Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-16644 | N/A | Webform REST - Moderately critical - Access bypass - S… |
Drupal |
Webform REST |
2026-08-25T22:21:51.345Z | 2026-08-26T18:40:31.903Z |
| cve-2026-16645 | N/A | PhotoSwipe - Responsive JavaScript Modal Image Gallery… |
Drupal |
PhotoSwipe - Responsive JavaScript Modal Image Gallery |
2026-08-25T22:21:47.480Z | 2026-08-26T18:41:49.991Z |
| cve-2026-15088 | N/A | Development Environment - Critical - Unsupported - SA-… |
Drupal |
Development Environment |
2026-08-25T22:21:43.754Z | 2026-08-26T18:54:39.563Z |
| cve-2026-18259 | N/A | Token Content Access - Moderately critical - Access by… |
Drupal |
Token Content Access |
2026-08-25T22:21:39.663Z | 2026-08-26T18:42:47.144Z |
| cve-2026-18260 | N/A | Disable Login Page - Critical - Unsupported - SA-CONTR… |
Drupal |
Disable Login Page |
2026-08-25T22:21:34.604Z | 2026-08-27T12:56:55.168Z |
| cve-2026-18261 | N/A | Powerful Surveys - Critical - Unsupported - SA-CONTRIB… |
Drupal |
Powerful Surveys |
2026-08-25T22:21:28.297Z | 2026-08-26T18:53:24.106Z |
| cve-2026-18985 | N/A | Edit in-place field - Moderately critical - Access byp… |
Drupal |
Edit in-place field |
2026-08-25T22:19:31.812Z | 2026-08-26T18:11:42.417Z |
| cve-2026-79911 | TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-b… |
TOTOLINK |
N600R |
2026-08-25T22:15:13.200Z | 2026-08-27T14:34:41.311Z | |
| cve-2026-80138 | 9.2 (v4.0) 9.8 (v3.1) | ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Inje… |
MacWarrior |
clipbucket-v5 |
2026-08-25T22:12:23.914Z | 2026-08-26T12:23:55.095Z |
| cve-2026-70665 | Doorkeeper OpenID Connect: DCR endpoint persists unval… |
doorkeeper-gem |
doorkeeper-openid_connect |
2026-08-25T22:09:53.197Z | 2026-08-27T14:34:50.455Z | |
| cve-2026-63403 | Faktory: Unrecovered panic in command handlers allows … |
contribsys |
faktory |
2026-08-25T22:04:48.255Z | 2026-08-26T14:31:10.402Z | |
| cve-2026-73180 | Apache Tomcat: Authenticated WebSocket session survive… |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T22:01:58.000Z | 2026-08-26T18:35:13.414Z | |
| cve-2026-63404 | Faktory: Insecure predictable /tmp/redis.conf enables … |
contribsys |
faktory |
2026-08-25T22:01:19.220Z | 2026-08-28T22:40:31.790Z | |
| cve-2026-68763 | Apache Tomcat: DoS via allocation leak in HTTP/2 backl… |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T22:00:37.047Z | 2026-08-26T18:36:43.341Z | |
| cve-2026-79845 | code-projects Simple Inventory System edit.php sql injection |
code-projects |
Simple Inventory System |
2026-08-25T22:00:11.376Z | 2026-08-26T14:32:32.575Z | |
| cve-2026-68569 | Apache Tomcat: Principal lookup can fail open in some cases |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T21:59:17.438Z | 2026-08-26T18:38:54.931Z | |
| cve-2026-80185 | 5.7 (v3.1) | Bluez: sdp-xml: bluez 5.86: unprivileged-local and adj… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-08-25T21:58:16.883Z | 2026-08-26T14:36:48.005Z |
| cve-2026-80186 | 7.6 (v3.1) | Bluez: stack overflow in name2utf8 causes dos and pote… |
Red Hat |
Red Hat Enterprise Linux 10 |
2026-08-25T21:58:16.875Z | 2026-08-27T14:34:59.323Z |
| cve-2026-68525 | Apache Tomcat: Redirect after FORM auth may bypass met… |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T21:57:18.557Z | 2026-08-26T18:40:55.312Z | |
