
2026-04-14T15:38:18.366Z | 2026-04-14T16:46:15.629Z |
| cve-2026-23708 | 6.7 (v3.1) | A improper authentication vulnerability in Fortin… |
Fortinet |
FortiSOAR PaaS |
2026-04-14T15:38:18.327Z | 2026-04-15T03:58:22.574Z |
| cve-2026-39814 | 6.2 (v3.1) | A relative path traversal vulnerability in Fortin… |
Fortinet |
FortiWeb |
2026-04-14T15:38:16.660Z | 2026-04-15T03:58:21.366Z |
| cve-2026-25691 | 6.2 (v3.1) | A improper limitation of a pathname to a restrict… |
Fortinet |
FortiSandbox PaaS |
2026-04-14T15:38:16.406Z | 2026-04-14T16:46:16.085Z |
| cve-2025-59809 | 4.1 (v3.1) | A server-side request forgery (ssrf) vulnerabilit… |
Fortinet |
FortiSOAR on-premise |
2026-04-14T15:38:15.104Z | 2026-04-14T16:46:16.247Z |
| cve-2026-22155 | 6.2 (v3.1) | A cleartext transmission of sensitive information… |
Fortinet |
FortiSOAR on-premise |
2026-04-14T15:38:13.806Z | 2026-04-14T16:46:16.501Z |
| cve-2026-21742 | 5.4 (v3.1) | A cleartext transmission of sensitive information… |
Fortinet |
FortiSOAR PaaS |
2026-04-14T15:38:13.389Z | 2026-04-14T16:46:16.652Z |
| cve-2026-22574 | 4.1 (v3.1) | A storing passwords in a recoverable format vulne… |
Fortinet |
FortiSOAR PaaS |
2026-04-14T15:38:08.130Z | 2026-04-14T16:46:16.794Z |
| cve-2026-22154 | 4.4 (v3.1) | An improper neutralization of input during web pa… |
Fortinet |
FortiSOAR PaaS |
2026-04-14T15:38:07.043Z | 2026-04-14T16:46:17.029Z |
| cve-2025-53847 | 6.2 (v3.1) | A missing authentication for critical function vu… |
Fortinet |
FortiOS |
2026-04-14T15:38:06.336Z | 2026-04-14T16:46:17.175Z |
| cve-2026-22576 | 4.1 (v3.1) | A storing passwords in a recoverable format vulne… |
Fortinet |
FortiSOAR PaaS |
2026-04-14T15:38:05.576Z | 2026-04-14T16:46:17.327Z |
| cve-2026-27316 | 2.5 (v3.1) | A insufficiently protected credentials vulnerabil… |
Fortinet |
FortiSandbox |
2026-04-14T15:38:02.149Z | 2026-04-14T16:46:17.486Z |
| cve-2026-39808 | 9.1 (v3.1) | A improper neutralization of special elements use… |
Fortinet |
FortiSandbox |
2026-04-14T15:38:02.089Z | 2026-04-22T13:56:10.055Z |
| cve-2026-2401 | 2.4 (v4.0) | CWE-532 Insertion of Sensitive Information into L… |
Schneider Electric |
PowerChute™ Serial Shutdown |
2026-04-14T15:24:17.233Z | 2026-04-14T16:27:16.331Z |
| cve-2026-2400 | 5.3 (v4.0) | CWE-93 Improper Neutralization of CRLF Sequences … |
Schneider Electric |
PowerChute™ Serial Shutdown |
2026-04-14T15:22:53.245Z | 2026-04-14T16:27:22.220Z |
| cve-2026-2403 | 5.3 (v4.0) | CWE-1284 Improper Validation of Specified Quantit… |
Schneider Electric |
PowerChute™ Serial Shutdown |
2026-04-14T15:21:10.802Z | 2026-04-14T16:27:27.629Z |
| cve-2026-2405 | 5.3 (v4.0) | CWE-400 Uncontrolled Resource Consumption vulnera… |
Schneider Electric |
PowerChute™ Serial Shutdown |
2026-04-14T15:19:40.765Z | 2026-04-14T16:27:33.148Z |
| cve-2026-2402 | 6.9 (v4.0) | CWE-307 Improper Restriction of Excessive Authent… |
Schneider Electric |
PowerChute™ Serial Shutdown |
2026-04-14T15:16:17.583Z | 2026-04-14T16:27:38.566Z |
| cve-2026-2404 | 6.9 (v4.0) | CWE-116 Improper Encoding or Escaping of Output v… |
