Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-25836 | 6.7 (v3.1) | An improper neutralization of special elements us… |
Fortinet |
FortiSandbox Cloud |
2026-03-10T16:44:06.991Z | 2026-04-14T15:38:23.184Z |
| cve-2026-37589 | N/A | SourceCodester Storage Unit Rental Management Sys… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:33:11.824Z |
| cve-2026-36952 | N/A | Sourcecodester Online Thesis Archiving System v1.… |
n/a |
n/a |
2026-04-13T00:00:00.000Z | 2026-04-14T15:31:59.960Z |
| cve-2026-36950 | N/A | Sourcecodester Online Thesis Archiving System v1.… |
n/a |
n/a |
2026-04-13T00:00:00.000Z | 2026-04-14T15:31:40.795Z |
| cve-2026-28292 | simple-git has blockUnsafeOperationsPlugin bypass via … |
steveukx |
simple-git |
2026-03-10T18:34:21.717Z | 2026-04-14T15:30:40.620Z | |
| cve-2025-15527 | WP Recipe Maker <= 10.2.2 - Insecure Direct Object Ref… |
brechtvds |
WP Recipe Maker |
2026-01-16T04:44:33.994Z | 2026-04-14T15:30:23.549Z | |
| cve-2026-37590 | N/A | SourceCodester Storage Unit Rental Management Sys… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:29:38.686Z |
| cve-2026-37591 | N/A | Sourcecodester Storage Unit Rental Management Sys… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:29:26.653Z |
| cve-2026-37592 | N/A | Sourcecodester Storage Unit Rental Management Sys… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:29:15.190Z |
| cve-2026-37593 | N/A | SourceCodester Online Employees Work From Home At… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:29:02.156Z |
| cve-2026-37594 | N/A | SourceCodester Online Employees Work From Home At… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:28:50.725Z |
| cve-2026-37595 | N/A | SourceCodester Online Employees Work From Home At… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:28:38.905Z |
| cve-2026-37596 | N/A | SourceCodester Online Employees Work From Home At… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:28:25.909Z |
| cve-2026-37597 | N/A | SourceCodester Online Employees Work From Home At… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:27:12.818Z |
| cve-2026-37598 | N/A | SourceCodester Patient Appointment Scheduler Syst… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:26:27.302Z |
| cve-2026-37600 | N/A | SourceCodester Patient Appointment Scheduler Syst… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:25:24.236Z |
| cve-2026-37601 | N/A | SourceCodester Patient Appointment Scheduler Syst… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:25:09.200Z |
| cve-2026-32270 | Craft Commerce: Unauthenticated information disclosure… |
craftcms |
commerce |
2026-04-13T20:08:05.032Z | 2026-04-14T15:25:04.635Z | |
| cve-2026-37602 | N/A | SourceCodester Patient Appointment Scheduler Syst… |
n/a |
n/a |
2026-04-14T00:00:00.000Z | 2026-04-14T15:24:23.662Z |
| cve-2026-31280 | N/A | An issue in the Bluetooth RFCOMM service of Paran… |
n/a |
n/a |
2026-04-13T00:00:00.000Z | 2026-04-14T15:23:22.851Z |
| cve-2026-1253 | Group Chat & Video Chat by AtomChat <= 1.1.7 - Missing… |
atomchat |
Group Chat & Video Chat by AtomChat |
2026-03-21T03:26:47.861Z | 2026-04-14T15:21:58.613Z | |
| cve-2025-70936 | N/A | Vtiger CRM 8.4.0 contains a reflected cross-site … |
n/a |
n/a |
2026-04-13T00:00:00.000Z | 2026-04-14T15:21:22.985Z |
| cve-2026-39464 | N/A | WordPress Coming Soon Page, Under Construction & Maint… |
SeedProd |
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd |
2026-04-08T08:30:06.040Z | 2026-04-14T15:19:39.308Z |
| cve-2026-33865 | 5.1 (v4.0) | Stored XSS via unsafe YAML parsing in MLflow |
Mlflow |
Mlflow |
2026-04-07T12:57:38.525Z | 2026-04-14T15:13:57.547Z |
| cve-2026-39469 | N/A | WordPress PageLayer plugin <= 2.0.8 - Sensitive Data E… |
Softaculous |
PageLayer |
2026-04-08T08:30:07.826Z | 2026-04-14T15:13:46.091Z |
| cve-2026-33866 | 5.3 (v4.0) | Authorization Bypass in MLflow AJAX Endpoint |
Mlflow |
Mlflow |
2026-04-07T12:57:44.380Z | 2026-04-14T15:12:44.168Z |
| cve-2026-1499 | WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Ar… |
revmakx |
WP Duplicate – WordPress Migration Plugin |
