Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-79921 | amqp091-go has a Potential Memory Exhaustion/Protocol … |
rabbitmq |
amqp091-go |
2026-08-26T20:24:58.115Z | 2026-08-29T02:50:25.822Z | |
| cve-2026-61790 | Weblate: Team-enforced 2FA is bypassed for global perm… |
WeblateOrg |
weblate |
2026-08-26T20:23:53.644Z | 2026-08-27T14:51:14.305Z | |
| cve-2026-55228 | Weblate:: WebIDOR in GroupViewSet allows authenticated… |
WeblateOrg |
weblate |
2026-08-26T20:14:02.713Z | 2026-08-27T15:20:40.892Z | |
| cve-2026-55227 | Observable object existence disclosure in private Webl… |
WeblateOrg |
weblate |
2026-08-26T20:10:39.333Z | 2026-08-27T13:51:40.681Z | |
| cve-2026-71054 | Vulnerability in Oracle Java SE (component: 2D). … |
Oracle Corporation |
Oracle Java SE |
2026-08-26T19:57:04.287Z | 2026-08-26T20:25:09.364Z | |
| cve-2026-77508 | Weblate: Unverified REST API email changes |
WeblateOrg |
weblate |
2026-08-26T19:56:59.825Z | 2026-08-27T14:32:57.362Z | |
| cve-2026-75601 | Static Web Server: Authentication bypass on /metrics e… |
static-web-server |
static-web-server |
2026-08-26T19:53:29.160Z | 2026-08-29T02:48:59.562Z | |
| cve-2026-60004 | 9.8 (v3.1) | Gitea before 1.27.1 allows remote code execution … |
Gitea |
Gitea |
2026-08-26T19:45:00.000Z | 2026-08-26T22:56:00.000Z |
| cve-2026-79938 | 7.6 (v3.1) | Dell PowerProtect Cyber Recovery, versions prior … |
Dell |
Power Protect Cyber Recovery |
2026-08-26T19:37:36.076Z | 2026-08-27T14:33:06.905Z |
| cve-2026-79939 | 5.8 (v3.1) | Dell PowerProtect Cyber Recovery, versions Prior … |
Dell |
Power Protect Cyber Recovery |
2026-08-26T19:32:57.153Z | 2026-08-27T15:21:36.311Z |
| cve-2026-46369 | Nimiq: Validity store off by one error |
nimiq |
core-rs-albatross |
2026-08-26T19:32:46.025Z | 2026-08-27T15:22:58.317Z | |
| cve-2026-66003 | Frappe: Access control bypass via REST API dot-notatio… |
frappe |
frappe |
2026-08-26T19:30:28.968Z | 2026-08-27T14:44:42.733Z | |
| cve-2026-49809 | 6.5 (v3.1) | Dell PowerProtect Cyber Recovery, versions 20.2 a… |
Dell |
Power Protect Cyber Recovery |
2026-08-26T19:28:34.851Z | 2026-08-28T18:35:57.350Z |
| cve-2026-47848 | 6.1 (v3.1) | Reactor Netty WebSocket Client Leaks Credentials On Redirect |
Spring |
Reactor Netty |
2026-08-26T19:22:26.712Z | 2026-08-26T19:44:38.993Z |
| cve-2026-47844 | 5.3 (v3.1) | Reactor Netty HTTP Server Leaks Exception Details |
Spring |
Reactor Netty |
2026-08-26T19:22:25.677Z | 2026-08-26T19:44:53.514Z |
| cve-2026-47843 | 3.7 (v3.1) | Reactor Netty may incorrectly route traffic due to DNS… |
Spring |
Reactor Netty |
2026-08-26T19:22:24.697Z | 2026-08-26T19:45:10.489Z |
| cve-2026-47842 | 6.5 (v3.1) | Deterministic AES/CBC Encryption in Spring Security Ae… |
Spring |
Spring Security |
2026-08-26T19:22:23.745Z | 2026-08-26T19:45:25.424Z |
| cve-2026-47834 | 4.8 (v3.1) | Spring Data JPA Sort expression validation bypass |
Spring |
Spring Data JPA |
2026-08-26T19:22:22.873Z | 2026-08-26T19:45:40.524Z |
| cve-2026-77652 | 7.8 (v3.1) | Dia: dia: heap buffer overflow in wpg colormap parser … |
GNOME |
Dia |
2026-08-26T19:21:39.936Z | 2026-08-27T14:43:23.737Z |
| cve-2026-74770 | 8.8 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:17:41.915Z | 2026-08-27T14:33:15.683Z |
| cve-2026-54245 | Fleet: SQL injection in Okta conditional access endpoi… |
fleetdm |
fleet |
2026-08-26T19:13:22.415Z | 2026-08-27T13:49:51.927Z | |
| cve-2026-74771 | 6.5 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:11:48.631Z | 2026-08-27T15:25:00.027Z |
| cve-2026-46371 | Fleet: Observer-level enrollment secret extraction via… |
fleetdm |
fleet |
2026-08-26T19:06:12.147Z | 2026-08-27T14:33:22.566Z | |
| cve-2026-74774 | 5.9 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:05:43.845Z | 2026-08-27T14:42:11.386Z |
| cve-2026-67275 | 5.3 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T19:01:27.487Z | 2026-08-27T14:33:32.218Z |
| cve-2026-56547 | 3.5 (v3.1) | An input reflection vulnerability affects HCL Traveler |
HCLSoftware |
Traveler |
2026-08-26T18:54:50.814Z | 2026-08-26T19:45:56.615Z |
