Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-48548 | 6.9 (v4.0) 6.5 (v3.1) | Nagios Core CSRF via cmd.cgi |
Nagios Enterprises, LLC. |
Nagios Core |
2026-08-26T15:33:59.685Z | 2026-08-26T17:29:31.213Z |
| cve-2026-54614 | DebugKit: MailPreview contains unsafe reflection |
cakephp |
debug_kit |
2026-08-26T15:30:23.966Z | 2026-08-29T02:40:09.901Z | |
| cve-2026-54569 | SENAITE.CORE: Improper Neutralization of Directives in… |
senaite |
senaite.core |
2026-08-26T15:28:19.919Z | 2026-08-26T17:35:57.088Z | |
| cve-2026-54606 | SunEditor: DOM XSS in SunEditor Embed Plugin via Exter… |
JiHong88 |
suneditor |
2026-08-26T15:25:58.083Z | 2026-08-26T18:28:06.384Z | |
| cve-2026-75062 | 9.2 (v4.0) | Eval Injection in google/langfun via default lf.query … |
Google |
langfun |
2026-08-26T14:50:50.604Z | 2026-08-27T16:55:00.832Z |
| cve-2026-80589 | block: stop the timeout timer when releasing a never a… |
Linux |
Linux |
2026-08-26T14:37:43.293Z | 2026-08-27T05:02:10.391Z | |
| cve-2026-80588 | mptcp: reclaim forward-allocated memory on RX path errors |
Linux |
Linux |
2026-08-26T14:37:42.685Z | 2026-08-27T05:02:09.335Z | |
| cve-2026-80587 | mptcp: avoid combining some incoming suboptions |
Linux |
Linux |
2026-08-26T14:37:42.093Z | 2026-08-27T12:40:23.299Z | |
| cve-2026-80586 | mptcp: options: reset DSS fields in case of unexpected size |
Linux |
Linux |
2026-08-26T14:37:41.493Z | 2026-08-27T05:02:07.204Z | |
| cve-2026-80585 | mptcp: fastopen: only mark MPTFO subflows with SYN data |
Linux |
Linux |
2026-08-26T14:37:40.901Z | 2026-08-27T05:02:06.112Z | |
| cve-2026-80584 | s390/qeth: validate user buffer length in SNMP and ARP… |
Linux |
Linux |
2026-08-26T14:37:40.302Z | 2026-08-27T05:02:04.879Z | |
| cve-2026-80583 | ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses |
Linux |
Linux |
2026-08-26T14:37:39.704Z | 2026-08-27T12:40:21.902Z | |
| cve-2026-80582 | drm/shmem_helper: Check VMA boundaries for PMD mappings |
Linux |
Linux |
2026-08-26T14:37:39.113Z | 2026-08-27T05:02:02.758Z | |
| cve-2026-80581 | N/A | ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in … |
Linux |
Linux |
2026-08-26T14:37:38.510Z | 2026-08-27T12:40:20.576Z |
| cve-2026-80580 | fbdev: bound mode sysfs output to the sysfs buffer |
Linux |
Linux |
2026-08-26T14:37:37.917Z | 2026-08-27T05:02:01.683Z | |
| cve-2026-80579 | fbdev: clear fb_info->mode before deleting a videomode |
Linux |
Linux |
2026-08-26T14:37:37.320Z | 2026-08-27T05:02:00.629Z | |
| cve-2026-80578 | fbdev: core: Fix pointer desynchronization in fb_io_read() |
Linux |
Linux |
2026-08-26T14:37:36.722Z | 2026-08-27T05:01:59.582Z | |
| cve-2026-80577 | N/A | drm/panthor: skip zero-sized firmware sections |
Linux |
Linux |
2026-08-26T14:37:36.132Z | 2026-08-26T14:37:36.132Z |
| cve-2026-80576 | drm/amdgpu: reject oversized IBs with per-ring packet limits |
Linux |
Linux |
2026-08-26T14:37:35.538Z | 2026-08-27T05:01:58.528Z | |
| cve-2026-80575 | Input: cs40l50-vibra - validate custom data from user space |
Linux |
Linux |
2026-08-26T14:37:34.942Z | 2026-08-27T05:01:57.416Z | |
| cve-2026-80574 | Input: focaltech - fix array out-of-bounds in focaltec… |
Linux |
Linux |
2026-08-26T14:37:34.353Z | 2026-08-27T05:01:56.362Z | |
| cve-2026-80573 | N/A | Input: iforce - validate input packet lengths |
Linux |
Linux |
2026-08-26T14:37:33.756Z | 2026-08-27T04:58:55.441Z |
| cve-2026-80572 | Input: byd - synchronize timer deletion before freeing… |
Linux |
Linux |
2026-08-26T14:37:33.141Z | 2026-08-27T12:40:19.284Z | |
| cve-2026-80571 | N/A | powerpc/pseries: papr-phy-attest - validate cmd.length… |
Linux |
Linux |
2026-08-26T14:37:32.541Z | 2026-08-26T14:37:32.541Z |
| cve-2026-80570 | Input: synaptics-rmi4 - zero report size on F54 work error |
Linux |
Linux |
2026-08-26T14:37:31.940Z | 2026-08-27T05:01:54.209Z | |
| cve-2026-80569 | Input: synaptics-rmi4 - bound the F54 report size to t… |
Linux |
Linux |
2026-08-26T14:37:31.338Z | 2026-08-27T05:01:53.135Z | |