| cve-2026-66422 | Apache Tomcat: Servlet role references can bypass decl… |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T21:55:16.928Z | 2026-08-26T18:52:26.487Z | |
| cve-2026-65927 | Apache Tomcat: RewriteValve [N] restarts at the second… |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T21:53:05.852Z | 2026-08-26T15:22:01.843Z | |
| cve-2026-62865 | TypeBot: Arbitrary server file read via Send Email blo… |
baptisteArno |
typebot.io |
2026-08-25T21:52:16.717Z | 2026-08-26T12:31:36.135Z | |
| cve-2026-65905 | Apache Tomcat: Limited replay attack possible with DIG… |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T21:51:33.307Z | 2026-08-26T15:21:11.604Z | |
| cve-2026-65637 | Apache Tomcat: HTTP/2 no-authority bypass of strict SN… |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T21:49:13.127Z | 2026-08-26T15:20:30.366Z | |
| cve-2026-62861 | TypeBot: Cross-tenant custom-domain removal via unboun… |
baptisteArno |
typebot.io |
2026-08-25T21:46:24.861Z | 2026-08-27T14:35:10.158Z | |
| cve-2026-65183 | Apache Tomcat: TOCTOU when setting specific permission… |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T21:44:49.363Z | 2026-08-26T15:19:19.234Z | |
| cve-2026-65182 | Apache Tomcat: Bypass longest prefix security constraint |
Apache Software Foundation |
Apache Tomcat |
2026-08-25T21:43:37.040Z | 2026-08-26T15:18:16.813Z | |
| cve-2026-62862 | TypeBot: Account takeover via brute-forceable 6-digit … |
baptisteArno |
typebot.io |
2026-08-25T21:43:21.320Z | 2026-08-26T15:04:13.958Z | |
| cve-2026-79804 | SililaWijesinghe Food Ordering System search.php sql i… |
SililaWijesinghe |
Food Ordering System |
2026-08-25T21:30:09.580Z | 2026-08-28T22:39:23.398Z | |
| cve-2026-80184 | 7.6 (v4.0) | In OpenStack Keystone before 29.0.3, tokens obtai… |
OpenStack |
Keystone |
2026-08-25T21:29:29.471Z | 2026-08-26T14:37:45.384Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2013-000039 | Wi-Fi Spot Configuration Software vulnerability in the connection process | 2013-05-15T14:25+09:00 | 2013-06-19T09:58+09:00 |
| jvndb-2013-000038 | OpenPNE vulnerable to cross-site scripting | 2013-05-13T13:39+09:00 | 2013-06-19T09:56+09:00 |
| jvndb-2013-000035 | Online Service Gate vulnerable in Office 365 password management | 2013-05-08T15:08+09:00 | 2013-05-08T15:08+09:00 |
| jvndb-2013-000037 | Yahoo! Browser vulnerable to address bar spoofing | 2013-04-26T15:50+09:00 | 2013-04-26T15:50+09:00 |
| jvndb-2013-000036 | jigbrowser+ for Android vulnerable to address bar spoofing | 2013-04-26T15:05+09:00 | 2013-04-26T15:05+09:00 |
| jvndb-2013-002427 | Buffer Overflow Vulnerability in Hitachi IT Operations Director | 2013-04-24T09:55+09:00 | 2013-04-24T09:55+09:00 |
| jvndb-2013-000034 | Multiple Cybozu products vulnerable to cross-site request forgery | 2013-04-15T17:08+09:00 | 2013-06-25T18:36+09:00 |
| jvndb-2013-000033 | Sleipnir Mobile for Android loads arbitrary Extension API | 2013-04-12T12:41+09:00 | 2013-04-12T12:41+09:00 |
| jvndb-2013-000032 | Sleipnir for Windows vulnerable to address bar spoofing | 2013-04-11T14:14+09:00 | 2013-04-11T14:14+09:00 |
| jvndb-2013-000031 | Active! mail vulnerable to information disclosure | 2013-04-04T14:43+09:00 | 2013-06-25T18:30+09:00 |
