Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-4344 | 7.1 (v3.1) | Stored Cross-Site Scripting (XSS) Vulnerability in Ass… |
Autodesk |
Fusion |
2026-04-14T13:56:56.801Z | 2026-04-15T03:58:14.791Z |
| cve-2026-4345 | 7.1 (v3.1) | Stored Cross-Site Scripting (XSS) Vulnerability in Des… |
Autodesk |
Fusion |
2026-04-14T13:56:22.111Z | 2026-04-15T03:58:16.255Z |
| cve-2026-4369 | 7.1 (v3.1) | Stored Cross-Site Scripting (XSS) Vulnerability in Ass… |
Autodesk |
Fusion |
2026-04-14T13:47:01.968Z | 2026-04-15T03:58:17.421Z |
| cve-2025-8095 | 9.1 (v4.0) | Recoverable obfuscation using the OECH1 prefix encodin… |
Progress Software Corporation |
OpenEdge |
2026-04-14T13:13:43.739Z | 2026-04-15T03:58:13.601Z |
| cve-2025-7389 | 8.2 (v4.0) | Unauthorized Arbitrary File Read via RMI in AdminServe… |
Progress Software Corporation |
OpenEdge |
2026-04-14T13:12:54.559Z | 2026-04-14T14:04:52.165Z |
| cve-2026-2450 | 7.4 (v4.0) | .NET misconfiguration: use of impersonation vulne… |
upKeeper Solutions |
upKeeper Instant Privilege Access |
2026-04-14T12:07:44.265Z | 2026-04-14T13:14:16.443Z |
| cve-2026-2449 | 9 (v4.0) | Improper neutralization of argument delimiters in… |
upKeeper Solutions |
upKeeper Instant Privilege Access |
2026-04-14T11:56:04.741Z | 2026-04-14T13:14:16.593Z |
| cve-2026-24069 | N/A | Improper Enforcement of Disabled Accounts in WebUI SSO… |
Kiuwan |
SAST |
2026-04-14T11:26:55.274Z | 2026-04-14T18:24:36.801Z |
| cve-2026-2332 | 7.4 (v3.1) | HTTP Request Smuggling via Chunked Extension Quoted-St… |
Eclipse Foundation |
Eclipse Jetty |
2026-04-14T10:59:10.193Z | 2026-04-15T03:58:12.322Z |
| cve-2025-13822 | 5.3 (v4.0) | Authentication bypass in MCPHub |
MCPHub |
MCPHub |
2026-04-14T10:23:49.910Z | 2026-04-14T13:14:16.888Z |
| cve-2026-33892 | A vulnerability has been identified in Industrial… |
Siemens |
Industrial Edge Management Pro V1 |
2026-04-14T08:40:46.807Z | 2026-04-14T13:46:34.636Z | |
| cve-2026-27668 | A vulnerability has been identified in RUGGEDCOM … |
Siemens |
RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) |
2026-04-14T08:40:45.661Z | 2026-04-14T12:58:05.664Z | |
| cve-2026-25654 | A vulnerability has been identified in SINEC NMS … |
Siemens |
SINEC NMS |
2026-04-14T08:40:41.053Z | 2026-04-14T13:46:23.821Z | |
| cve-2026-24032 | A vulnerability has been identified in SINEC NMS … |
Siemens |
SINEC NMS |
2026-04-14T08:40:39.853Z | 2026-04-14T13:18:01.056Z | |
| cve-2025-40745 | A vulnerability has been identified in Siemens So… |
Siemens |
Siemens Software Center |
2026-04-14T08:40:38.637Z | 2026-04-14T13:38:29.751Z | |
| cve-2026-31923 | Apache APISIX: Openid-connect `tls_verify` field is di… |
Apache Software Foundation |
Apache APISIX |
2026-04-14T08:38:59.039Z | 2026-04-14T18:16:34.559Z | |
| cve-2026-33929 | Apache PDFBox Examples: Path Traversal in PDFBox Extra… |
Apache Software Foundation |
Apache PDFBox Examples |
2026-04-14T08:09:39.517Z | 2026-04-14T19:50:07.000Z | |
| cve-2026-31924 | Apache APISIX: Plugin tencent-cloud-cls log export use… |
Apache Software Foundation |
Apache APISIX |
2026-04-14T08:08:05.615Z | 2026-04-14T19:51:55.994Z | |
| cve-2026-31908 | Apache APISIX: forward auth plugin allows header injection |
Apache Software Foundation |
Apache APISIX |
2026-04-14T08:06:18.026Z | 2026-04-16T12:06:00.176Z | |
