Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-47836 | 7.2 (v3.1) | Spring Cloud Config Server Susceptible To TOCTOU Attac… |
Spring |
Spring Cloud Config |
2026-08-26T17:05:21.979Z | 2026-08-27T03:58:24.390Z |
| cve-2026-32258 | Winter: Stored XSS through Editor Settings custom styles |
wintercms |
winter |
2026-08-26T16:49:06.852Z | 2026-08-26T17:35:11.529Z | |
| cve-2026-32257 | Winter: Stored XSS through Brand Settings custom styles |
wintercms |
winter |
2026-08-26T16:45:12.100Z | 2026-08-27T14:33:49.017Z | |
| cve-2026-35445 | Winter: Authenticated backend users can bypass Users c… |
wintercms |
winter |
2026-08-26T16:40:51.500Z | 2026-08-26T19:08:44.974Z | |
| cve-2026-81036 | 8.5 (v4.0) 8.1 (v3.1) | Stalwart Mail Server through 0.16.19 Authorization Cod… |
stalwartlabs |
stalwart |
2026-08-26T15:45:02.931Z | 2026-08-29T02:45:24.847Z |
| cve-2026-81035 | 7.2 (v4.0) 8.1 (v3.1) | Midday Missing Owner Check on Team Deletion |
midday-ai |
midday |
2026-08-26T15:45:02.234Z | 2026-08-26T16:06:39.105Z |
| cve-2026-81034 | 8.3 (v4.0) 6.5 (v3.1) | Netmaker through 1.6.0 Improper Certificate Validation… |
gravitl |
netmaker |
2026-08-26T15:45:01.529Z | 2026-08-26T18:31:47.883Z |
| cve-2026-81033 | 6.9 (v4.0) 5.3 (v3.1) | Automatisch through 0.15.0 User Enumeration via Forgot… |
automatisch |
automatisch |
2026-08-26T15:45:00.826Z | 2026-08-28T16:00:31.483Z |
| cve-2026-81032 | 9.3 (v4.0) 9.8 (v3.1) | NebulaGraph through 3.8.0 Unauthenticated Read and Mod… |
vesoft-inc |
nebula |
2026-08-26T15:45:00.144Z | 2026-08-26T17:10:45.206Z |
| cve-2026-81031 | 8.6 (v4.0) 7.2 (v3.1) | IDURAR ERP CRM through 4.1.1 Account Takeover via Unve… |
idurar |
idurar-erp-crm |
2026-08-26T15:44:59.362Z | 2026-08-29T02:43:32.712Z |
| cve-2026-81030 | 7.1 (v4.0) 6.5 (v3.1) | Mage AI through 0.9.79 Arbitrary File Read via Unvalid… |
mage-ai |
mage-ai |
2026-08-26T15:44:58.663Z | 2026-08-26T16:05:12.110Z |
| cve-2026-81029 | 8.5 (v4.0) 8.1 (v3.1) | OpenMetadata before 2.0.0 JWT Disclosure via Unvalidat… |
open-metadata |
OpenMetadata |
2026-08-26T15:44:57.988Z | 2026-08-26T18:32:59.057Z |
| cve-2026-81028 | 6.9 (v4.0) 4.9 (v3.1) | ZLMediaKit downloadFile Root-Directory Confinement Byp… |
ZLMediaKit |
ZLMediaKit |
2026-08-26T15:44:57.303Z | 2026-08-28T16:00:38.893Z |
| cve-2026-81027 | 8.4 (v4.0) 8.5 (v3.1) | one-api through 0.6.10 Missing Authorization on URL-Pa… |
songquanpeng |
one-api |
2026-08-26T15:44:56.599Z | 2026-08-26T17:25:39.276Z |
| cve-2026-80428 | 9.3 (v4.0) 9.8 (v3.1) | ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP … |
ILIAS-eLearning e.V. |
ILIAS |
2026-08-26T15:44:55.917Z | 2026-08-29T02:41:40.892Z |
| cve-2026-80427 | 8.6 (v4.0) 8.4 (v3.1) | bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument I… |
nfriedly |
bestzip |
2026-08-26T15:44:55.220Z | 2026-08-29T11:48:06.751Z |
| cve-2026-80426 | 7 (v4.0) 7.1 (v3.1) | FiftyOne before 1.21.0 Stored Cross-Site Scripting via… |
voxel51 |
fiftyone |
2026-08-26T15:44:54.517Z | 2026-08-29T11:48:06.089Z |
| cve-2026-48549 | 6.9 (v4.0) 6.5 (v3.1) | Nagios Core / XI CSRF via cmd.cgi Double-Submit Cookie |
Nagios Enterprises, LLC. |
Nagios Core |
2026-08-26T15:37:20.083Z | 2026-08-28T16:00:44.978Z |
| cve-2026-48548 | 6.9 (v4.0) 6.5 (v3.1) | Nagios Core CSRF via cmd.cgi |
