Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-5823 | itsourcecode Construction Management System borrowed_t… |
itsourcecode |
Construction Management System |
2026-04-08T23:30:14.821Z | 2026-04-09T13:02:22.003Z | |
| cve-2026-5815 | D-Link DIR-645 hedwig.cgi hedwigcgi_main stack-based o… |
D-Link |
DIR-645 |
2026-04-08T23:15:14.287Z | 2026-04-13T19:54:18.197Z | |
| cve-2026-5814 | PHPGurukul Online Course Registration check_availabili… |
PHPGurukul |
Online Course Registration |
2026-04-08T23:00:17.193Z | 2026-04-09T14:17:57.980Z | |
| cve-2026-5813 | PHPGurukul Online Course Registration check_availabili… |
PHPGurukul |
Online Course Registration |
2026-04-08T22:45:11.613Z | 2026-04-09T15:04:03.190Z | |
| cve-2026-5812 | SourceCodester Pharmacy Product Management System POST… |
SourceCodester |
Pharmacy Product Management System |
2026-04-08T22:30:15.161Z | 2026-04-09T16:16:28.528Z | |
| cve-2025-9484 | 4.3 (v3.1) | Missing Authorization in GitLab |
GitLab |
GitLab |
2026-04-08T22:27:17.831Z | 2026-04-09T13:03:18.113Z |
| cve-2025-12664 | 7.5 (v3.1) | Improper Validation of Specified Quantity in Input in GitLab |
GitLab |
GitLab |
2026-04-08T22:26:42.854Z | 2026-04-09T13:03:53.739Z |
| cve-2026-1092 | 7.5 (v3.1) | Improper Validation of Specified Quantity in Input in GitLab |
GitLab |
GitLab |
2026-04-08T22:26:12.837Z | 2026-04-09T15:09:51.969Z |
| cve-2026-1101 | 6.5 (v3.1) | Improper Validation of Specified Quantity in Input in GitLab |
GitLab |
GitLab |
2026-04-08T22:26:07.834Z | 2026-04-09T15:41:03.766Z |
| cve-2026-1516 | 5.7 (v3.1) | Improper Control of Generation of Code ('Code Injectio… |
GitLab |
GitLab |
2026-04-08T22:25:57.848Z | 2026-04-09T15:42:34.893Z |
| cve-2026-1752 | 4.3 (v3.1) | Incorrect Authorization in GitLab |
GitLab |
GitLab |
2026-04-08T22:25:52.858Z | 2026-04-09T14:58:43.291Z |
| cve-2026-2104 | 4.3 (v3.1) | Authorization Bypass Through User-Controlled Key in GitLab |
GitLab |
GitLab |
2026-04-08T22:25:47.858Z | 2026-04-09T15:43:25.441Z |
| cve-2026-2619 | 4.3 (v3.1) | Incorrect Authorization in GitLab |
GitLab |
GitLab |
2026-04-08T22:25:37.932Z | 2026-04-09T13:04:26.216Z |
| cve-2026-4332 | 5.4 (v3.1) | Improper Neutralization of Input During Web Page Gener… |
GitLab |
GitLab |
2026-04-08T22:25:27.848Z | 2026-04-09T13:05:08.328Z |
| cve-2026-4916 | 2.7 (v3.1) | Missing Authorization in GitLab |
GitLab |
GitLab |
2026-04-08T22:25:22.837Z | 2026-04-09T13:05:54.501Z |
| cve-2026-5173 | 8.5 (v3.1) | Exposed Dangerous Method or Function in GitLab |
GitLab |
GitLab |
2026-04-08T22:25:12.946Z | 2026-04-09T13:16:53.628Z |
| cve-2026-3199 | 9.4 (v4.0) | Nexus Repository 3 - Authenticated Remote Code Executi… |
Sonatype |
Nexus Repository |
2026-04-08T22:17:10.117Z | 2026-04-09T13:17:32.341Z |
| cve-2026-3438 | 5.1 (v4.0) | Nexus Repository 3 - Reflected Cross-Site Scripting (X… |
Sonatype |
Nexus Repository |
2026-04-08T22:16:09.657Z | 2026-04-09T13:18:17.962Z |
| cve-2026-5811 | SourceCodester Online Food Ordering System POST Parame… |
SourceCodester |
Online Food Ordering System |
2026-04-08T22:15:13.008Z | 2026-04-09T13:18:59.568Z | |