| cve-2026-4109 | Eventin – Events Calendar, Event Booking, Ticket & Reg… |
arraytics |
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) |
2026-04-14T07:43:03.588Z | 2026-04-14T13:00:42.566Z | |
| cve-2026-2582 | Germanized for WooCommerce <= 3.20.5 - Unauthenticated… |
vendidero |
Germanized for WooCommerce |
2026-04-14T06:43:52.199Z | 2026-04-14T14:04:52.319Z | |
| cve-2026-3017 | Smart Post Show – Post Grid, Post Carousel & Slider, a… |
shapedplugin |
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts |
2026-04-14T05:30:32.830Z | 2026-04-14T13:44:18.666Z | |
| cve-2026-4059 | ShopLentor <= 3.3.5 - Authenticated (Contributor+) Sto… |
devitemsllc |
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin |
2026-04-14T03:37:33.893Z | 2026-04-14T14:04:52.486Z | |
| cve-2026-4479 | WholeSale Products Dynamic Pricing Management WooComme… |
wpcodefactory |
WholeSale Products Dynamic Pricing Management WooCommerce |
2026-04-14T03:37:33.525Z | 2026-04-14T14:04:52.634Z | |
| cve-2026-1607 | Surbma | Booking.com <= 2.1 - Authenticated (Contribut… |
surbma |
Surbma | Booking.com Shortcode |
2026-04-14T03:37:32.795Z | 2026-04-14T13:18:48.779Z | |
| cve-2026-40313 | PraisonAI: ArtiPACKED Vulnerability via GitHub Actions… |
MervinPraison |
PraisonAI |
2026-04-14T03:10:23.697Z | 2026-04-14T16:27:49.836Z | |
| cve-2026-40289 | PraisonAI Browser Server allows unauthenticated WebSoc… |
MervinPraison |
PraisonAI |
2026-04-14T03:05:05.514Z | 2026-04-14T20:18:37.319Z | |
| cve-2026-40288 | PraisonAI: Critical RCE via `type: job` workflow YAML |
MervinPraison |
PraisonAI |
2026-04-14T03:00:21.547Z | 2026-04-14T15:57:15.812Z | |
| cve-2026-40287 | PraisonAI has RCE via Automatic tools.py Import |
MervinPraison |
PraisonAI |
2026-04-14T02:55:38.270Z | 2026-04-14T13:23:29.807Z | |
| cve-2026-40315 | PraisonAI: SQLiteConversationStore didn't validate tab… |
MervinPraison |
PraisonAI |
2026-04-14T02:45:33.880Z | 2026-04-14T13:25:13.165Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2016-000215 | Access restriction bypass vulnerability in WFS-SR01 | 2016-11-02T16:21+09:00 | 2017-11-27T16:42+09:00 |
| jvndb-2016-000214 | Command injection vulnerability in WFS-SR01 | 2016-11-02T16:20+09:00 | 2017-11-27T16:42+09:00 |
| jvndb-2016-000212 | The installer of The Public Certification Service for Individuals "The JPKI user's software" may insecurely load Dynamic Link Libraries | 2016-11-01T16:44+09:00 | 2017-12-25T11:28+09:00 |
| jvndb-2016-000213 | mobiGate App fails to verify SSL server certificates | 2016-11-01T13:47+09:00 | 2018-01-17T12:18+09:00 |
| jvndb-2016-000211 | Installer of 7-Zip for Windows may insecurely load Dynamic Link Libraries | 2016-10-26T15:13+09:00 | 2017-12-25T10:27+09:00 |
| jvndb-2016-000210 | SQL injection vulnerability in WordPress plugin WP-OliveCart | 2016-10-20T14:22+09:00 | 2018-01-17T12:10+09:00 |
| jvndb-2016-000209 | Cross-site request forgery vulnerability in WordPress plugin WP-OliveCart | 2016-10-20T14:22+09:00 | 2018-01-17T12:10+09:00 |
| jvndb-2016-000208 | Cross-site scripting vulnerability in WordPress plugin WP-OliveCart | 2016-10-20T14:22+09:00 | 2018-01-17T12:10+09:00 |
| jvndb-2016-000206 | Installer of Evernote for Windows may insecurely load Dynamic Link Libraries | 2016-10-19T15:32+09:00 | 2017-11-27T18:12+09:00 |
