Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-18794 | 8.8 (v4.0) 8.2 (v3.1) | OpenRGB: insufficient input data checks lead to Denial… |
CalcProgrammer1 |
OpenRGB |
2026-08-26T09:29:57.359Z | 2026-08-26T12:57:54.118Z |
| cve-2026-2388 | Reviews and Rating – Google Reviews <= 5.10 - Authenti… |
designextreme |
Reviews and Rating – Google Reviews |
2026-08-26T09:27:43.234Z | 2026-08-27T14:34:17.895Z | |
| cve-2026-77535 | 9.1 (v3.1) | A malicious actor with access to the network and … |
Ubiquiti Inc |
UniFi Network Application |
2026-08-26T09:27:25.053Z | 2026-08-26T13:01:06.867Z |
| cve-2026-59683 | 9.3 (v4.0) 9.8 (v3.1) | OpenRGB: local and remote system compromise via arbitr… |
CalcProgrammer1 |
OpenRGB |
2026-08-26T09:24:42.722Z | 2026-08-26T13:01:35.058Z |
| cve-2026-77534 | 9.9 (v3.1) | A malicious actor with access to the network and … |
Ubiquiti Inc |
UniFi OS Server |
2026-08-26T09:21:17.844Z | 2026-08-27T03:56:44.534Z |
| cve-2026-19042 | 8.8 (v3.1) | Command Injection in TeamViewer Desktop Client for Lin… |
TeamViewer |
Full Client |
2026-08-26T09:16:13.127Z | 2026-08-26T13:02:05.302Z |
| cve-2026-59682 | 8.8 (v4.0) 9.1 (v3.1) | Arbitrary file overwrite and deletion local and remote… |
CalcProgrammer1 |
OpenRGB |
2026-08-26T09:13:22.465Z | 2026-08-26T13:04:59.707Z |
| cve-2026-16444 | 7.5 (v3.1) | Improper Validation of File Paths in TeamViewer Deskto… |
TeamViewer |
Full Client, Host, QuickSupport & Portable |
2026-08-26T09:10:16.193Z | 2026-08-27T03:58:23.229Z |
| cve-2026-77533 | 9.9 (v3.1) | A malicious actor with access to the network and … |
Ubiquiti Inc |
UniFi Protect Application |
2026-08-26T08:57:33.271Z | 2026-08-26T15:46:54.332Z |
| cve-2026-19197 | Broken access control in dashboard snapshots |
Grafana |
Grafana OSS |
2026-08-26T08:50:27.854Z | 2026-08-27T17:22:36.904Z | |
| cve-2026-19538 | 8.2 (v4.0) | Bypass of BLOCKED ACL items on proxy protocol port ove… |
NLnet Labs |
NSD |
2026-08-26T08:47:08.992Z | 2026-08-26T14:00:12.918Z |
| cve-2026-19401 | 8.2 (v4.0) | Remote UDP DoS by sending multiple DNS Cookie options |
NLnet Labs |
NSD |
2026-08-26T08:44:08.078Z | 2026-08-26T14:16:26.813Z |
| cve-2026-18916 | 6.9 (v4.0) | Remote TCP DoS by throttling the TCP receive window |
NLnet Labs |
NSD |
2026-08-26T08:39:12.258Z | 2026-08-26T14:22:31.309Z |
| cve-2026-18664 | 8.2 (v4.0) | Wrong interpretation of ACL ranges |
NLnet Labs |
NSD |
2026-08-26T08:34:22.871Z | 2026-08-26T14:47:35.523Z |
| cve-2026-80237 | 8.8 (v3.1) 8.7 (v4.0) | Thinking Software Technology|Efence - Arbitrary File Upload |
Thinking Software Technology |
Efence |
2026-08-26T08:28:14.081Z | 2026-08-26T14:54:40.597Z |
| cve-2026-80236 | 8.2 (v3.1) 8.8 (v4.0) | Thinking Software Technology|Efence - SQL Injection |
Thinking Software Technology |
Efence |
2026-08-26T08:27:12.886Z | 2026-08-26T13:05:40.957Z |
| cve-2026-80235 | 9.8 (v3.1) 9.3 (v4.0) | Thinking Software Technology|EFence - Arbitrary File Upload |
Thinking Software Technology |
EFence |
2026-08-26T08:26:12.960Z | 2026-08-26T13:57:37.398Z |
| cve-2026-80234 | 5.3 (v3.1) 6.9 (v4.0) | CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authen… |
CAYIN Technology |
CAYIN CMS-WS |
2026-08-26T08:22:13.081Z | 2026-08-26T13:57:58.236Z |
| cve-2026-80233 | 7.2 (v3.1) 8.6 (v4.0) | CAYIN Technology|CAYIN CMS-WS/CMS-SE/SMP - Arbitrary … |