Nagios Enterprises, LLC. |
Nagios Core |
2026-08-26T15:33:59.685Z | 2026-08-26T17:29:31.213Z |
| cve-2026-54614 | DebugKit: MailPreview contains unsafe reflection |
cakephp |
debug_kit |
2026-08-26T15:30:23.966Z | 2026-08-29T02:40:09.901Z | |
| cve-2026-54569 | SENAITE.CORE: Improper Neutralization of Directives in… |
senaite |
senaite.core |
2026-08-26T15:28:19.919Z | 2026-08-26T17:35:57.088Z | |
| cve-2026-54606 | SunEditor: DOM XSS in SunEditor Embed Plugin via Exter… |
JiHong88 |
suneditor |
2026-08-26T15:25:58.083Z | 2026-08-26T18:28:06.384Z | |
| cve-2026-75062 | 9.2 (v4.0) | Eval Injection in google/langfun via default lf.query … |
Google |
langfun |
2026-08-26T14:50:50.604Z | 2026-08-27T16:55:00.832Z |
| cve-2026-80589 | block: stop the timeout timer when releasing a never a… |
Linux |
Linux |
2026-08-26T14:37:43.293Z | 2026-08-27T05:02:10.391Z | |
| cve-2026-80588 | mptcp: reclaim forward-allocated memory on RX path errors |
Linux |
Linux |
2026-08-26T14:37:42.685Z | 2026-08-27T05:02:09.335Z | |
| cve-2026-80587 | mptcp: avoid combining some incoming suboptions |
Linux |
Linux |
2026-08-26T14:37:42.093Z | 2026-08-27T12:40:23.299Z | |
| cve-2026-80586 | mptcp: options: reset DSS fields in case of unexpected size |
Linux |
Linux |
2026-08-26T14:37:41.493Z | 2026-08-27T05:02:07.204Z | |
| cve-2026-80585 | mptcp: fastopen: only mark MPTFO subflows with SYN data |
Linux |
Linux |
2026-08-26T14:37:40.901Z | 2026-08-27T05:02:06.112Z | |
| cve-2026-80584 | s390/qeth: validate user buffer length in SNMP and ARP… |
Linux |
Linux |
2026-08-26T14:37:40.302Z | 2026-08-27T05:02:04.879Z | |
| cve-2026-80583 | ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses |
Linux |
Linux |
2026-08-26T14:37:39.704Z | 2026-08-27T12:40:21.902Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2016-000154 | Multiple AKABEi SOFT2 LTD. games vulnerable to OS command injection | 2016-08-31T15:33+09:00 | 2016-09-05T17:56+09:00 |
| jvndb-2016-000153 | LINE for Windows fails to properly verify downloaded files | 2016-08-25T14:26+09:00 | 2017-05-23T14:28+09:00 |
| jvndb-2016-000151 | YoruFukurou (NightOwl) vulnerable to denial-of-service (DoS) | 2016-08-24T14:14+09:00 | 2016-10-27T09:43+09:00 |
| jvndb-2016-000152 | simple chat vulnerable to cross-site scripting | 2016-08-23T13:37+09:00 | 2016-09-05T17:45+09:00 |
| jvndb-2016-000149 | Cybozu Garoon fails to restrict access permissions | 2016-08-22T15:16+09:00 | 2017-05-23T12:01+09:00 |
| jvndb-2016-000148 | Cybozu Garoon vulnerable to authentication bypass | 2016-08-22T15:16+09:00 | 2017-05-23T12:01+09:00 |
| jvndb-2016-000147 | Cybozu Garoon vulnerable to SQL injection | 2016-08-22T15:16+09:00 | 2017-05-23T12:01+09:00 |
| jvndb-2016-000146 | "Check available times" function in Cybozu Garoon vulnerable to cross-site scripting | 2016-08-22T15:16+09:00 | 2017-05-23T12:01+09:00 |
| jvndb-2016-000145 | "New appointment" function in Cybozu Garoon vulnerable to cross-site scripting | 2016-08-22T15:16+09:00 | 2017-05-23T12:01+09:00 |
| jvndb-2016-000144 | "User details" function in Cybozu Garoon vulnerable to cross-site scripting | 2016-08-22T15:16+09:00 | 2017-05-23T12:01+09:00 |
| jvndb-2016-000143 | "Response request" function in Cybozu Garoon vulnerable to cross-site scripting | 2016-08-22T15:16+09:00 | 2017-05-23T12:01+09:00 |
| jvndb-2016-000142 | Cybozu Garoon vulnerable to open redirect | 2016-08-22T15:16+09:00 | 2017-05-23T12:01+09:00 |
| jvndb-2016-000150 | Geeklog IVYWE edition contains a cross-site scripting vulnerability | 2016-08-19T14:13+09:00 | 2017-05-23T14:28+09:00 |
| jvndb-2016-000141 | OSSEC Web UI vulnerable to cross-site scripting | 2016-08-18T14:24+09:00 | 2017-05-23T14:28+09:00 |
| jvndb-2016-000140 | ClipBucket vulnerable to cross-site scripting | 2016-08-18T14:09+09:00 | 2016-09-05T17:41+09:00 |
| jvndb-2016-000139 | Installer of PhishWall Client Internet Explorer version may insecurely load Dynamic Link Libraries | 2016-08-17T16:12+09:00 | 2017-05-23T14:28+09:00 |
| jvndb-2016-000138 | Cybozu Mailwise contains issue in preventing clickjacking attacks | 2016-08-16T14:14+09:00 | 2017-05-23T12:01+09:00 |
| jvndb-2016-000137 | Cybozu Mailwise vulnerable to information disclosure | 2016-08-16T14:14+09:00 | 2017-05-23T12:02+09:00 |
| jvndb-2016-000136 | Cybozu Mailwise vulnerable to information disclosure | 2016-08-16T14:14+09:00 | 2017-05-23T12:02+09:00 |
| jvndb-2016-000135 | Cybozu Mailwise vulnerable to mail header injection | 2016-08-16T14:10+09:00 | 2017-05-23T16:23+09:00 |
| jvndb-2016-000134 | Multiple I-O DATA Recording Hard disk products vulnerable to cross-site request forgery | 2016-08-08T12:28+09:00 | 2016-10-24T18:27+09:00 |
| jvndb-2016-000127 | Android stock browser vulnerable to denial-of-service (DoS) | 2016-08-05T13:41+09:00 | 2016-08-05T13:41+09:00 |
| jvndb-2016-000133 | Coordinate Plus App fails to verify SSL server certificates | 2016-08-04T13:41+09:00 | 2017-05-23T14:28+09:00 |
| jvndb-2016-003527 | Information Disclosure Vulnerability in Hitachi Command Suite | 2016-08-02T13:50+09:00 | 2016-09-14T18:18+09:00 |
| jvndb-2016-000130 | EC-CUBE plugin "Coupon Plugin" vulnerable to SQL injection | 2016-07-25T11:15+09:00 | 2016-08-04T17:55+09:00 |
| jvndb-2016-000129 | Android OS issue where it is affected by the CRIME attack | 2016-07-25T11:15+09:00 | 2025-04-18T16:36+09:00 |
| jvndb-2016-000128 | Android OS Contacts app fails to restrict access permissions | 2016-07-25T11:14+09:00 | 2016-07-25T11:14+09:00 |
| jvndb-2016-000126 | Vtiger CRM does not properly restrict access to application data | 2016-07-20T14:56+09:00 | 2016-08-04T18:02+09:00 |
| jvndb-2016-000125 | WordPress plugin "Nofollow Links" vulnerable to cross-site scripting | 2016-07-20T14:56+09:00 | 2016-08-05T17:40+09:00 |
| jvndb-2016-000123 | LINE for Windows may insecurely load Dynamic Link Libraries | 2016-07-08T14:29+09:00 | 2016-08-19T17:44+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0409 | Multiples vulnérabilités dans SonicWall Secure Mobile Access | 2025-05-15T00:00:00.000000 | 2025-05-15T00:00:00.000000 |
| certfr-2025-avi-0408 | Multiples vulnérabilités dans les produits Microsoft | 2025-05-14T00:00:00.000000 | 2025-05-14T00:00:00.000000 |
| certfr-2025-avi-0407 | Multiples vulnérabilités dans Microsoft Azure | 2025-05-14T00:00:00.000000 | 2025-05-14T00:00:00.000000 |
| certfr-2025-avi-0406 | Vulnérabilité dans Microsoft .Net | 2025-05-14T00:00:00.000000 | 2025-05-14T00:00:00.000000 |
| certfr-2025-avi-0405 | Multiples vulnérabilités dans Microsoft Windows | 2025-05-14T00:00:00.000000 | 2025-05-14T00:00:00.000000 |