| jvndb-2016-000207 | The installer of e-Tax Software may insecurely load Dynamic Link Libraries | 2016-10-19T12:29+09:00 | 2018-01-17T11:48+09:00 |
| jvndb-2016-000168 | Toshiba FlashAir does not require authentication in "Internet pass-thru Mode" | 2016-10-12T10:03+09:00 | 2017-11-27T17:04+09:00 |
| jvndb-2016-000201 | SetucoCMS vulnerable to session management | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000200 | SetucoCMS vulnerable to code injection | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000199 | SetucoCMS vulnerable to denial-of-service (DoS) | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000198 | SetucoCMS vulnerable to SQL injection | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000197 | SetucoCMS vulnerable to cross-site scripting | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000196 | SetucoCMS vulnerable to cross-site request forgery | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000195 | Cryptography API: Next Generation (CNG) vulnerable to denial-of-service (DoS) | 2016-10-07T14:11+09:00 | 2016-10-07T14:11+09:00 |
| jvndb-2016-000202 | Usermin cross-site scripting vulnerabilties | 2016-10-07T13:50+09:00 | 2017-05-16T17:52+09:00 |
| jvndb-2016-000193 | Cybozu Office vulnerable to Reflected File Download (RFD) | 2016-10-03T15:47+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000192 | Cybozu Office vulnerable to denial-of-service (DoS) | 2016-10-03T15:46+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000191 | Cybozu Office vulnerable to information disclosure | 2016-10-03T15:43+09:00 | 2017-04-24T15:05+09:00 |
| jvndb-2016-000190 | Cybozu Office vulnerable to mail header injection | 2016-10-03T15:43+09:00 | 2017-04-24T15:05+09:00 |
| jvndb-2016-000189 | "Project" function in Cybozu Office vulnerable vulnerable to operation restriction bypass | 2016-10-03T15:43+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000188 | Breadcrumb trail in Cybozu Office vulnerable vulnerable to browse restriction bypass | 2016-10-03T15:43+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000187 | "Project" function in Cybozu Office vulnerable vulnerable to access restriction bypass | 2016-10-03T15:43+09:00 | 2017-04-24T15:05+09:00 |
| jvndb-2016-000186 | "Schedule" function in Cybozu Office vulnerable to cross-site scripting | 2016-10-03T15:43+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000185 | "Project" function in Cybozu Office vulnerable to cross-site scripting | 2016-10-03T15:43+09:00 | 2017-04-24T15:05+09:00 |
| jvndb-2016-000184 | "Customapp" function in Cybozu Office vulnerable to cross-site scripting | 2016-10-03T15:43+09:00 | 2017-04-24T15:05+09:00 |
| jvndb-2016-000194 | Docomo L-04D mobile WiFi router vulnerable to cross-site request forgery | 2016-10-03T15:17+09:00 | 2018-01-17T11:53+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-1059 | Multiples vulnérabilités dans les produits Intel | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1058 | Multiples vulnérabilités dans les produits Ivanti | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1057 | Multiples vulnérabilités dans les produits HPE Aruba Networking | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1056 | Multiples vulnérabilités dans les produits Adobe | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1055 | Multiples vulnérabilités dans Google Chrome | 2024-12-11T00:00:00.000000 | 2024-12-11T00:00:00.000000 |