2026-02-06T08:25:25.712Z | 2026-04-14T15:12:22.866Z | |
| cve-2026-2757 | N/A | Incorrect boundary conditions in the WebRTC: Audio/Vid… |
Mozilla |
Firefox |
2026-02-24T13:32:57.740Z | 2026-04-14T15:11:01.347Z |
| cve-2026-1055 | TalkJS <= 0.1.15 - Authenticated (Administrator+) Stor… |
talkjs |
TalkJS |
2026-02-19T04:36:28.335Z | 2026-04-14T15:10:31.175Z | |
| cve-2026-1999 | 7.1 (v4.0) | Incorrect Authorization vulnerability was identified i… |
GitHub |
Enterprise Server |
2026-02-18T20:44:51.396Z | 2026-04-14T15:09:57.585Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2012-000005 | osCommerce vulnerable to cross-site scripting | 2012-01-20T16:15+09:00 | 2012-04-26T16:58+09:00 |
| jvndb-2012-000037 | sp mode mail issue in the verification of SSL certificates | 2012-04-26T14:21+09:00 | 2012-04-26T14:21+09:00 |
| jvndb-2012-000036 | OSQA vulnerable to cross-site scripting | 2012-04-26T14:15+09:00 | 2012-04-26T14:15+09:00 |
| jvndb-2012-000034 | Multiple JustSystems products may insecurely load dynamic libraries | 2012-04-24T13:36+09:00 | 2012-04-24T13:36+09:00 |
| jvndb-2012-000033 | TwitRocker2 (Android version) vulnerable in the WebView class | 2012-04-20T12:21+09:00 | 2012-04-20T12:21+09:00 |
| jvndb-2012-000031 | ActiveScriptRuby vulnerable to arbitrary Ruby script execution | 2012-04-13T14:08+09:00 | 2012-04-13T14:08+09:00 |
| jvndb-2012-000032 | Dokodemo Rikunabi 2013 vulnerable to cross-site scripting | 2012-04-13T14:03+09:00 | 2012-04-13T14:03+09:00 |
| jvndb-2012-001932 | Vulnerability in Fujitsu Interstage List Works Where Permissions Cannot Be Denied | 2012-04-11T11:45+09:00 | 2012-04-11T11:45+09:00 |
| jvndb-2012-000030 | SENCHA SNS vulnerable to session fixation | 2012-04-05T16:41+09:00 | 2012-04-05T16:41+09:00 |
| jvndb-2012-000029 | SENCHA SNS vulnerable to cross-site request forgery | 2012-04-05T16:41+09:00 | 2012-04-05T16:41+09:00 |
| jvndb-2012-000028 | TOSHIBA TEC e-Studio series vulnerable to authentication bypass | 2012-04-05T16:40+09:00 | 2012-04-05T16:40+09:00 |
| jvndb-2012-000027 | Janetter vulnerable to cross-site request forgery | 2012-03-19T14:31+09:00 | 2012-03-19T14:31+09:00 |
| jvndb-2012-000026 | Janetter vulnerable to information disclosure | 2012-03-19T14:27+09:00 | 2012-03-19T14:27+09:00 |
| jvndb-2012-001793 | JP1/Cm2/Network Node Manager i Denial of Service (DoS) Vulnerability | 2012-03-19T12:04+09:00 | 2012-03-19T12:04+09:00 |
| jvndb-2012-000025 | Redmine vulnerable to cross-site scripting | 2012-03-13T13:39+09:00 | 2012-03-13T13:39+09:00 |
| jvndb-2012-000024 | twicca fails to restrict access permissions | 2012-03-13T13:36+09:00 | 2012-03-13T13:36+09:00 |
| jvndb-2012-000023 | Jenkins vulnerable to cross-site scripting | 2012-03-09T14:35+09:00 | 2012-03-09T14:35+09:00 |
| jvndb-2012-000022 | Jenkins vulnerable to cross-site scripting | 2012-03-09T14:28+09:00 | 2012-03-09T14:28+09:00 |
| jvndb-2012-000021 | SquirrelMail plugin Autocomplete vulnerable to cross-site scripting | 2012-03-09T14:18+09:00 | 2012-03-09T14:18+09:00 |
| jvndb-2012-000020 | ES File Explorer fails to restrict access permissions | 2012-03-05T15:50+09:00 | 2012-03-05T15:50+09:00 |
| jvndb-2012-000019 | Kingsoft Internet Security 2011 vulnerable to denial-of-service | 2012-03-01T14:03+09:00 | 2012-03-01T14:03+09:00 |
| jvndb-2012-000014 | Multiple COOKPAD applications for Android vulnerable in WebView class | 2012-02-22T14:44+09:00 | 2012-02-29T10:56+09:00 |
| jvndb-2012-000018 | Movable Type vulnerable to session hijacking | 2012-02-23T14:28+09:00 | 2012-02-23T14:28+09:00 |
| jvndb-2012-000017 | Movable Type vulnerable to OS command injection | 2012-02-23T14:21+09:00 | 2012-02-23T14:21+09:00 |
| jvndb-2012-000016 | Movable Type vulnerable to cross-site scripting | 2012-02-23T14:20+09:00 | 2012-02-23T14:20+09:00 |
| jvndb-2012-000015 | Movable Type vulnerable to cross-site request forgery | 2012-02-23T14:19+09:00 | 2012-02-23T14:19+09:00 |
| jvndb-2008-001576 | Fujitsu Interstage Application Server Interstage Management Console Arbitrary File Read/Delete Vulnerability | 2008-09-03T12:34+09:00 | 2012-02-15T18:13+09:00 |