| cve-2026-5810 | SourceCodester Sales and Inventory System GET Paramete… |
SourceCodester |
Sales and Inventory System |
2026-04-08T22:00:17.660Z | 2026-04-13T19:45:56.736Z | |
| cve-2026-40037 | 7.1 (v4.0) 6.5 (v3.1) | OpenClaw < 2026.3.31 - Unsafe Request Body Replay via … |
OpenClaw |
OpenClaw |
2026-04-08T21:35:29.255Z | 2026-04-09T14:40:56.336Z |
| cve-2026-40036 | 8.7 (v4.0) 7.5 (v3.1) | Unfurl < 2026.04 - Denial of Service via Unbounded zli… |
obsidianforensics |
unfurl |
2026-04-08T21:35:28.460Z | 2026-04-11T03:05:51.530Z |
| cve-2026-40035 | 9.3 (v4.0) 9.1 (v3.1) | Unfurl - Werkzeug Debugger Exposure via String Config … |
obsidianforensics |
unfurl |
2026-04-08T21:35:27.703Z | 2026-04-09T13:19:56.161Z |
| cve-2026-40032 | 8.5 (v4.0) 7.8 (v3.1) | UAC < 3.3.0-rc1 Command Injection via Placeholder Subs… |
tclahr |
UAC |
2026-04-08T21:35:27.020Z | 2026-04-09T19:32:44.357Z |
| cve-2026-40031 | 8.5 (v4.0) 7.8 (v3.1) | MemProcFS < 5.17 DLL/Shared Library Hijacking |
ufrisk |
MemProcFS |
2026-04-08T21:35:26.293Z | 2026-04-09T16:16:34.107Z |
| cve-2026-40030 | 8.4 (v4.0) 7.8 (v3.1) | parseusbs < 1.9 Command Injection via Volume Path Argument |
khyrenz |
parseusbs |
2026-04-08T21:35:25.533Z | 2026-04-09T18:10:49.070Z |
| cve-2026-40029 | 8.5 (v4.0) 7.8 (v3.1) | parseusbs < 1.9 Command Injection via Crafted LNK Filename |
khyrenz |
parseusbs |
2026-04-08T21:35:24.801Z | 2026-04-09T14:48:31.844Z |
| cve-2026-40028 | 5.1 (v4.0) 5.4 (v3.1) | Hayabusa < 3.8.0 XSS via JSON Log Import |
Yamato-Security |
hayabusa |
2026-04-08T21:35:24.001Z | 2026-04-11T03:04:53.201Z |
| cve-2026-40027 | 8.4 (v4.0) 7.3 (v3.1) | ALEAPP NQ Vault Artifact Parser Path Traversal |
abrignoni |
ALEAPP |
2026-04-08T21:35:23.178Z | 2026-04-09T13:41:25.490Z |
| cve-2026-40026 | 4.8 (v4.0) 4.4 (v3.1) | Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bou… |
sleuthkit |
sleuthkit |
2026-04-08T21:35:22.278Z | 2026-04-09T19:39:36.707Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2011-000046 | Multiple Cybozu products vulnerable to cross-site scripting | 2011-06-24T19:21+09:00 | 2011-06-24T19:21+09:00 |
| jvndb-2011-000045 | Multiple Cybozu products vulnerable to cross-site scripting | 2011-06-24T19:18+09:00 | 2011-06-24T19:18+09:00 |
| jvndb-2011-000044 | Cybozu Garoon vulnerable to cross-site scripting | 2011-06-24T19:15+09:00 | 2011-06-24T19:15+09:00 |
| jvndb-2011-000042 | WeblyGo vulnerable to cross-site scripting | 2011-06-20T15:37+09:00 | 2011-06-20T15:37+09:00 |
| jvndb-2011-000043 | Ichitaro series vulnerable to arbitrary code execution | 2011-06-16T19:04+09:00 | 2011-06-16T19:04+09:00 |
| jvndb-2011-000041 | Microsoft MSXML vulnerability in HTTP request processing | 2011-06-16T12:28+09:00 | 2011-06-16T12:28+09:00 |
| jvndb-2011-000040 | Microsoft Outlook read receipt function vulnerability | 2011-06-16T12:25+09:00 | 2011-06-16T12:25+09:00 |
| jvndb-2011-000039 | ASP.NET vulnerable to cross-site scripting | 2011-06-16T12:23+09:00 | 2011-06-16T12:23+09:00 |
| jvndb-2011-000038 | Internet Explorer vulnerable to cross-site scripting | 2011-06-16T12:21+09:00 | 2011-06-16T12:21+09:00 |