| jvndb-2013-000025 | OpenWnn for Android vulnerable to information disclosure | 2013-03-29T13:58+09:00 | 2013-03-29T13:58+09:00 |
| jvndb-2013-000030 | Lotus Domino vulnerable to denial-of-service (DoS) | 2013-03-28T12:32+09:00 | 2013-03-28T12:32+09:00 |
| jvndb-2013-000028 | OpenWnn/Flick support vulnerable to information disclosure | 2013-03-26T14:55+09:00 | 2013-03-26T14:55+09:00 |
| jvndb-2013-000027 | COBIME vulnerable to information disclosure | 2013-03-26T14:55+09:00 | 2013-03-26T14:55+09:00 |
| jvndb-2013-000029 | Simeji vulnerable to information disclosure | 2013-03-26T14:51+09:00 | 2013-03-26T14:51+09:00 |
| jvndb-2013-000026 | ArtIME Japanese Input vulnerable to information disclosure | 2013-03-26T13:36+09:00 | 2013-03-26T13:36+09:00 |
| jvndb-2013-000024 | Multiple NEC mobile routers vulnerable to cross-site request forgery | 2013-03-19T13:45+09:00 | 2013-06-25T18:19+09:00 |
| jvndb-2013-000023 | VxWorks Web Server vulnerable to denial-of-service (DoS) | 2013-03-18T14:43+09:00 | 2013-06-25T18:15+09:00 |
| jvndb-2013-000022 | VxWorks WebCLI vulnerable to denial-of-service (DoS) | 2013-03-18T14:40+09:00 | 2013-06-25T18:10+09:00 |
| jvndb-2013-000021 | VxWorks SSH server (IPSSH) denial-of-service (DoS) vulnerability | 2013-03-18T14:38+09:00 | 2013-06-25T18:06+09:00 |
| jvndb-2013-000018 | VxWorks SSH server (IPSSH) denial-of-service (DoS) vulnerability | 2013-03-18T14:33+09:00 | 2013-06-25T17:54+09:00 |
| jvndb-2013-000019 | VxWorks SSH server (IPSSH) denial-of-service (DoS) vulnerability | 2013-03-18T14:32+09:00 | 2013-06-25T17:57+09:00 |
| jvndb-2013-000020 | VxWorks SSH server (IPSSH) denial-of-service (DoS) vulnerability | 2013-03-18T14:30+09:00 | 2013-06-25T18:01+09:00 |
| jvndb-2013-000017 | Multiple Cisco products vulnerable to denial-of-service (DoS) | 2013-03-07T14:13+09:00 | 2013-03-11T16:22+09:00 |
| jvndb-2013-000016 | Kingsoft Writer vulnerable to buffer overflow | 2013-03-01T14:47+09:00 | 2013-03-01T14:47+09:00 |
| jvndb-2013-000014 | dopvSTAR* vulnerable to cross-site scripting | 2013-02-28T13:46+09:00 | 2013-02-28T13:46+09:00 |
| jvndb-2013-000013 | dopvCOMET* vulnerable to cross-site scripting | 2013-02-28T13:37+09:00 | 2013-02-28T13:37+09:00 |
| jvndb-2013-000015 | Multiple JustSystems products vulnerable to arbitrary code execution | 2013-02-26T14:45+09:00 | 2013-02-26T14:45+09:00 |
| jvndb-2013-001605 | Multiple vulnerabilities in Hitachi Tuning Manager and JP1/Performance Management | 2013-02-22T20:09+09:00 | 2013-02-22T20:09+09:00 |
| jvndb-2013-000012 | NEC Universal RAID Utility fails to restrict access permissions | 2013-02-21T13:54+09:00 | 2013-03-01T11:34+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-0924 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-10-25T00:00:00.000000 | 2024-10-25T00:00:00.000000 |
| certfr-2024-avi-0923 | Multiples vulnérabilités dans les produits IBM | 2024-10-25T00:00:00.000000 | 2024-10-25T00:00:00.000000 |
| certfr-2024-avi-0922 | Multiples vulnérabilités dans Microsoft Edge | 2024-10-25T00:00:00.000000 | 2024-10-25T00:00:00.000000 |
| certfr-2024-avi-0921 | Vulnérabilité dans les produits Microsoft | 2024-10-24T00:00:00.000000 | 2024-10-24T00:00:00.000000 |