Schneider Electric |
PowerChute™ Serial Shutdown |
2026-04-14T15:13:50.351Z | 2026-04-14T16:27:43.927Z |
| cve-2026-5713 | 5.3 (v4.0) | Out-of-bounds read/write during remote profiling and a… |
Python Software Foundation |
CPython |
2026-04-14T15:11:51.122Z | 2026-04-15T17:24:22.172Z |
| cve-2026-2399 | 6.9 (v4.0) | CWE-22 Improper Limitation of a Pathname to a Res… |
Schneider Electric |
PowerChute™ Serial Shutdown |
2026-04-14T15:09:58.751Z | 2026-04-14T15:52:07.599Z |
| cve-2026-39809 | 6.2 (v3.1) | A improper neutralization of special elements use… |
Fortinet |
FortiClientEMS |
2026-04-14T15:05:56.647Z | 2026-04-15T03:58:18.867Z |
| cve-2026-4832 | 6.9 (v4.0) | CWE-798 Use of Hard-coded Credentials vulnerabili… |
Schneider Electric |
Easergy MiCOM P14x |
2026-04-14T15:05:00.845Z | 2026-04-14T18:16:06.726Z |
| cve-2026-37980 | 6.9 (v3.1) | Org.keycloak.forms.login: keycloak: keycloak: arbitrar… |
Red Hat |
Red Hat Build of Keycloak |
2026-04-14T14:54:42.871Z | 2026-04-14T15:43:02.647Z |
| cve-2026-4914 | 5.4 (v3.1) | Stored XSS in Ivanti N-ITSM before version 2025.4… |
Ivanti |
Neurons for ITSM (On-Premise) |
2026-04-14T14:15:48.101Z | 2026-04-14T17:20:09.361Z |
| cve-2026-4913 | 5.7 (v3.1) | Improper protection of an alternate path in Ivant… |
Ivanti |
Neurons for ITSM (On-Premise) |
2026-04-14T14:10:30.529Z | 2026-04-14T15:07:48.368Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2016-000222 | Cybozu Garoon vulnerable to cross-site scripting | 2016-12-19T12:22+09:00 | 2017-11-27T16:58+09:00 |
| jvndb-2016-000246 | Mutiple SONY Videoconference Systems do not properly perform authentication | 2016-12-16T14:11+09:00 | 2018-01-17T14:03+09:00 |
| jvndb-2016-000245 | Apache ActiveMQ vulnerable to cross-site scripting | 2016-12-13T14:00+09:00 | 2018-04-04T12:25+09:00 |
| jvndb-2016-000244 | Access restriction bypass to delete DBM files in Cybozu Dezie | 2016-12-12T14:49+09:00 | 2017-11-27T17:12+09:00 |
| jvndb-2016-000243 | Access restriction bypass to download DBM files in Cybozu Dezie | 2016-12-12T14:49+09:00 | 2017-11-27T17:12+09:00 |
| jvndb-2016-006114 | The Bank of Tokyo-Mitsubishi UFJ for Android vulnerable to SSL/TLS downgrade attack | 2016-12-08T11:33+09:00 | 2018-02-28T11:47+09:00 |
| jvndb-2016-000242 | Sleipnir for Mac vulnerable to URL spoofing | 2016-12-07T14:44+09:00 | 2018-01-17T11:48+09:00 |
| jvndb-2016-002331 | ManageEngine Password Manager Pro fails to restrict access permissions | 2016-12-05T15:02+09:00 | 2016-12-05T15:02+09:00 |
| jvndb-2016-002298 | Keitai Kit for Movable Type vulnerable to OS command injection | 2016-12-05T15:02+09:00 | 2016-12-05T15:02+09:00 |
| jvndb-2016-006038 | Multiple SONY network cameras vulnerable to sensitive information disclosure | 2016-12-05T14:33+09:00 | 2017-05-23T14:28+09:00 |
| jvndb-2016-003380 | ManageEngine Password Manager Pro vulnerable to cross-site request forgery | 2016-12-05T14:32+09:00 | 2017-05-23T16:23+09:00 |
| jvndb-2016-002299 | SaAT Netizen fails to properly verify downloaded installation and update files | 2016-12-05T13:52+09:00 | 2024-06-27T13:59+09:00 |