| cve-2026-46370 | Fleet has observer-level enrollment secret extraction … |
fleetdm |
fleet |
2026-08-26T18:54:31.761Z | 2026-08-29T02:47:37.283Z | |
| cve-2026-68861 | 8.8 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T18:54:30.310Z | 2026-08-27T15:27:18.434Z |
| cve-2026-68863 | 7.5 (v3.1) | Dell PowerProtect One, versions 20.1.0.0 and belo… |
Dell |
PowerProtect One |
2026-08-26T18:50:10.312Z | 2026-08-27T14:41:45.811Z |
| cve-2026-71172 | 4.3 (v3.1) | Dell Cloud Disaster Recovery, versions 20.2 and p… |
Dell |
Cloud Disaster Recovery |
2026-08-26T18:44:09.039Z | 2026-08-26T19:46:12.189Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2016-000221 | Multiple I-O DATA network camera products vulnerable to information disclosure | 2016-11-11T13:51+09:00 | 2018-01-17T12:02+09:00 |
| jvndb-2016-005655 | Vulnerabilitie in JP1/IT Desktop Management 2 - Manager and JP1/NETM/DM | 2016-11-10T16:59+09:00 | 2016-11-10T16:59+09:00 |
| jvndb-2016-000215 | Access restriction bypass vulnerability in WFS-SR01 | 2016-11-02T16:21+09:00 | 2017-11-27T16:42+09:00 |
| jvndb-2016-000214 | Command injection vulnerability in WFS-SR01 | 2016-11-02T16:20+09:00 | 2017-11-27T16:42+09:00 |
| jvndb-2016-000212 | The installer of The Public Certification Service for Individuals "The JPKI user's software" may insecurely load Dynamic Link Libraries | 2016-11-01T16:44+09:00 | 2017-12-25T11:28+09:00 |
| jvndb-2016-000213 | mobiGate App fails to verify SSL server certificates | 2016-11-01T13:47+09:00 | 2018-01-17T12:18+09:00 |
| jvndb-2016-000211 | Installer of 7-Zip for Windows may insecurely load Dynamic Link Libraries | 2016-10-26T15:13+09:00 | 2017-12-25T10:27+09:00 |
| jvndb-2016-000210 | SQL injection vulnerability in WordPress plugin WP-OliveCart | 2016-10-20T14:22+09:00 | 2018-01-17T12:10+09:00 |
| jvndb-2016-000209 | Cross-site request forgery vulnerability in WordPress plugin WP-OliveCart | 2016-10-20T14:22+09:00 | 2018-01-17T12:10+09:00 |
| jvndb-2016-000208 | Cross-site scripting vulnerability in WordPress plugin WP-OliveCart | 2016-10-20T14:22+09:00 | 2018-01-17T12:10+09:00 |
| jvndb-2016-000206 | Installer of Evernote for Windows may insecurely load Dynamic Link Libraries | 2016-10-19T15:32+09:00 | 2017-11-27T18:12+09:00 |
| jvndb-2016-000207 | The installer of e-Tax Software may insecurely load Dynamic Link Libraries | 2016-10-19T12:29+09:00 | 2018-01-17T11:48+09:00 |
| jvndb-2016-000168 | Toshiba FlashAir does not require authentication in "Internet pass-thru Mode" | 2016-10-12T10:03+09:00 | 2017-11-27T17:04+09:00 |
| jvndb-2016-000201 | SetucoCMS vulnerable to session management | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000200 | SetucoCMS vulnerable to code injection | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000199 | SetucoCMS vulnerable to denial-of-service (DoS) | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000198 | SetucoCMS vulnerable to SQL injection | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000197 | SetucoCMS vulnerable to cross-site scripting | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000196 | SetucoCMS vulnerable to cross-site request forgery | 2016-10-07T15:04+09:00 | 2017-05-17T14:44+09:00 |
| jvndb-2016-000195 | Cryptography API: Next Generation (CNG) vulnerable to denial-of-service (DoS) | 2016-10-07T14:11+09:00 | 2016-10-07T14:11+09:00 |
| jvndb-2016-000202 | Usermin cross-site scripting vulnerabilties | 2016-10-07T13:50+09:00 | 2017-05-16T17:52+09:00 |
| jvndb-2016-000193 | Cybozu Office vulnerable to Reflected File Download (RFD) | 2016-10-03T15:47+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000192 | Cybozu Office vulnerable to denial-of-service (DoS) | 2016-10-03T15:46+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000191 | Cybozu Office vulnerable to information disclosure | 2016-10-03T15:43+09:00 | 2017-04-24T15:05+09:00 |
| jvndb-2016-000190 | Cybozu Office vulnerable to mail header injection | 2016-10-03T15:43+09:00 | 2017-04-24T15:05+09:00 |
