Recent vulnerabilities


ID CVSS Description Vendor Product Published Updated
cve-2026-46370 Fleet has observer-level enrollment secret extraction … fleetdm
fleet
2026-08-26T18:54:31.761Z 2026-08-29T02:47:37.283Z
cve-2026-68861 8.8 (v3.1) Dell PowerProtect One, versions 20.1.0.0 and belo… Dell
PowerProtect One
2026-08-26T18:54:30.310Z 2026-08-27T15:27:18.434Z
cve-2026-68863 7.5 (v3.1) Dell PowerProtect One, versions 20.1.0.0 and belo… Dell
PowerProtect One
2026-08-26T18:50:10.312Z 2026-08-27T14:41:45.811Z
cve-2026-71172 4.3 (v3.1) Dell Cloud Disaster Recovery, versions 20.2 and p… Dell
Cloud Disaster Recovery
2026-08-26T18:44:09.039Z 2026-08-26T19:46:12.189Z
cve-2026-41262 Fleet: Cross-Team Policy Data Exposure via Global Poli… fleetdm
fleet
2026-08-26T18:32:30.669Z 2026-08-26T18:57:43.948Z
cve-2026-71171 7.2 (v3.1) Dell Cloud Disaster Recovery, versions 20.2 and p… Dell
Cloud Disaster Recovery
2026-08-26T18:30:52.487Z 2026-08-26T18:48:27.558Z
cve-2026-48786 Fleet: Observer-class users can view team enroll secre… fleetdm
fleet
2026-08-26T18:25:09.971Z 2026-08-26T18:49:37.564Z
cve-2026-70419 9.1 (v3.1) Dell Cloud Disaster Recovery, versions 20.2 and p… Dell
Cloud Disaster Recovery
2026-08-26T18:24:28.070Z 2026-08-26T18:52:08.264Z
cve-2026-79940 5.9 (v3.1) Dell iDRAC9, 14G versions prior to 7.00.00.182 an… Dell
iDRAC9
2026-08-26T18:16:42.618Z 2026-08-26T19:46:27.415Z
cve-2026-63179 Winter: Local File Inclusion through @import directive… wintercms
winter
2026-08-26T18:06:14.103Z 2026-08-26T18:51:15.095Z
cve-2026-19485 9.3 (v4.0) Bucket Squatting in Vertex AI Search for Commerce Google Cloud
Vertex AI Search for Commerce
2026-08-26T18:06:00.596Z 2026-08-26T19:04:26.776Z
cve-2026-54256 Winter: Authenticated IDOR in backend FileUpload widge… wintercms
winter
2026-08-26T17:53:36.237Z 2026-08-27T14:33:39.110Z
cve-2026-32639 Winter: Broken access control in `Cms\Controllers\Inde… wintercms
winter
2026-08-26T17:50:32.102Z 2026-08-29T02:46:44.275Z
cve-2026-58474 8.6 (v4.0) 8.8 (v3.1) whichllm < 0.5.16 Code Injection via run and snippet c… Andyyyy64
whichllm
2026-08-26T17:49:04.041Z 2026-08-29T11:47:31.365Z
cve-2026-76784 8.7 (v4.0) Insufficient Cryptographic Protections in Local Device… TP-Link Systems Inc.
HS103P3 / HS103P4 v5
2026-08-26T17:47:54.278Z 2026-08-26T18:50:19.860Z
cve-2026-32593 Winter: SQL Injection in Backend Filter Widget numberr… wintercms
winter
2026-08-26T17:27:07.836Z 2026-08-26T18:29:20.480Z
cve-2026-47841 7.4 (v3.1) WebAuthn User Verification Bypass via Session Serialization Spring
Spring Security
2026-08-26T17:08:52.788Z 2026-08-27T03:58:22.127Z
cve-2026-47837 6.8 (v3.1) Spring Cloud Config Server Monitor Endpoint Does Not V… Spring
Spring Cloud Config
2026-08-26T17:08:51.832Z 2026-08-26T18:50:49.428Z
cve-2026-47836 7.2 (v3.1) Spring Cloud Config Server Susceptible To TOCTOU Attac… Spring
Spring Cloud Config
2026-08-26T17:05:21.979Z 2026-08-27T03:58:24.390Z
cve-2026-32258 Winter: Stored XSS through Editor Settings custom styles wintercms
winter
2026-08-26T16:49:06.852Z 2026-08-26T17:35:11.529Z
cve-2026-32257 Winter: Stored XSS through Brand Settings custom styles wintercms
winter
2026-08-26T16:45:12.100Z 2026-08-27T14:33:49.017Z
cve-2026-35445 Winter: Authenticated backend users can bypass Users c… wintercms
winter
2026-08-26T16:40:51.500Z 2026-08-26T19:08:44.974Z
cve-2026-81036 8.5 (v4.0) 8.1 (v3.1) Stalwart Mail Server through 0.16.19 Authorization Cod… stalwartlabs
stalwart
2026-08-26T15:45:02.931Z 2026-08-29T02:45:24.847Z
cve-2026-81035 7.2 (v4.0) 8.1 (v3.1) Midday Missing Owner Check on Team Deletion midday-ai
midday
2026-08-26T15:45:02.234Z 2026-08-26T16:06:39.105Z
cve-2026-81034 8.3 (v4.0) 6.5 (v3.1) Netmaker through 1.6.0 Improper Certificate Validation… gravitl
netmaker
2026-08-26T15:45:01.529Z 2026-08-26T18:31:47.883Z
cve-2026-81033 6.9 (v4.0) 5.3 (v3.1) Automatisch through 0.15.0 User Enumeration via Forgot… automatisch
automatisch
2026-08-26T15:45:00.826Z 2026-08-28T16:00:31.483Z
cve-2026-81032 9.3 (v4.0) 9.8 (v3.1) NebulaGraph through 3.8.0 Unauthenticated Read and Mod… vesoft-inc
nebula
2026-08-26T15:45:00.144Z 2026-08-26T17:10:45.206Z
cve-2026-81031 8.6 (v4.0) 7.2 (v3.1) IDURAR ERP CRM through 4.1.1 Account Takeover via Unve… idurar
idurar-erp-crm
2026-08-26T15:44:59.362Z 2026-08-29T02:43:32.712Z
cve-2026-81030 7.1 (v4.0) 6.5 (v3.1) Mage AI through 0.9.79 Arbitrary File Read via Unvalid… mage-ai
mage-ai
2026-08-26T15:44:58.663Z 2026-08-26T16:05:12.110Z
cve-2026-81029 8.5 (v4.0) 8.1 (v3.1) OpenMetadata before 2.0.0 JWT Disclosure via Unvalidat… open-metadata
OpenMetadata
2026-08-26T15:44:57.988Z 2026-08-26T18:32:59.057Z
ID CVSS Description Vendor Product Published Updated
ID Description Package Published Updated
ID Description Type
ID Description Updated
ID Description Updated
ID Description Published Updated
jvndb-2016-000184 "Customapp" function in Cybozu Office vulnerable to cross-site scripting 2016-10-03T15:43+09:00 2017-04-24T15:05+09:00
jvndb-2016-000194 Docomo L-04D mobile WiFi router vulnerable to cross-site request forgery 2016-10-03T15:17+09:00 2018-01-17T11:53+09:00