| jvndb-2016-000241 | WNC01WH vulnerable to directory traversal due to an issue in processing POST request | 2016-12-02T14:46+09:00 | 2017-11-27T17:11+09:00 |
| jvndb-2016-000240 | WNC01WH vulnerable to directory traversal due to an issue in processing commands | 2016-12-02T14:45+09:00 | 2017-11-27T16:27+09:00 |
| jvndb-2016-000239 | WNC01WH vulnerable to enabling debug option | 2016-12-02T14:44+09:00 | 2017-11-27T16:27+09:00 |
| jvndb-2016-000238 | WNC01WH vulnerable to stored cross-site scripting | 2016-12-02T14:43+09:00 | 2017-11-27T16:27+09:00 |
| jvndb-2016-000237 | WNC01WH vulnerable to cross-site request forgery | 2016-12-02T14:43+09:00 | 2017-11-27T16:27+09:00 |
| jvndb-2016-000236 | WNC01WH vulnerable to denial-of-service (DoS) | 2016-12-02T14:43+09:00 | 2017-11-27T16:27+09:00 |
| jvndb-2016-000233 | The installers of multiple Japan Pension Service software may insecurely load Dynamic Link Libraries | 2016-12-01T13:40+09:00 | 2018-01-17T13:54+09:00 |
| jvndb-2016-000235 | Multiple I-O DATA network camera products vulnerable to buffer overflow | 2016-11-30T15:17+09:00 | 2018-01-17T11:48+09:00 |
| jvndb-2016-000234 | Multiple I-O DATA network camera products vulnerable to OS command injection | 2016-11-30T15:17+09:00 | 2018-01-17T11:52+09:00 |
| jvndb-2016-000231 | kintone mobile for Android fails to verify SSL server certificates | 2016-11-28T13:47+09:00 | 2018-01-17T12:34+09:00 |
| jvndb-2016-000232 | Simple keitai chat vulnerable to cross-site scripting | 2016-11-25T13:54+09:00 | 2018-01-17T11:57+09:00 |
| jvndb-2016-000220 | DERAEMON-CMS vulnerable to cross-site scripting | 2016-11-15T13:41+09:00 | 2018-01-17T12:09+09:00 |
| jvndb-2016-000219 | CG-WLR300NX fails to restrict access permissions | 2016-11-11T14:50+09:00 | 2018-01-17T12:09+09:00 |
| jvndb-2016-000218 | CG-WLR300NX vulnerable to cross-site scripting | 2016-11-11T14:49+09:00 | 2018-01-17T12:18+09:00 |
| jvndb-2016-000217 | CG-WLR300NX vulnerable to cross-site request forgery | 2016-11-11T14:49+09:00 | 2018-01-17T12:18+09:00 |
| jvndb-2016-000216 | Multiple Corega wireless LAN routers vulnerable to cross-site scripting | 2016-11-11T14:45+09:00 | 2017-11-27T16:42+09:00 |
| jvndb-2016-000221 | Multiple I-O DATA network camera products vulnerable to information disclosure | 2016-11-11T13:51+09:00 | 2018-01-17T12:02+09:00 |
| jvndb-2016-005655 | Vulnerabilitie in JP1/IT Desktop Management 2 - Manager and JP1/NETM/DM | 2016-11-10T16:59+09:00 | 2016-11-10T16:59+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-1089 | Vulnérabilité dans les produits StormShield Management Center | 2024-12-17T00:00:00.000000 | 2024-12-17T00:00:00.000000 |
| certfr-2024-avi-1088 | Multiples vulnérabilités dans les produits Foxit | 2024-12-17T00:00:00.000000 | 2024-12-17T00:00:00.000000 |
| certfr-2024-avi-1087 | Vulnérabilité dans les produits Siemens | 2024-12-17T00:00:00.000000 | 2024-12-17T00:00:00.000000 |
| certfr-2024-avi-1086 | Multiples vulnérabilités dans Trend Micro Apex One | 2024-12-17T00:00:00.000000 | 2024-12-17T00:00:00.000000 |