| jvndb-2011-000037 | Clipboard contents alteration vulnerability in Internet Explorer | 2011-06-16T12:18+09:00 | 2011-06-16T12:18+09:00 |
| jvndb-2011-000036 | Microsoft Windows VBScript implementation file name disclosure vulnerability | 2011-06-16T12:11+09:00 | 2011-06-16T12:11+09:00 |
| jvndb-2011-000035 | Java Web Start may insecurely load dynamic libraries | 2011-06-10T16:23+09:00 | 2013-03-26T15:14+09:00 |
| jvndb-2011-000034 | Java Web Start may insecurely load settings files | 2011-06-10T16:23+09:00 | 2013-03-26T14:46+09:00 |
| jvndb-2011-000033 | Java Web Start may insecurely load policy files | 2011-06-10T16:22+09:00 | 2013-03-29T14:50+09:00 |
| jvndb-2011-000032 | WalRack upload file handilng vulnerability | 2011-05-26T13:37+09:00 | 2011-05-26T13:37+09:00 |
| jvndb-2011-000031 | Movable Type vulnerable to cross-site scripting | 2011-05-25T17:37+09:00 | 2011-05-25T17:37+09:00 |
| jvndb-2011-000030 | iVIEW Suite vulnerable to SQL injection | 2011-05-19T16:49+09:00 | 2011-05-19T16:49+09:00 |
| jvndb-2011-000028 | Virus Buster 2009 key input encryption function vulnerability | 2011-05-17T17:17+09:00 | 2011-05-17T17:17+09:00 |
| jvndb-2011-000026 | Applications that use the Windows Help function may be vulnerable to privilege escalation | 2011-05-13T19:36+09:00 | 2011-05-13T19:36+09:00 |
| jvndb-2011-000027 | La Fonera+ vulnerable to denial-of-service (DoS) | 2011-05-13T19:17+09:00 | 2011-05-13T19:17+09:00 |
| jvndb-2011-000029 | EC-CUBE vulnerable to cross-site request forgery | 2011-05-11T08:44+09:00 | 2011-05-11T08:44+09:00 |
| jvndb-2011-000025 | Multiple Buffalo routers vulnerable to cross-site request forgery | 2011-05-11T08:37+09:00 | 2011-05-11T08:37+09:00 |
| jvndb-2011-000024 | Multiple Yamaha routers vulnerable to denial-of-service (DoS) | 2011-05-11T08:32+09:00 | 2011-05-31T10:39+09:00 |
| jvndb-2011-000023 | Password Vault Web Access vulnerable to cross-site scripting | 2011-04-08T14:09+09:00 | 2011-04-08T14:09+09:00 |
| jvndb-2011-001156 | Hitachi Tuning Manager Software Cross-Site Scripting Vulnerability | 2011-04-01T15:52+09:00 | 2011-04-01T15:52+09:00 |
| jvndb-2011-000022 | Picasa may insecurely load executable files | 2011-03-28T08:11+09:00 | 2011-03-28T08:11+09:00 |
| jvndb-2011-000021 | e107 vulnerable to cross-site scripting | 2011-03-28T08:06+09:00 | 2011-03-28T08:06+09:00 |
| jvndb-2011-000020 | IBM Tivoli vulnerable to denial-of-service (DoS) | 2011-03-10T16:38+09:00 | 2018-02-07T17:10+09:00 |
| jvndb-2011-001145 | JP1/NETM/DM Denial of Service (DoS) Vulnerability | 2011-03-08T10:25+09:00 | 2011-03-08T10:25+09:00 |
| jvndb-2011-000019 | OTRS vulnerable to OS command injection | 2011-03-07T18:19+09:00 | 2011-03-07T18:19+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-0168 | Vulnérabilité dans les produits Xen | 2024-02-27T00:00:00.000000 | 2024-02-27T00:00:00.000000 |
| certfr-2024-avi-0167 | Vulnérabilité dans les produits Moxa | 2024-02-27T00:00:00.000000 | 2024-02-27T00:00:00.000000 |
| certfr-2024-avi-0166 | Vulnérabilité dans les produits WithSecure | 2024-02-26T00:00:00.000000 | 2024-02-26T00:00:00.000000 |