| jvndb-2016-000189 | "Project" function in Cybozu Office vulnerable vulnerable to operation restriction bypass | 2016-10-03T15:43+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000188 | Breadcrumb trail in Cybozu Office vulnerable vulnerable to browse restriction bypass | 2016-10-03T15:43+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000187 | "Project" function in Cybozu Office vulnerable vulnerable to access restriction bypass | 2016-10-03T15:43+09:00 | 2017-04-24T15:05+09:00 |
| jvndb-2016-000186 | "Schedule" function in Cybozu Office vulnerable to cross-site scripting | 2016-10-03T15:43+09:00 | 2017-04-24T15:10+09:00 |
| jvndb-2016-000185 | "Project" function in Cybozu Office vulnerable to cross-site scripting | 2016-10-03T15:43+09:00 | 2017-04-24T15:05+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0469 | Vulnérabilité dans les produits Synology | 2025-06-02T00:00:00.000000 | 2025-06-02T00:00:00.000000 |
| certfr-2025-avi-0468 | Vulnérabilité dans Roundcube | 2025-06-02T00:00:00.000000 | 2025-06-05T00:00:00.000000 |
| certfr-2025-avi-0467 | Multiples vulnérabilités dans IBM Db2 | 2025-05-30T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0466 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-05-30T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0465 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-05-30T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0464 | Multiples vulnérabilités dans le noyau Linux de Debian | 2025-05-30T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0463 | Multiples vulnérabilités dans le noyau Linux de Debian LTS | 2025-05-30T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0462 | Multiples vulnérabilités dans Microsoft Edge | 2025-05-30T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0461 | Vulnérabilité dans Apache Tomcat | 2025-05-30T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0460 | Vulnérabilité dans Spring Cloud Gateway Server | 2025-05-30T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0459 | Multiples vulnérabilités dans ISC Kea DHCP | 2025-05-30T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0458 | Multiples vulnérabilités dans Curl | 2025-05-28T00:00:00.000000 | 2025-05-28T00:00:00.000000 |
| certfr-2025-avi-0457 | Vulnérabilité dans Traefik | 2025-05-28T00:00:00.000000 | 2025-05-28T00:00:00.000000 |
| certfr-2025-avi-0456 | Multiples vulnérabilités dans Citrix et Xen | 2025-05-28T00:00:00.000000 | 2025-05-28T00:00:00.000000 |
| certfr-2025-avi-0455 | Multiples vulnérabilités dans Google Chrome | 2025-05-28T00:00:00.000000 | 2025-05-28T00:00:00.000000 |
| certfr-2025-avi-0454 | Multiples vulnérabilités dans les produits Mozilla | 2025-05-28T00:00:00.000000 | 2025-05-28T00:00:00.000000 |
| certfr-2025-avi-0453 | Vulnérabilité dans Mattermost Server | 2025-05-27T00:00:00.000000 | 2025-08-19T00:00:00.000000 |
| certfr-2025-avi-0452 | Multiples vulnérabilités dans les produits IBM | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0451 | Vulnérabilité dans Microsoft Edge | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0450 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0449 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0448 | Multiples vulnérabilités dans Tenable Nessus Network Monitor | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0447 | Multiples vulnérabilités dans Grafana | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0446 | Multiples vulnérabilités dans Asterisk | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0445 | Multiples vulnérabilités dans Mozilla Thunderbird | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0444 | Vulnérabilité dans OpenSSL | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0443 | Vulnérabilité dans VMware Avi Load Balancer | 2025-05-23T00:00:00.000000 | 2025-05-23T00:00:00.000000 |
| certfr-2025-avi-0442 | Vulnérabilité dans Mozilla Firefox pour iOS | 2025-05-22T00:00:00.000000 | 2025-05-22T00:00:00.000000 |
| certfr-2025-avi-0441 | Vulnérabilité dans Mattermost Server | 2025-05-22T00:00:00.000000 | 2025-08-19T00:00:00.000000 |
| certfr-2025-avi-0440 | Vulnérabilité dans Grafana | 2025-05-22T00:00:00.000000 | 2025-05-22T00:00:00.000000 |