jvndb-2016-000183 baserCMS plugin Uploader vulnerable to cross-site request forgery 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000182 baserCMS plugin Mail vulnerable to cross-site request forgery 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000181 baserCMS plugin Feed vulnerable to cross-site request forgery 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000180 baserCMS plugin Blog vulnerable to cross-site request forgery 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000179 baserCMS vulnerable to cross-site scripting 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000178 baserCMS vulnerable to cross-site request forgery 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000177 baserCMS vulnerable to cross-site request forgery 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000176 baserCMS plugin Blog vulnerable to cross-site request forgery 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000175 baserCMS plugin Blog vulnerable to cross-site scripting 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000174 baserCMS plugin Mail vulnerable to cross-site request forgery 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000173 baserCMS plugin Mail vulnerable to cross-site scripting 2016-09-29T16:04+09:00 2017-11-27T16:37+09:00
jvndb-2016-000172 baserCMS vulnerable to cross-site request forgery 2016-09-29T16:04+09:00 2017-11-27T16:36+09:00
jvndb-2016-000171 ManageEngine ServiceDesk Plus uses an insecure method for cookie generation 2016-09-29T14:39+09:00 2017-05-23T14:28+09:00
jvndb-2016-000170 ManageEngine ServiceDesk Plus fails to restrict access permissions 2016-09-29T14:39+09:00 2017-05-23T14:28+09:00
jvndb-2016-000169 ManageEngine ServiceDesk Plus vulnerable to cross-site scripting 2016-09-29T14:39+09:00 2017-05-23T14:28+09:00
jvndb-2016-000167 Multiple plugins for Geeklog IVYWE edition vulnerable to cross-site scripting 2016-09-23T14:15+09:00 2017-05-23T14:28+09:00
jvndb-2016-000161 Money Forward Apps for Android vulnerability that allows unintended operations 2016-09-20T15:19+09:00 2017-11-27T18:01+09:00
jvndb-2016-000160 Money Forward Apps for Android vulnerable in the WebView class 2016-09-20T15:19+09:00 2017-11-27T18:01+09:00
jvndb-2016-000166 Trend Micro Internet Security vulnerability where files may be excluded as scan targets 2016-09-16T14:31+09:00 2016-09-16T14:31+09:00
jvndb-2016-000165 Splunk Enterprise and Splunk Light vulnerable to cross-site scripting 2016-09-16T14:17+09:00 2018-01-24T11:53+09:00
jvndb-2016-000164 Splunk Enterprise and Splunk Light vulnerable to open redirect 2016-09-16T14:16+09:00 2017-11-27T16:55+09:00
jvndb-2016-000163 Splunk Enterprise and Splunk Light vulnerable to open redirect 2016-09-16T14:08+09:00 2017-11-27T16:55+09:00
jvndb-2016-000162 Splunk Enterprise and Splunk Lite vulnerable to cross-site scripting 2016-09-16T13:56+09:00 2017-11-27T16:55+09:00
jvndb-2016-000159 H2O use of externally-controlled format string 2016-09-15T14:26+09:00 2017-11-27T17:23+09:00
jvndb-2016-000158 Zend Framework vulnerable to SQL injection 2016-09-15T14:11+09:00 2017-03-16T14:15+09:00
jvndb-2016-000157 CS-Cart add-on "Twigmo" vulnerable to PHP object injection 2016-09-14T15:00+09:00 2017-05-23T14:28+09:00
jvndb-2016-000156 ADOdb vulnerable to cross-site scripting 2016-09-06T13:45+09:00 2017-11-27T16:43+09:00
jvndb-2016-004496 Information Disclosure Vulnerability in Hitachi Automation Director and JP1/Automatic Operation 2016-09-02T16:09+09:00 2016-09-30T09:47+09:00
ID Description Updated
ID Description
ID Description Published Updated
certfr-2025-avi-0439 Multiples vulnérabilités dans Google Chrome 2025-05-22T00:00:00.000000 2025-05-22T00:00:00.000000
certfr-2025-avi-0438 Multiples vulnérabilités dans les produits Cisco 2025-05-22T00:00:00.000000 2025-05-22T00:00:00.000000