| certfr-2024-avi-1085 | Multiples vulnérabilités dans Moodle | 2024-12-17T00:00:00.000000 | 2024-12-17T00:00:00.000000 |
| certfr-2024-avi-1084 | Vulnérabilité dans SolarWinds Web Help Desk | 2024-12-16T00:00:00.000000 | 2024-12-16T00:00:00.000000 |
| certfr-2024-avi-1083 | Multiples vulnérabilités dans Mozilla Thunderbird | 2024-12-16T00:00:00.000000 | 2024-12-16T00:00:00.000000 |
| certfr-2024-avi-1082 | Multiples vulnérabilités dans les produits Synology | 2024-12-16T00:00:00.000000 | 2024-12-16T00:00:00.000000 |
| certfr-2024-avi-1081 | Multiples vulnérabilités dans les produits IBM | 2024-12-13T00:00:00.000000 | 2024-12-13T00:00:00.000000 |
| certfr-2024-avi-1080 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-12-13T00:00:00.000000 | 2024-12-13T00:00:00.000000 |
| certfr-2024-avi-1079 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-12-13T00:00:00.000000 | 2024-12-13T00:00:00.000000 |
| certfr-2024-avi-1078 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2024-12-13T00:00:00.000000 | 2024-12-13T00:00:00.000000 |
| certfr-2024-avi-1077 | Multiples vulnérabilités dans Microsoft Edge | 2024-12-13T00:00:00.000000 | 2024-12-13T00:00:00.000000 |
| certfr-2024-avi-1076 | Multiples vulnérabilités dans Suricata | 2024-12-13T00:00:00.000000 | 2024-12-13T00:00:00.000000 |
| certfr-2024-avi-1075 | Multiples vulnérabilités dans Nagios XI | 2024-12-13T00:00:00.000000 | 2024-12-13T00:00:00.000000 |
| certfr-2024-avi-1074 | Multiples vulnérabilités dans les produits Palo Alto Networks | 2024-12-12T00:00:00.000000 | 2024-12-12T00:00:00.000000 |
| certfr-2024-avi-1073 | Vulnérabilité dans les produits Mozilla | 2024-12-12T00:00:00.000000 | 2024-12-12T00:00:00.000000 |
| certfr-2024-avi-1072 | Multiples vulnérabilités dans les produits Apple | 2024-12-12T00:00:00.000000 | 2024-12-12T00:00:00.000000 |
| certfr-2024-avi-1071 | Multiples vulnérabilités dans les produits Tenable | 2024-12-12T00:00:00.000000 | 2024-12-12T00:00:00.000000 |
| certfr-2024-avi-1070 | Multiples vulnérabilités dans les produits Microsoft | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1069 | Multiples vulnérabilités dans Microsoft Windows | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1068 | Multiples vulnérabilités dans Microsoft Office | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1067 | Multiples vulnérabilités dans les produits Atlassian | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1066 | Vulnérabilité dans Apache Struts | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1065 | Multiples vulnérabilités dans GitLab | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1064 | Multiples vulnérabilités dans GLPI | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1063 | Vulnérabilité dans cURL et libcurl | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1062 | Multiples vulnérabilités dans les produits Siemens | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1061 | Multiples vulnérabilités dans les produits Splunk | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1060 | Multiples vulnérabilités dans Ruby on Rails | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |