Recent vulnerabilities


ID CVSS Description Vendor Product Published Updated
cve-2026-41262 Fleet: Cross-Team Policy Data Exposure via Global Poli… fleetdm
fleet
2026-08-26T18:32:30.669Z 2026-08-26T18:57:43.948Z
cve-2026-71171 7.2 (v3.1) Dell Cloud Disaster Recovery, versions 20.2 and p… Dell
Cloud Disaster Recovery
2026-08-26T18:30:52.487Z 2026-08-26T18:48:27.558Z
cve-2026-48786 Fleet: Observer-class users can view team enroll secre… fleetdm
fleet
2026-08-26T18:25:09.971Z 2026-08-26T18:49:37.564Z
cve-2026-70419 9.1 (v3.1) Dell Cloud Disaster Recovery, versions 20.2 and p… Dell
Cloud Disaster Recovery
2026-08-26T18:24:28.070Z 2026-08-26T18:52:08.264Z
cve-2026-79940 5.9 (v3.1) Dell iDRAC9, 14G versions prior to 7.00.00.182 an… Dell
iDRAC9
2026-08-26T18:16:42.618Z 2026-08-26T19:46:27.415Z
cve-2026-63179 Winter: Local File Inclusion through @import directive… wintercms
winter
2026-08-26T18:06:14.103Z 2026-08-26T18:51:15.095Z
cve-2026-19485 9.3 (v4.0) Bucket Squatting in Vertex AI Search for Commerce Google Cloud
Vertex AI Search for Commerce
2026-08-26T18:06:00.596Z 2026-08-26T19:04:26.776Z
cve-2026-54256 Winter: Authenticated IDOR in backend FileUpload widge… wintercms
winter
2026-08-26T17:53:36.237Z 2026-08-27T14:33:39.110Z
cve-2026-32639 Winter: Broken access control in `Cms\Controllers\Inde… wintercms
winter
2026-08-26T17:50:32.102Z 2026-08-29T02:46:44.275Z
cve-2026-58474 8.6 (v4.0) 8.8 (v3.1) whichllm < 0.5.16 Code Injection via run and snippet c… Andyyyy64
whichllm
2026-08-26T17:49:04.041Z 2026-08-29T11:47:31.365Z
cve-2026-76784 8.7 (v4.0) Insufficient Cryptographic Protections in Local Device… TP-Link Systems Inc.
HS103P3 / HS103P4 v5
2026-08-26T17:47:54.278Z 2026-08-26T18:50:19.860Z
cve-2026-32593 Winter: SQL Injection in Backend Filter Widget numberr… wintercms
winter
2026-08-26T17:27:07.836Z 2026-08-26T18:29:20.480Z
cve-2026-47841 7.4 (v3.1) WebAuthn User Verification Bypass via Session Serialization Spring
Spring Security
2026-08-26T17:08:52.788Z 2026-08-27T03:58:22.127Z
cve-2026-47837 6.8 (v3.1) Spring Cloud Config Server Monitor Endpoint Does Not V… Spring
Spring Cloud Config
2026-08-26T17:08:51.832Z 2026-08-26T18:50:49.428Z
cve-2026-47836 7.2 (v3.1) Spring Cloud Config Server Susceptible To TOCTOU Attac… Spring
Spring Cloud Config
2026-08-26T17:05:21.979Z 2026-08-27T03:58:24.390Z
cve-2026-32258 Winter: Stored XSS through Editor Settings custom styles wintercms
winter
2026-08-26T16:49:06.852Z 2026-08-26T17:35:11.529Z
cve-2026-32257 Winter: Stored XSS through Brand Settings custom styles wintercms
winter
2026-08-26T16:45:12.100Z 2026-08-27T14:33:49.017Z
cve-2026-35445 Winter: Authenticated backend users can bypass Users c… wintercms
winter
2026-08-26T16:40:51.500Z 2026-08-26T19:08:44.974Z
cve-2026-81036 8.5 (v4.0) 8.1 (v3.1) Stalwart Mail Server through 0.16.19 Authorization Cod… stalwartlabs
stalwart
2026-08-26T15:45:02.931Z 2026-08-29T02:45:24.847Z
cve-2026-81035 7.2 (v4.0) 8.1 (v3.1) Midday Missing Owner Check on Team Deletion midday-ai
midday
2026-08-26T15:45:02.234Z 2026-08-26T16:06:39.105Z
cve-2026-81034 8.3 (v4.0) 6.5 (v3.1) Netmaker through 1.6.0 Improper Certificate Validation… gravitl
netmaker
2026-08-26T15:45:01.529Z 2026-08-26T18:31:47.883Z
cve-2026-81033 6.9 (v4.0) 5.3 (v3.1) Automatisch through 0.15.0 User Enumeration via Forgot… automatisch
automatisch
2026-08-26T15:45:00.826Z 2026-08-28T16:00:31.483Z
cve-2026-81032 9.3 (v4.0) 9.8 (v3.1) NebulaGraph through 3.8.0 Unauthenticated Read and Mod… vesoft-inc
nebula
2026-08-26T15:45:00.144Z 2026-08-26T17:10:45.206Z
cve-2026-81031 8.6 (v4.0) 7.2 (v3.1) IDURAR ERP CRM through 4.1.1 Account Takeover via Unve… idurar
idurar-erp-crm
2026-08-26T15:44:59.362Z 2026-08-29T02:43:32.712Z
cve-2026-81030 7.1 (v4.0) 6.5 (v3.1) Mage AI through 0.9.79 Arbitrary File Read via Unvalid… mage-ai
mage-ai
2026-08-26T15:44:58.663Z 2026-08-26T16:05:12.110Z
cve-2026-81029 8.5 (v4.0) 8.1 (v3.1) OpenMetadata before 2.0.0 JWT Disclosure via Unvalidat… open-metadata
OpenMetadata
2026-08-26T15:44:57.988Z 2026-08-26T18:32:59.057Z
cve-2026-81028 6.9 (v4.0) 4.9 (v3.1) ZLMediaKit downloadFile Root-Directory Confinement Byp… ZLMediaKit
ZLMediaKit
2026-08-26T15:44:57.303Z 2026-08-28T16:00:38.893Z
cve-2026-81027 8.4 (v4.0) 8.5 (v3.1) one-api through 0.6.10 Missing Authorization on URL-Pa… songquanpeng
one-api
2026-08-26T15:44:56.599Z 2026-08-26T17:25:39.276Z
cve-2026-80428 9.3 (v4.0) 9.8 (v3.1) ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP … ILIAS-eLearning e.V.
ILIAS
2026-08-26T15:44:55.917Z 2026-08-29T02:41:40.892Z
cve-2026-80427 8.6 (v4.0) 8.4 (v3.1) bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument I… nfriedly
bestzip
2026-08-26T15:44:55.220Z 2026-08-29T11:48:06.751Z
ID CVSS Description Vendor Product Published Updated
ID Description Package Published Updated
ID Description Type
ID Description Updated
ID Description Updated
ID Description Published Updated
jvndb-2016-000032 Multiple Corega wireless LAN routers vulnerable to cross-site request forgery 2016-03-02T14:52+09:00 2016-03-16T13:46+09:00
jvndb-2016-001472 Remote File Inclusion Vulnerability in Hitachi Command Suite 2016-02-25T16:09+09:00 2016-09-14T18:18+09:00
jvndb-2016-000031 Log-Chat vulnerable to cross-site scripting 2016-02-22T14:56+09:00 2016-02-25T15:10+09:00
jvndb-2016-000029 LINE for Windows and LINE for Mac OS vulnerable to denial-of-service (DoS) 2016-02-19T14:43+09:00 2016-03-10T17:39+09:00
jvndb-2016-000027 EC-CUBE plugin "Help plug-in" vulnerable to SQL injection 2016-02-19T14:42+09:00 2016-03-03T17:51+09:00
jvndb-2016-000030 baserCMS vulnerable to OS command injection 2016-02-19T14:39+09:00 2016-03-07T15:51+09:00
jvndb-2016-000028 Internet Explorer cross-domain policy bypass 2016-02-19T14:39+09:00 2016-02-23T11:23+09:00
jvndb-2016-000026 Cybozu Office vulnerable to cross-site scripting 2016-02-15T16:21+09:00 2016-06-06T15:00+09:00
jvndb-2016-000025 Cybozu Office vulnerable to open redirect 2016-02-15T16:20+09:00 2016-02-23T16:32+09:00
jvndb-2016-000024 Cybozu Office vulnerable to cross-site request forgery 2016-02-15T16:20+09:00 2016-02-23T16:32+09:00