CAYIN Technology |
CAYIN CMS-WS |
2026-08-26T08:19:40.187Z | 2026-08-26T13:58:21.259Z |
| cve-2026-9668 | 6.3 (v3.1) | SQL injection vulnerability in ZTE SCP product |
ZTE |
SCP |
2026-08-26T08:02:07.539Z | 2026-08-26T13:58:39.827Z |
| cve-2026-75977 | Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) P… |
kitae-park |
Mang Board WP |
2026-08-26T07:42:01.311Z | 2026-08-26T14:00:00.264Z | |
| cve-2026-6178 | Betheme <= 28.4 - Authenticated (Contributor+) Stored … |
MuffinGroup |
Betheme |
2026-08-26T07:42:00.865Z | 2026-08-26T14:51:16.787Z | |
| cve-2026-18884 | WooCommerce Lottery <= 2.2.9 - Unauthenticated Time-Ba… |
wpgenie |
WooCommerce Lottery |
2026-08-26T07:42:00.282Z | 2026-08-26T18:51:23.804Z | |
| cve-2026-78237 | 7.8 (v3.1) | Insufficient input validation in Admin By Request (ABR) |
Admin By Request (ABR) |
Admin By Request (ABR) |
2026-08-26T07:24:32.411Z | 2026-08-28T07:03:58.670Z |
| cve-2026-78236 | 8.8 (v3.1) | Insecure PIN derivation mechanism in Admin By Request (ABR) |
Admin By Request (ABR) |
Admin By Request (ABR) |
2026-08-26T07:20:58.647Z | 2026-08-28T06:41:41.298Z |
| cve-2026-58108 | 1.2 (v4.0) | Personal access token delete filters on Session column… |
Ericsson |
CodeChecker |
2026-08-26T06:48:06.407Z | 2026-08-26T13:59:36.984Z |
| cve-2026-15366 | 2.4 (v4.0) | A control logic defect in a specific built-in web… |
vivo |
Kids Mode |
2026-08-26T06:46:54.944Z | 2026-08-26T13:59:11.317Z |
| cve-2026-15365 | 2.4 (v4.0) | A pop-up logic flaw in a certain feature of Kids … |
vivo |
Kids Mode |
2026-08-26T06:45:35.488Z | 2026-08-26T15:15:52.942Z |
| cve-2026-18331 | Formidable Forms <= 6.33.1 - Unauthenticated Stored Cr… |
strategy11team |
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More |
2026-08-26T06:08:28.961Z | 2026-08-26T14:08:15.044Z | |
| cve-2026-18431 | Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthentic… |
themefusion |
Avada (Fusion) Builder |
2026-08-26T06:08:28.442Z | 2026-08-27T14:34:23.749Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2014-000108 | jigbrowser+ for iOS same origin policy bypass | 2014-09-25T14:52+09:00 | 2014-09-29T11:47+09:00 |
| jvndb-2014-000107 | SLFileManager for Android vulnerable to directory traversal | 2014-09-25T14:52+09:00 | 2015-07-31T16:30+09:00 |
| jvndb-2014-000111 | Yuko Yuko App for Android fails to verify SSL server certificates | 2014-09-22T13:50+09:00 | 2014-09-22T13:50+09:00 |
| jvndb-2014-000110 | Dotclear vulnerable to cross-site scripting | 2014-09-19T13:42+09:00 | 2014-09-25T17:52+09:00 |
| jvndb-2014-000109 | Bump for Android vulnerable in handling of implicit intents | 2014-09-19T13:41+09:00 | 2014-09-25T17:44+09:00 |
| jvndb-2014-000114 | FileMaker Pro fails to verify SSL server certificates | 2014-09-18T20:36+09:00 | 2014-09-24T18:47+09:00 |
| jvndb-2014-000113 | FileMaker Pro vulnerable to cross-site scripting | 2014-09-18T20:36+09:00 | 2015-05-22T11:37+09:00 |
| jvndb-2014-000106 | 365 Links series vulnerable to cross-site scripting | 2014-09-17T15:23+09:00 | 2014-09-19T13:33+09:00 |
| jvndb-2014-000105 | Help Page in multiple Adobe products vulnerable to cross-site scripting | 2014-09-12T14:00+09:00 | 2014-09-29T11:42+09:00 |
| jvndb-2014-000104 | Movable Type vulnerable to cross-site scripting | 2014-09-09T15:02+09:00 | 2014-09-11T16:56+09:00 |