| certfr-2025-avi-0404 | Multiples vulnérabilités dans Microsoft Office | 2025-05-14T00:00:00.000000 | 2025-05-14T00:00:00.000000 |
| certfr-2025-avi-0403 | Multiples vulnérabilités dans les produits Ivanti | 2025-05-14T00:00:00.000000 | 2025-05-14T00:00:00.000000 |
| certfr-2025-avi-0402 | Multiples vulnérabilités dans les produits Intel | 2025-05-14T00:00:00.000000 | 2025-05-14T00:00:00.000000 |
| certfr-2025-avi-0401 | Multiples vulnérabilités dans Juniper Networks Secure Analytics | 2025-05-14T00:00:00.000000 | 2025-05-30T00:00:00.000000 |
| certfr-2025-avi-0400 | Multiples vulnérabilités dans Ivanti Endpoint Manager Mobile (EPMM) | 2025-05-13T00:00:00.000000 | 2025-05-13T00:00:00.000000 |
| certfr-2025-avi-0399 | Multiples vulnérabilités dans les produits Fortinet | 2025-05-13T00:00:00.000000 | 2025-05-13T00:00:00.000000 |
| certfr-2025-avi-0398 | Vulnérabilité dans les produits Schneider Electric | 2025-05-13T00:00:00.000000 | 2025-05-13T00:00:00.000000 |
| certfr-2025-avi-0397 | Multiples vulnérabilités dans les produits Siemens | 2025-05-13T00:00:00.000000 | 2025-05-13T00:00:00.000000 |
| certfr-2025-avi-0396 | Multiples vulnérabilités dans les produits SAP | 2025-05-13T00:00:00.000000 | 2025-06-12T00:00:00.000000 |
| certfr-2025-avi-0395 | Vulnérabilité dans les produits Citrix | 2025-05-13T00:00:00.000000 | 2025-05-13T00:00:00.000000 |
| certfr-2025-avi-0394 | Multiples vulnérabilités dans les produits Intel | 2025-05-13T00:00:00.000000 | 2025-05-13T00:00:00.000000 |
| certfr-2025-avi-0393 | Multiples vulnérabilités dans les produits Apple | 2025-05-13T00:00:00.000000 | 2025-05-13T00:00:00.000000 |
| certfr-2025-avi-0392 | Multiples vulnérabilités dans Mattermost Server | 2025-05-13T00:00:00.000000 | 2025-06-12T00:00:00.000000 |
| certfr-2025-avi-0391 | Vulnérabilité dans Xen | 2025-05-13T00:00:00.000000 | 2025-05-13T00:00:00.000000 |
| certfr-2025-avi-0390 | Vulnérabilité dans les produits VMware | 2025-05-13T00:00:00.000000 | 2025-05-13T00:00:00.000000 |
| certfr-2025-avi-0389 | Vulnérabilité dans les produits VMware | 2025-05-12T00:00:00.000000 | 2025-05-12T00:00:00.000000 |
| certfr-2025-avi-0388 | Multiples vulnérabilités dans les produits Mitel | 2025-05-12T00:00:00.000000 | 2025-05-12T00:00:00.000000 |
| certfr-2025-avi-0387 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-05-09T00:00:00.000000 | 2025-05-09T00:00:00.000000 |
| certfr-2025-avi-0386 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-05-09T00:00:00.000000 | 2025-05-09T00:00:00.000000 |
| certfr-2025-avi-0385 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-05-09T00:00:00.000000 | 2025-05-09T00:00:00.000000 |
| certfr-2025-avi-0384 | Multiples vulnérabilités dans les produits IBM | 2025-05-09T00:00:00.000000 | 2025-05-09T00:00:00.000000 |
| certfr-2025-avi-0383 | Vulnérabilité dans Microsoft Edge | 2025-05-09T00:00:00.000000 | 2025-05-09T00:00:00.000000 |
| certfr-2025-avi-0382 | Multiples vulnérabilités dans les produits F5 | 2025-05-09T00:00:00.000000 | 2025-05-09T00:00:00.000000 |
| certfr-2025-avi-0381 | Multiples vulnérabilités dans GitLab | 2025-05-09T00:00:00.000000 | 2025-05-09T00:00:00.000000 |
| certfr-2025-avi-0380 | Vulnérabilité dans PostgreSQL | 2025-05-09T00:00:00.000000 | 2025-05-09T00:00:00.000000 |