| certfr-2024-avi-1054 | Multiples vulnérabilités dans les produits SAP | 2024-12-10T00:00:00.000000 | 2024-12-10T00:00:00.000000 |
| certfr-2024-avi-1053 | Multiples vulnérabilités dans les produits Schneider Electric | 2024-12-10T00:00:00.000000 | 2024-12-10T00:00:00.000000 |
| certfr-2024-avi-1052 | Multiples vulnérabilités dans les produits Qnap | 2024-12-09T00:00:00.000000 | 2024-12-09T00:00:00.000000 |
| certfr-2024-avi-1051 | Multiples vulnérabilités dans les produits IBM | 2024-12-06T00:00:00.000000 | 2024-12-06T00:00:00.000000 |
| certfr-2024-avi-1050 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2024-12-06T00:00:00.000000 | 2024-12-06T00:00:00.000000 |
| certfr-2024-avi-1049 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-12-06T00:00:00.000000 | 2024-12-06T00:00:00.000000 |
| certfr-2024-avi-1048 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-12-06T00:00:00.000000 | 2024-12-06T00:00:00.000000 |
| certfr-2024-avi-1047 | Multiples vulnérabilités dans Microsoft Edge | 2024-12-06T00:00:00.000000 | 2024-12-06T00:00:00.000000 |
| certfr-2024-avi-1046 | Multiples vulnérabilités dans Tenable Security Center | 2024-12-06T00:00:00.000000 | 2024-12-06T00:00:00.000000 |
| certfr-2024-avi-1045 | Multiples vulnérabilités dans Google Pixel | 2024-12-06T00:00:00.000000 | 2024-12-06T00:00:00.000000 |
| certfr-2024-avi-1044 | Multiples vulnérabilités dans MISP | 2024-12-05T00:00:00.000000 | 2024-12-05T00:00:00.000000 |
| certfr-2024-avi-1043 | Vulnérabilité dans Cisco NX-OS | 2024-12-05T00:00:00.000000 | 2024-12-05T00:00:00.000000 |
| certfr-2024-avi-1042 | Multiples vulnérabilités dans Sonicwall Secure Mobile Access | 2024-12-05T00:00:00.000000 | 2024-12-05T00:00:00.000000 |
| certfr-2024-avi-1041 | Vulnérabilité dans SolarWinds Platform | 2024-12-04T00:00:00.000000 | 2024-12-04T00:00:00.000000 |
| certfr-2024-avi-1040 | Vulnérabilité dans Moxa VPort 07-3 Series | 2024-12-04T00:00:00.000000 | 2024-12-04T00:00:00.000000 |
| certfr-2024-avi-1039 | Multiples vulnérabilités dans les produits Veeam | 2024-12-04T00:00:00.000000 | 2024-12-04T00:00:00.000000 |
| certfr-2024-avi-1038 | Vulnérabilité dans Google Chrome | 2024-12-04T00:00:00.000000 | 2024-12-04T00:00:00.000000 |
| certfr-2024-avi-1037 | Multiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager | 2024-12-04T00:00:00.000000 | 2024-12-04T00:00:00.000000 |
| certfr-2024-avi-1036 | Multiples vulnérabilités dans Google Android | 2024-12-03T00:00:00.000000 | 2024-12-03T00:00:00.000000 |
| certfr-2024-avi-1035 | Multiples vulnérabilités dans les produits Axis | 2024-12-03T00:00:00.000000 | 2024-12-03T00:00:00.000000 |
| certfr-2024-avi-1034 | Multiples vulnérabilités dans Ruby on Rails | 2024-12-03T00:00:00.000000 | 2024-12-03T00:00:00.000000 |
| certfr-2024-avi-1033 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-11-29T00:00:00.000000 | 2024-11-29T00:00:00.000000 |
| certfr-2024-avi-1032 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2024-11-29T00:00:00.000000 | 2024-11-29T00:00:00.000000 |
| certfr-2024-avi-1031 | Multiples vulnérabilités dans le noyau Linux de Debian | 2024-11-29T00:00:00.000000 | 2024-11-29T00:00:00.000000 |
| certfr-2024-avi-1030 | Multiples vulnérabilités dans IBM QRadar | 2024-11-29T00:00:00.000000 | 2024-11-29T00:00:00.000000 |