| jvndb-2014-000084 | WisePoint vulnerable to session fixation | 2014-09-04T16:46+09:00 | 2014-09-09T15:02+09:00 |
| jvndb-2014-000103 | EmFTP may insecurely load executable files | 2014-09-04T16:36+09:00 | 2014-09-09T15:15+09:00 |
| jvndb-2014-000102 | Kindle App for Android fails to verify SSL server certificates | 2014-08-29T13:38+09:00 | 2014-09-03T18:25+09:00 |
| jvndb-2014-000101 | MailPoet Newsletters vulnerable to cross-site request forgery | 2014-08-26T13:33+09:00 | 2014-08-28T18:13+09:00 |
| jvndb-2014-000099 | Advance-Flow vulnerable to SQL injection | 2014-08-19T12:35+09:00 | 2014-08-20T16:26+09:00 |
| jvndb-2014-000100 | Cakifo vulnerable to cross-site scripting | 2014-08-18T13:32+09:00 | 2014-08-20T16:30+09:00 |
| jvndb-2014-000096 | Shutter vulnerable to cross-site scripting | 2014-08-15T13:27+09:00 | 2014-08-19T16:27+09:00 |
| jvndb-2014-000095 | Shutter vulnerable to SQL injection | 2014-08-15T13:24+09:00 | 2015-01-15T17:47+09:00 |
| jvndb-2014-000098 | Ameba for Android contains an issue where it fails to verify SSL server certificates | 2014-08-14T12:32+09:00 | 2014-08-18T12:22+09:00 |
| jvndb-2014-000097 | Dominion KX2-101 vulnerable to denial-of-service (DoS) | 2014-08-12T14:03+09:00 | 2014-08-18T09:44+09:00 |
| jvndb-2014-000094 | Piwigo vulnerable to SQL injection | 2014-08-08T13:57+09:00 | 2014-08-08T13:57+09:00 |
| jvndb-2014-000093 | Piwigo vulnerable to cross-site scripting | 2014-08-08T13:52+09:00 | 2014-08-19T16:48+09:00 |
| jvndb-2014-000092 | Piwigo vulnerable to cross-site scripting | 2014-08-08T13:49+09:00 | 2014-08-15T13:35+09:00 |
| jvndb-2014-000085 | GOM Player vulnerable to denial-of-service (DoS) | 2014-08-06T15:22+09:00 | 2014-08-13T18:29+09:00 |
| jvndb-2014-000091 | ServerView Operations Manager vulnerable to cross-site scripting | 2014-08-01T15:42+09:00 | 2014-08-18T10:05+09:00 |
| jvndb-2014-000086 | Outlook.com for Android contains an issue where it fails to verify SSL server certificates | 2014-07-30T15:11+09:00 | 2014-08-18T10:09+09:00 |
| jvndb-2014-000087 | Multiple I-O DATA IP Cameras vulnerable to authentication bypass | 2014-07-29T14:24+09:00 | 2014-08-01T18:30+09:00 |
| jvndb-2014-000088 | PerlMailer vulnerable to cross-site scripting | 2014-07-29T14:20+09:00 | 2014-08-01T18:28+09:00 |
| jvndb-2014-000089 | acmailer contains a cross-site request forgery vulnerability | 2014-07-29T14:15+09:00 | 2014-08-01T18:29+09:00 |
| jvndb-2013-002240 | Arbitrary program execution vulnerability in TrendLink ActiveX control | 2014-07-25T14:44+09:00 | 2014-07-25T14:44+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2025-avi-0024 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2025-01-10T00:00:00.000000 | 2025-01-10T00:00:00.000000 |
| certfr-2025-avi-0023 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2025-01-10T00:00:00.000000 | 2025-01-10T00:00:00.000000 |
| certfr-2025-avi-0022 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2025-01-10T00:00:00.000000 | 2025-01-10T00:00:00.000000 |
| certfr-2025-avi-0021 | Multiples vulnérabilités dans les produits IBM | 2025-01-10T00:00:00.000000 | 2025-01-10T00:00:00.000000 |
| certfr-2025-avi-0020 | Vulnérabilité dans Asterisk | 2025-01-10T00:00:00.000000 | 2025-01-10T00:00:00.000000 |