jvndb-2016-000023 Cybozu Office access restriction bypass vulnerability 2016-02-15T15:45+09:00 2016-02-23T16:32+09:00
jvndb-2016-000022 Cybozu Office vulnerable to information disclosure 2016-02-15T15:44+09:00 2016-02-23T16:32+09:00
jvndb-2016-000021 Cybozu Office vulnerable to information disclosure 2016-02-15T15:44+09:00 2016-02-23T16:32+09:00
jvndb-2016-000020 Cybozu Office vulnerable to denial-of-service (DoS) 2016-02-15T15:43+09:00 2016-02-23T16:32+09:00
jvndb-2016-000018 Microsoft Producer for Microsoft Office PowerPoint vulnerable to cross-site scripting 2016-02-15T09:56+09:00 2016-02-15T09:56+09:00
jvndb-2016-000019 Akerun - Smart Lock Robot App for iOS fails to verify SSL server certificates 2016-02-12T15:59+09:00 2017-05-23T12:25+09:00
jvndb-2016-000017 JOB-CUBE vulnerable to cross-site scripting 2016-01-29T14:06+09:00 2016-03-04T17:47+09:00
jvndb-2016-000016 Vine MV vulnerable to cross-site scripting 2016-01-29T13:50+09:00 2016-02-10T10:19+09:00
jvndb-2016-000015 EXPRESSCLUSTER X vulnerable to directory traversal 2016-01-29T13:45+09:00 2016-03-16T14:24+09:00
jvndb-2016-000012 HOME SPOT CUBE vulnerable to OS command injection 2016-01-27T14:40+09:00 2016-02-16T17:26+09:00
jvndb-2016-000011 HOME SPOT CUBE vulnerable to clickjacking 2016-01-27T14:40+09:00 2016-02-16T17:26+09:00
jvndb-2016-000010 HOME SPOT CUBE vulnerable to cross-site request forgery 2016-01-27T14:40+09:00 2016-02-16T17:26+09:00
jvndb-2016-000009 HOME SPOT CUBE vulnerable to HTTP header injection 2016-01-27T14:40+09:00 2016-02-16T17:26+09:00
jvndb-2016-000008 HOME SPOT CUBE vulnerable to open redirect 2016-01-27T14:40+09:00 2016-02-16T17:26+09:00
jvndb-2016-000007 HOME SPOT CUBE vulnerable to cross-site scripting 2016-01-27T14:40+09:00 2016-02-16T17:26+09:00
jvndb-2016-000006 Multiple Buffalo network devices vulnerable to cross-site scripting 2016-01-22T14:36+09:00 2016-03-10T17:53+09:00
jvndb-2016-000005 Multiple Buffalo network devices vulnerable to cross-site request forgery 2016-01-22T14:36+09:00 2016-03-10T17:53+09:00
jvndb-2016-000004 Shoplat App for iOS issue in the verification of SSL certificates 2016-01-18T14:24+09:00 2017-05-23T13:57+09:00
jvndb-2016-000003 H2O vulnerable to HTTP header injection 2016-01-15T13:57+09:00 2016-01-27T17:33+09:00
jvndb-2016-000002 acmailer vulnerable to OS command injection 2016-01-15T13:57+09:00 2016-01-27T17:20+09:00
ID Description Updated
ID Description
ID Description Published Updated
certfr-2025-avi-0289 Vulnérabilité dans Microsoft .Net 2025-04-09T00:00:00.000000 2025-04-09T00:00:00.000000
certfr-2025-avi-0288 Multiples vulnérabilités dans Microsoft Windows 2025-04-09T00:00:00.000000 2025-04-09T00:00:00.000000
certfr-2025-avi-0287 Multiples vulnérabilités dans Microsoft Office 2025-04-09T00:00:00.000000 2025-04-09T00:00:00.000000
certfr-2025-avi-0286 Vulnérabilité dans Google Chrome 2025-04-09T00:00:00.000000 2025-04-09T00:00:00.000000
certfr-2025-avi-0285 Multiples vulnérabilités dans les produits SAP 2025-04-08T00:00:00.000000 2025-04-25T00:00:00.000000