| certfr-2024-avi-0920 | Vulnérabilité dans Microsoft Azure | 2024-10-24T00:00:00.000000 | 2024-10-24T00:00:00.000000 |
| certfr-2024-avi-0919 | Multiples vulnérabilités dans les produits Cisco | 2024-10-24T00:00:00.000000 | 2024-10-24T00:00:00.000000 |
| certfr-2024-avi-0918 | Multiples vulnérabilités dans GitLab | 2024-10-24T00:00:00.000000 | 2024-10-24T00:00:00.000000 |
| certfr-2024-avi-0917 | Vulnérabilité dans Fortinet FortiManager | 2024-10-23T00:00:00.000000 | 2024-10-24T00:00:00.000000 |
| certfr-2024-avi-0916 | Multiples vulnérabilités dans le greffon pour Office 365 de Splunk | 2024-10-23T00:00:00.000000 | 2024-10-23T00:00:00.000000 |
| certfr-2024-avi-0915 | Multiples vulnérabilités dans les produits Centreon | 2024-10-23T00:00:00.000000 | 2024-10-23T00:00:00.000000 |
| certfr-2024-avi-0914 | Vulnérabilité dans les produits Spring | 2024-10-23T00:00:00.000000 | 2024-10-23T00:00:00.000000 |
| certfr-2024-avi-0913 | Multiples vulnérabilités dans Google Chrome | 2024-10-23T00:00:00.000000 | 2024-10-23T00:00:00.000000 |
| certfr-2024-avi-0912 | Multiples vulnérabilités dans Liferay | 2024-10-23T00:00:00.000000 | 2024-10-23T00:00:00.000000 |
| certfr-2024-avi-0911 | Vulnérabilité dans les produits Moxa | 2024-10-22T00:00:00.000000 | 2024-10-22T00:00:00.000000 |
| certfr-2024-avi-0910 | Vulnérabilité dans MongoDB | 2024-10-22T00:00:00.000000 | 2024-10-22T00:00:00.000000 |
| certfr-2024-avi-0909 | Multiples vulnérabilités dans les produits Synology | 2024-10-21T00:00:00.000000 | 2024-10-22T00:00:00.000000 |
| certfr-2024-avi-0908 | Vulnérabilité dans Microsoft Edge | 2024-10-21T00:00:00.000000 | 2024-10-21T00:00:00.000000 |
| certfr-2024-avi-0907 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-10-18T00:00:00.000000 | 2024-10-18T00:00:00.000000 |
| certfr-2024-avi-0906 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-10-18T00:00:00.000000 | 2024-10-18T00:00:00.000000 |
| certfr-2024-avi-0905 | Multiples vulnérabilités dans les produits Moxa | 2024-10-18T00:00:00.000000 | 2024-10-18T00:00:00.000000 |
| certfr-2024-avi-0904 | Multiples vulnérabilités dans Foxit PDF Editor | 2024-10-18T00:00:00.000000 | 2024-10-18T00:00:00.000000 |
| certfr-2024-avi-0903 | Multiples vulnérabilités dans les produits IBM | 2024-10-18T00:00:00.000000 | 2024-10-18T00:00:00.000000 |
| certfr-2024-avi-0902 | Multiples vulnérabilités dans le noyau Linux de Red Hat | 2024-10-18T00:00:00.000000 | 2024-10-18T00:00:00.000000 |
| certfr-2024-avi-0901 | Multiples vulnérabilités dans Microsoft Edge | 2024-10-18T00:00:00.000000 | 2024-10-18T00:00:00.000000 |
| certfr-2024-avi-0900 | Multiples vulnérabilités dans Spring Framework | 2024-10-18T00:00:00.000000 | 2024-10-18T00:00:00.000000 |
| certfr-2024-avi-0899 | Vulnérabilité dans Grafana | 2024-10-18T00:00:00.000000 | 2024-10-21T00:00:00.000000 |
| certfr-2024-avi-0898 | Multiples vulnérabilités dans Google Pixel | 2024-10-17T00:00:00.000000 | 2024-10-17T00:00:00.000000 |
| certfr-2024-avi-0897 | Multiples vulnérabilités dans les produits Cisco | 2024-10-17T00:00:00.000000 | 2024-10-17T00:00:00.000000 |
| certfr-2024-avi-0896 | Vulnérabilité dans VMware HCX | 2024-10-17T00:00:00.000000 | 2024-10-17T00:00:00.000000 |
| certfr-2024-avi-0895 | Vulnérabilité dans OpenSSL | 2024-10-17T00:00:00.000000 | 2024-10-18T00:00:00.000000 |