| cve-2026-80568 | Input: synaptics-rmi4 - block s_input when F54 queue is busy |
Linux |
Linux |
2026-08-26T14:37:30.740Z | 2026-08-27T05:01:52.050Z | |
| cve-2026-80567 | N/A | Input: synaptics-rmi4 - propagate F54 worker errors to… |
Linux |
Linux |
2026-08-26T14:37:30.152Z | 2026-08-26T14:37:30.152Z |
| cve-2026-80566 | N/A | Input: hynitron_cstxxx - validate touch count and finger IDs |
Linux |
Linux |
2026-08-26T14:37:29.552Z | 2026-08-26T14:37:29.552Z |
| cve-2026-80565 | crypto: qce - fix error path in devm_qce_register_algs |
Linux |
Linux |
2026-08-26T14:37:28.953Z | 2026-08-27T05:01:50.972Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2015-000180 | pWebManager vulnerable to OS command injection | 2015-11-13T14:25+09:00 | 2015-11-17T16:21+09:00 |
| jvndb-2015-000177 | Apple OS X authentication issue when recovering from sleep mode | 2015-11-13T14:25+09:00 | 2015-11-17T16:15+09:00 |
| jvndb-2015-000176 | SonicWall TotalSecure TZ 100 Series vulnerable to denial-of-service (DoS) | 2015-11-06T12:30+09:00 | 2015-11-09T10:47+09:00 |
| jvndb-2015-000174 | Multiple TYPE-MOON games vulnerable to OS command injection | 2015-11-05T14:11+09:00 | 2015-11-09T10:39+09:00 |
| jvndb-2015-000175 | ISUCON5 qualifier portal web application (eventapp) vulnerable to OS command injection | 2015-11-02T14:10+09:00 | 2015-11-11T15:33+09:00 |
| jvndb-2015-000172 | Multiple routers contain issue in preventing clickjacking attacks | 2015-10-30T15:16+09:00 | 2016-02-12T17:16+09:00 |
| jvndb-2015-000171 | HTML::Scrubber vulnerable to cross-site scripting | 2015-10-30T15:16+09:00 | 2015-10-30T15:16+09:00 |
| jvndb-2015-000170 | Enisys Gw fails to restrict access permissions | 2015-10-29T13:46+09:00 | 2015-11-02T18:05+09:00 |
| jvndb-2015-000169 | Enisys Gw vulnerable to cross-site scripting | 2015-10-29T13:46+09:00 | 2015-11-02T18:05+09:00 |
| jvndb-2015-000168 | Enisys Gw vulnerable to arbitrary file creation | 2015-10-29T13:37+09:00 | 2015-11-02T18:05+09:00 |
| jvndb-2015-000167 | Enisys Gw vulnerable to SQL injection | 2015-10-29T13:37+09:00 | 2015-11-02T18:05+09:00 |
| jvndb-2015-000164 | ANA App fails to verify SSL server certificates | 2015-10-28T14:50+09:00 | 2018-03-07T13:50+09:00 |
| jvndb-2015-000166 | EC-CUBE vulnerable to cross-site request forgery | 2015-10-26T12:27+09:00 | 2015-11-13T19:36+09:00 |
| jvndb-2015-000162 | AirDroid for Android vulnerable in handling of implicit intents | 2015-10-16T14:00+09:00 | 2015-10-20T17:56+09:00 |
| jvndb-2015-000160 | Avast vulnerable to directory traversal | 2015-10-16T14:00+09:00 | 2015-10-20T17:56+09:00 |
| jvndb-2015-000126 | eXtplorer vulnerable to cross-site request forgery | 2015-10-15T12:24+09:00 | 2015-10-19T15:55+09:00 |
| jvndb-2015-000159 | Party Track SDK for iOS fails to verify server certificates | 2015-10-14T15:41+09:00 | 2015-11-11T17:32+09:00 |
| jvndb-2015-000158 | Pref Shimane CMS vulnerable to SQL injection | 2015-10-09T14:12+09:00 | 2015-10-14T17:26+09:00 |
| jvndb-2015-000154 | phpRechnung vulnerable to SQL injection | 2015-10-09T14:12+09:00 | 2015-10-14T17:26+09:00 |
| jvndb-2015-000153 | Dojo Toolkit vulnerable to cross-site scripting | 2015-10-09T14:12+09:00 | 2015-10-14T17:26+09:00 |
| jvndb-2015-000152 | Cybozu Garoon vulnerable to LDAP injection | 2015-10-07T14:48+09:00 | 2016-06-02T19:15+09:00 |
| jvndb-2015-000151 | Multiple PHP code execution vulnerabilitles in Cybozu Garoon | 2015-10-07T14:48+09:00 | 2016-05-30T15:34+09:00 |
| jvndb-2015-000149 | gollum vulnerable to file exposure | 2015-10-02T13:36+09:00 | 2015-10-08T15:26+09:00 |
| jvndb-2015-000148 | Dotclear vulnerable to cross-site scripting | 2015-10-02T13:36+09:00 | 2015-10-06T18:02+09:00 |
| jvndb-2015-000147 | AjaXplorer vulnerable to directory traversal | 2015-10-01T14:11+09:00 | 2015-10-07T17:38+09:00 |
| jvndb-2015-000141 | Python for Windows may insecurely load dynamic libraries | 2015-10-01T14:11+09:00 | 2015-10-08T15:25+09:00 |