| certfr-2024-avi-0165 | Multiples vulnérabilités dans Microsoft Edge | 2024-02-26T00:00:00.000000 | 2024-02-26T00:00:00.000000 |
| certfr-2024-avi-0164 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0163 | Multiples vulnérabilités dans le noyau Linux d'Ubuntu | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0162 | Multiples vulnérabilités dans les produits IBM | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0161 | Vulnérabilité dans les produits SonicWall | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0160 | Multiples vulnérabilités dans Ruby on Rails | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0159 | Multiples vulnérabilités dans les produits Mozilla | 2024-02-23T00:00:00.000000 | 2024-02-23T00:00:00.000000 |
| certfr-2024-avi-0158 | Vulnérabilité dans Kaspersky Endpoint Security | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0157 | Vulnérabilité dans PostgreSQL JDBC | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0156 | Multiples vulnérabilités dans les produits Tenable | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0155 | Multiples vulnérabilités dans Gitlab | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0154 | Vulnérabilité dans Spring Framework | 2024-02-22T00:00:00.000000 | 2024-02-22T00:00:00.000000 |
| certfr-2024-avi-0153 | Multiples vulnérabilités dans les produits VMware | 2024-02-21T00:00:00.000000 | 2024-02-21T00:00:00.000000 |
| certfr-2024-avi-0152 | Multiples vulnérabilités dans Google Chrome | 2024-02-21T00:00:00.000000 | 2024-02-21T00:00:00.000000 |
| certfr-2024-avi-0151 | Multiples vulnérabilités dans Joomla! | 2024-02-21T00:00:00.000000 | 2025-01-28T00:00:00.000000 |
| certfr-2024-avi-0150 | Multiples vulnérabilités dans les produits Mozilla | 2024-02-21T00:00:00.000000 | 2024-02-21T00:00:00.000000 |
| certfr-2024-avi-0149 | Multiples vulnérabilités dans Moodle | 2024-02-20T00:00:00.000000 | 2024-02-20T00:00:00.000000 |
| certfr-2024-avi-0148 | Vulnérabilité dans Kaspersky Anti Targeted Attack | 2024-02-20T00:00:00.000000 | 2024-02-20T00:00:00.000000 |
| certfr-2024-avi-0147 | Vulnérabilité dans Spring Security | 2024-02-19T00:00:00.000000 | 2024-02-19T00:00:00.000000 |
| certfr-2024-avi-0146 | Multiples vulnérabilités dans le noyau Linux de RedHat | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0145 | Multiples vulnérabilités dans les produits IBM | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0144 | Multiples vulnérabilités dans le noyau Linux de SUSE | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0143 | Multiples vulnérabilités dans le noyau Linux Ubuntu | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0142 | Vulnérabilité dans NetApp SnapCenter | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0141 | Vulnérabilité dans Liferay | 2024-02-16T00:00:00.000000 | 2024-02-16T00:00:00.000000 |
| certfr-2024-avi-0140 | Multiples vulnérabilités dans Liferay | 2024-02-15T00:00:00.000000 | 2024-02-15T00:00:00.000000 |
| certfr-2024-avi-0139 | Multiples vulnérabilités dans les produits Palo Alto Networks | 2024-02-15T00:00:00.000000 | 2024-02-19T00:00:00.000000 |