| certfr-2025-avi-0019 | Multiples vulnérabilités dans Mozilla Thunderbird | 2025-01-09T00:00:00.000000 | 2025-01-15T00:00:00.000000 |
| certfr-2025-avi-0018 | Multiples vulnérabilités dans les produits Juniper Networks | 2025-01-09T00:00:00.000000 | 2025-01-09T00:00:00.000000 |
| certfr-2025-avi-0017 | Vulnérabilité dans les produits HPE Aruba Networking | 2025-01-09T00:00:00.000000 | 2025-01-09T00:00:00.000000 |
| certfr-2025-avi-0016 | Multiples vulnérabilités dans les produits Palo Alto Networks | 2025-01-09T00:00:00.000000 | 2025-01-09T00:00:00.000000 |
| certfr-2025-avi-0015 | Multiples vulnérabilités dans GitLab | 2025-01-09T00:00:00.000000 | 2025-01-09T00:00:00.000000 |
| certfr-2025-avi-0014 | Multiples vulnérabilités dans les produits Ivanti | 2025-01-09T00:00:00.000000 | 2025-01-09T00:00:00.000000 |
| certfr-2025-avi-0013 | Multiples vulnérabilités dans les produits SonicWall | 2025-01-08T00:00:00.000000 | 2025-01-08T00:00:00.000000 |
| certfr-2025-avi-0012 | Vulnérabilité dans Google Chrome | 2025-01-08T00:00:00.000000 | 2025-01-08T00:00:00.000000 |
| certfr-2025-avi-0011 | Vulnérabilité dans VMware Aria automation et Cloud Fondation | 2025-01-08T00:00:00.000000 | 2025-01-08T00:00:00.000000 |
| certfr-2025-avi-0010 | Multiples vulnérabilités dans les produits Splunk | 2025-01-08T00:00:00.000000 | 2025-01-08T00:00:00.000000 |
| certfr-2025-avi-0009 | Multiples vulnérabilités dans les produits Mozilla | 2025-01-08T00:00:00.000000 | 2025-01-15T00:00:00.000000 |
| certfr-2025-avi-0008 | Multiples vulnérabilités dans Joomla! | 2025-01-08T00:00:00.000000 | 2025-01-08T00:00:00.000000 |
| certfr-2025-avi-0007 | Multiples vulnérabilités dans HPE Aruba Networking 501 Wireless Client Bridge | 2025-01-08T00:00:00.000000 | 2025-01-08T00:00:00.000000 |
| certfr-2025-avi-0006 | Multiples vulnérabilités dans LibreOffice | 2025-01-08T00:00:00.000000 | 2025-01-08T00:00:00.000000 |
| certfr-2025-avi-0005 | Vulnérabilité dans Google Pixel | 2025-01-08T00:00:00.000000 | 2025-01-08T00:00:00.000000 |
| certfr-2025-avi-0004 | Multiples vulnérabilités dans Google Android | 2025-01-07T00:00:00.000000 | 2025-01-03T00:00:00.000000 |
| certfr-2025-avi-0003 | Multiples vulnérabilités dans les produits IBM | 2025-01-03T00:00:00.000000 | 2025-01-03T00:00:00.000000 |
| certfr-2025-avi-0002 | Multiples vulnérabilités dans le noyau Linux de Debian LTS | 2025-01-03T00:00:00.000000 | 2025-01-06T00:00:00.000000 |
| certfr-2025-avi-0001 | Multiples vulnérabilités dans les produits Moxa | 2025-01-03T00:00:00.000000 | 2025-01-03T00:00:00.000000 |
| certfr-2024-avi-1110 | Multiples vulnérabilités dans le greffon Security QRadar Log Management AQL de IBM | 2024-12-27T00:00:00.000000 | 2024-12-27T00:00:00.000000 |
| certfr-2024-avi-1109 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-12-27T00:00:00.000000 | 2024-12-27T00:00:00.000000 |
| certfr-2024-avi-1108 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-12-27T00:00:00.000000 | 2024-12-27T00:00:00.000000 |
| certfr-2024-avi-1107 | Vulnérabilité dans les produits Palo Alto Networks | 2024-12-27T00:00:00.000000 | 2024-12-27T00:00:00.000000 |
| certfr-2024-avi-1106 | Vulnérabilité dans Adobe ColdFusion | 2024-12-24T00:00:00.000000 | 2024-12-24T00:00:00.000000 |
| certfr-2024-avi-1105 | Multiples vulnérabilités dans Tenable Security Center | 2024-12-23T00:00:00.000000 | 2024-12-23T00:00:00.000000 |