| jvndb-2015-000140 | Canary Labs Trend Web Server vulnerable to buffer overflow | 2015-10-01T14:11+09:00 | 2015-10-06T18:00+09:00 |
| jvndb-2015-000146 | MATCHA SNS access restriction bypass vulnerability | 2015-09-30T15:05+09:00 | 2015-10-08T15:25+09:00 |
| jvndb-2015-000145 | MATCHA SNS vulnerable to code injection | 2015-09-30T15:05+09:00 | 2015-10-08T15:25+09:00 |
| jvndb-2015-000144 | MATCHA INVOICE vulnerable to code injection | 2015-09-30T15:04+09:00 | 2015-10-08T15:25+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0234 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0233 | Multiples vulnérabilités dans les produits IBM | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0232 | Vulnérabilité dans Liferay | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0231 | Vulnérabilité dans Microsoft Office | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0230 | Vulnérabilité dans Tenable Nessus Agent | 2025-03-21T00:00:00.000000 | 2025-03-21T00:00:00.000000 |
| certfr-2025-avi-0229 | Vulnérabilité dans Veeam Backup & Replication | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0228 | Multiples vulnérabilités dans Spring Security | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0227 | Vulnérabilité dans Liferay | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0226 | Vulnérabilité dans Google Chrome | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0225 | Vulnérabilité dans Drupal | 2025-03-20T00:00:00.000000 | 2025-03-20T00:00:00.000000 |
| certfr-2025-avi-0224 | Multiples vulnérabilités dans les produits Synology | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0223 | Multiples vulnérabilités dans Suricata | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0222 | Vulnérabilité dans MongoDB C Driver | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0221 | Multiples vulnérabilités dans HPE Aruba Networking AOS-CX | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0220 | Vulnérabilité dans Mattermost Server | 2025-03-19T00:00:00.000000 | 2025-04-17T00:00:00.000000 |
| certfr-2025-avi-0219 | Multiples vulnérabilités dans GLPI | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0218 | Multiples vulnérabilités dans Atlassian Jira | 2025-03-19T00:00:00.000000 | 2025-03-19T00:00:00.000000 |
| certfr-2025-avi-0217 | Multiples vulnérabilités dans Mattermost Server | 2025-03-18T00:00:00.000000 | 2025-04-17T00:00:00.000000 |
| certfr-2025-avi-0216 | Multiples vulnérabilités dans les produits Schneider Electric | 2025-03-17T00:00:00.000000 | 2025-03-17T00:00:00.000000 |
| certfr-2025-avi-0215 | Multiples vulnérabilités dans VMware Tanzu Gemfire | 2025-03-17T00:00:00.000000 | 2025-03-17T00:00:00.000000 |
| certfr-2025-avi-0214 | Multiples vulnérabilités dans les produits IBM | 2025-03-14T00:00:00.000000 | 2025-03-14T00:00:00.000000 |
| certfr-2025-avi-0213 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-03-14T00:00:00.000000 | 2025-03-14T00:00:00.000000 |
| certfr-2025-avi-0212 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-03-14T00:00:00.000000 | 2025-03-14T00:00:00.000000 |
| certfr-2025-avi-0211 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-03-14T00:00:00.000000 | 2025-03-14T00:00:00.000000 |
| certfr-2025-avi-0210 | Multiples vulnérabilités dans VMware Tanzu | 2025-03-14T00:00:00.000000 | 2025-03-14T00:00:00.000000 |
| certfr-2025-avi-0209 | Multiples vulnérabilités dans PHP | 2025-03-14T00:00:00.000000 | 2025-03-14T00:00:00.000000 |
| certfr-2025-avi-0208 | Vulnérabilité dans Microsoft Dataverse | 2025-03-14T00:00:00.000000 | 2025-03-14T00:00:00.000000 |
| certfr-2025-avi-0207 | Multiples vulnérabilités dans Cisco IOS XR | 2025-03-13T00:00:00.000000 | 2025-03-13T00:00:00.000000 |
| certfr-2025-avi-0206 | Vulnérabilité dans Juniper Networks Junos OS | 2025-03-13T00:00:00.000000 | 2025-03-13T00:00:00.000000 |
| certfr-2025-avi-0205 | Multiples vulnérabilités dans GitLab | 2025-03-13T00:00:00.000000 | 2025-03-13T00:00:00.000000 |