| jvndb-2012-000013 | cforms II vulnerable to cross-site scripting | 2012-02-15T17:14+09:00 | 2012-02-15T17:14+09:00 |
| jvndb-2012-000011 | ALFTP may insecurely load executable files | 2012-02-13T15:58+09:00 | 2012-02-13T15:58+09:00 |
| jvndb-2012-000012 | Apache Struts 2 vulnerable to an arbitrary Java method execution | 2012-02-10T14:29+09:00 | 2012-02-10T14:29+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-0263 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-03-29T00:00:00.000000 | 2024-03-29T00:00:00.000000 |
| certfr-2024-avi-0262 | Multiples vulnérabilités dans les produits IBM | 2024-03-29T00:00:00.000000 | 2024-03-29T00:00:00.000000 |
| certfr-2024-avi-0257 | Multiples vulnérabilités dans Elasticsearch | 2024-03-28T00:00:00.000000 | 2024-03-29T00:00:00.000000 |
| certfr-2024-avi-0261 | Multiples vulnérabilités dans Microsoft Edge | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0260 | Multiples vulnérabilités dans les produits Cisco | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0259 | Multiples vulnérabilités dans GitLab | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0258 | Multiples vulnérabilités dans les produits Splunk | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0256 | Vulnérabilité dans Wireshark | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0255 | Vulnérabilité dans GLPI | 2024-03-28T00:00:00.000000 | 2024-03-28T00:00:00.000000 |
| certfr-2024-avi-0254 | Multiples vulnérabilités dans Google Chrome | 2024-03-27T00:00:00.000000 | 2024-03-27T00:00:00.000000 |
| certfr-2024-avi-0253 | Vulnérabilité dans Aruba ArubaOS-Switch | 2024-03-27T00:00:00.000000 | 2024-03-27T00:00:00.000000 |
| certfr-2024-avi-0252 | Multiples vulnérabilités dans Nagios XI | 2024-03-27T00:00:00.000000 | 2024-03-27T00:00:00.000000 |
| certfr-2024-avi-0251 | Multiples vulnérabilités dans Kaspersky Anti Targeted Attack | 2024-03-26T00:00:00.000000 | 2024-03-26T00:00:00.000000 |
| certfr-2024-avi-0250 | Vulnérabilité dans les produits Apple | 2024-03-26T00:00:00.000000 | 2024-03-26T00:00:00.000000 |
| certfr-2024-avi-0249 | Multiples vulnérabilités dans Tenable Security Center | 2024-03-26T00:00:00.000000 | 2024-03-26T00:00:00.000000 |
| certfr-2024-avi-0248 | Vulnérabilité dans Microsoft .Net | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0247 | Multiples vulnérabilités dans Microsoft Edge | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0246 | Multiples vulnérabilités dans Mozilla Firefox | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0245 | Multiples vulnérabilités dans MISP | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0244 | Multiples vulnérabilités dans les produits Netapp | 2024-03-25T00:00:00.000000 | 2024-03-25T00:00:00.000000 |
| certfr-2024-avi-0243 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-03-22T00:00:00.000000 | 2024-03-22T00:00:00.000000 |
| certfr-2024-avi-0242 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-03-22T00:00:00.000000 | 2024-03-22T00:00:00.000000 |
| certfr-2024-avi-0241 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2024-03-22T00:00:00.000000 | 2024-03-22T00:00:00.000000 |
| certfr-2024-avi-0240 | Multiples vulnérabilités dans les produits IBM | 2024-03-22T00:00:00.000000 | 2024-03-22T00:00:00.000000 |
| certfr-2024-avi-0239 | Vulnérabilité dans Microsoft Xbox Gaming Services | 2024-03-21T00:00:00.000000 | 2024-03-21T00:00:00.000000 |
| certfr-2024-avi-0238 | Multiples vulnérabilités dans les produits Ivanti | 2024-03-21T00:00:00.000000 | 2024-03-21T00:00:00.000000 |
| certfr-2024-avi-0237 | Multiples vulnérabilités dans les produits Belden | 2024-03-20T00:00:00.000000 | 2024-03-20T00:00:00.000000 |
| certfr-2024-avi-0236 | Vulnérabilité dans Spring Authorization Server | 2024-03-20T00:00:00.000000 | 2024-03-20T00:00:00.000000 |
| certfr-2024-avi-0235 | Multiples vulnérabilités dans Google Chrome | 2024-03-20T00:00:00.000000 | 2024-03-20T00:00:00.000000 |
| certfr-2024-avi-0234 | Multiples vulnérabilités dans les produits Mozilla | 2024-03-20T00:00:00.000000 | 2024-03-20T00:00:00.000000 |