certfr-2025-avi-0437 Multiples vulnérabilités dans GitLab 2025-05-22T00:00:00.000000 2025-05-22T00:00:00.000000
certfr-2025-avi-0436 Vulnérabilité dans ISC BIND 2025-05-22T00:00:00.000000 2025-05-22T00:00:00.000000
certfr-2025-avi-0435 Multiples vulnérabilités dans les produits Atlassian 2025-05-21T00:00:00.000000 2025-05-21T00:00:00.000000
certfr-2025-avi-0434 Multiples vulnérabilités dans Node.js 2025-05-21T00:00:00.000000 2025-05-21T00:00:00.000000
certfr-2025-avi-0433 Multiples vulnérabilités dans Adobe ColdFusion 2025-05-21T00:00:00.000000 2025-05-21T00:00:00.000000
certfr-2025-avi-0432 Vulnérabilité dans Schneider Electric EcoStruxure Power Build Rapsody 2025-05-21T00:00:00.000000 2025-05-21T00:00:00.000000
certfr-2025-avi-0431 Vulnérabilité dans Mitel OpenScapeXpressions 2025-05-21T00:00:00.000000 2025-05-21T00:00:00.000000
certfr-2025-avi-0430 Multiples vulnérabilités dans les produits VMware 2025-05-21T00:00:00.000000 2025-05-21T00:00:00.000000
certfr-2025-avi-0429 Multiples vulnérabilités dans Typo3 2025-05-20T00:00:00.000000 2025-05-20T00:00:00.000000
certfr-2025-avi-0428 Multiples vulnérabilités dans VMware Cloud Foundation 2025-05-20T00:00:00.000000 2025-05-20T00:00:00.000000
certfr-2025-avi-0427 Vulnérabilité dans Spring Security 2025-05-20T00:00:00.000000 2025-05-20T00:00:00.000000
certfr-2025-avi-0426 Vulnérabilité dans Juniper Networks Junos OS 2025-05-19T00:00:00.000000 2025-05-19T00:00:00.000000
certfr-2025-avi-0425 Vulnérabilité dans les produits Synology 2025-05-19T00:00:00.000000 2025-05-19T00:00:00.000000
certfr-2025-avi-0424 Multiples vulnérabilités dans les produits Mozilla 2025-05-19T00:00:00.000000 2025-05-19T00:00:00.000000
certfr-2025-avi-0423 Multiples vulnérabilités dans les produits Netgate 2025-05-19T00:00:00.000000 2025-05-19T00:00:00.000000
certfr-2025-avi-0422 Multiples vulnérabilités dans IBM QRadar SIEM 2025-05-16T00:00:00.000000 2025-05-16T00:00:00.000000
certfr-2025-avi-0421 Multiples vulnérabilités dans le noyau Linux de Red Hat 2025-05-16T00:00:00.000000 2025-05-16T00:00:00.000000
certfr-2025-avi-0420 Multiples vulnérabilités dans les produits Nextcloud 2025-05-16T00:00:00.000000 2025-05-16T00:00:00.000000
certfr-2025-avi-0419 Vulnérabilité dans Microsoft Defender pour Endpoint 2025-05-16T00:00:00.000000 2025-05-16T00:00:00.000000
certfr-2025-avi-0418 Multiples vulnérabilités dans Microsoft Edge 2025-05-16T00:00:00.000000 2025-05-16T00:00:00.000000
certfr-2025-avi-0417 Vulnérabilité dans Spring Framework 2025-05-16T00:00:00.000000 2025-05-16T00:00:00.000000
certfr-2025-avi-0416 Vulnérabilité dans Synacor Zimbra Collaboration 2025-05-16T00:00:00.000000 2025-05-16T00:00:00.000000
certfr-2025-avi-0415 Vulnérabilité dans Python 2025-05-16T00:00:00.000000 2025-05-16T00:00:00.000000
certfr-2025-avi-0414 Multiples vulnérabilités dans Synacor Zimbra Collaboration 2025-05-15T00:00:00.000000 2025-05-15T00:00:00.000000
certfr-2025-avi-0413 Multiples vulnérabilités dans Mattermost Server 2025-05-15T00:00:00.000000 2025-05-15T00:00:00.000000
certfr-2025-avi-0412 Multiples vulnérabilités dans Google Chrome 2025-05-15T00:00:00.000000 2025-05-15T00:00:00.000000
certfr-2025-avi-0411 Multiples vulnérabilités dans les produits Mozilla 2025-05-15T00:00:00.000000 2025-05-15T00:00:00.000000
certfr-2025-avi-0410 Multiples vulnérabilités dans les produits Palo Alto Networks 2025-05-15T00:00:00.000000 2025-05-15T00:00:00.000000