certfr-2025-avi-0284 Multiples vulnérabilités dans les produits Siemens 2025-04-08T00:00:00.000000 2025-04-08T00:00:00.000000
certfr-2025-avi-0283 Multiples vulnérabilités dans VMware Tanzu Greenplum 2025-04-08T00:00:00.000000 2025-04-10T00:00:00.000000
certfr-2025-avi-0282 Multiples vulnérabilités dans Schneider Electric ConneXium Network Manager 2025-04-08T00:00:00.000000 2025-04-08T00:00:00.000000
certfr-2025-avi-0281 Multiples vulnérabilités dans Google Android 2025-04-08T00:00:00.000000 2025-04-08T00:00:00.000000
certfr-2025-avi-0280 Vulnérabilité dans les produits ESET 2025-04-07T00:00:00.000000 2025-04-07T00:00:00.000000
certfr-2025-avi-0279 Multiples vulnérabilités dans les produits IBM 2025-04-04T00:00:00.000000 2025-04-04T00:00:00.000000
certfr-2025-avi-0278 Multiples vulnérabilités dans le noyau Linux de SUSE 2025-04-04T00:00:00.000000 2025-04-04T00:00:00.000000
certfr-2025-avi-0277 Multiples vulnérabilités dans le noyau Linux de Debian LTS 2025-04-04T00:00:00.000000 2025-04-04T00:00:00.000000
certfr-2025-avi-0276 Multiples vulnérabilités dans le noyau Linux d'Ubuntu 2025-04-04T00:00:00.000000 2025-04-04T00:00:00.000000
certfr-2025-avi-0275 Multiples vulnérabilités dans Microsoft Edge 2025-04-04T00:00:00.000000 2025-04-04T00:00:00.000000
certfr-2025-avi-0274 Multiples vulnérabilités dans MISP 2025-04-04T00:00:00.000000 2025-04-04T00:00:00.000000
certfr-2025-avi-0273 Vulnérabilité dans les produits Ivanti 2025-04-03T00:00:00.000000 2025-04-03T00:00:00.000000
certfr-2025-avi-0272 Multiples vulnérabilités dans les produits Splunk 2025-04-03T00:00:00.000000 2025-04-03T00:00:00.000000
certfr-2025-avi-0271 Vulnérabilité dans Tenable Nessus Agent 2025-04-03T00:00:00.000000 2025-04-03T00:00:00.000000
certfr-2025-avi-0270 Multiples vulnérabilités dans les produits Cisco 2025-04-03T00:00:00.000000 2025-04-03T00:00:00.000000
certfr-2025-avi-0269 Multiples vulnérabilités dans les produits Moxa 2025-04-02T00:00:00.000000 2025-04-02T00:00:00.000000
certfr-2025-avi-0268 Vulnérabilité dans les produits VMware 2025-04-02T00:00:00.000000 2025-04-02T00:00:00.000000
certfr-2025-avi-0267 Multiples vulnérabilités dans MongoDB Server 2025-04-02T00:00:00.000000 2025-04-02T00:00:00.000000
certfr-2025-avi-0266 Multiples vulnérabilités dans les produits Mozilla 2025-04-02T00:00:00.000000 2025-04-02T00:00:00.000000
certfr-2025-avi-0265 Multiples vulnérabilités dans Google Chrome 2025-04-02T00:00:00.000000 2025-04-11T00:00:00.000000
certfr-2025-avi-0264 Multiples vulnérabilités dans Trend Micro Deep Security Agent 2025-04-02T00:00:00.000000 2025-04-02T00:00:00.000000
certfr-2025-avi-0263 Multiples vulnérabilités dans HPE Aruba Networking Virtual Intranet Access 2025-04-02T00:00:00.000000 2025-04-02T00:00:00.000000
certfr-2025-avi-0262 Multiples vulnérabilités dans les produits Kaspersky 2025-04-02T00:00:00.000000 2025-04-02T00:00:00.000000
certfr-2025-avi-0261 Multiples vulnérabilités dans Microsoft Azure 2025-04-01T00:00:00.000000 2025-04-01T00:00:00.000000
certfr-2025-avi-0260 Multiples vulnérabilités dans Zabbix 2025-04-01T00:00:00.000000 2025-04-01T00:00:00.000000