Recent vulnerabilities
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| cve-2026-33785 | 8.8 (v3.1) 6.3 (v4.0) | Junos OS: MX Series: Missing Authorization for specifi… |
Juniper Networks |
Junos OS |
2026-04-09T21:37:04.370Z | 2026-04-14T03:55:32.652Z |
| cve-2026-35337 | Apache Storm Client: RCE through Unsafe Deserializatio… |
Apache Software Foundation |
Apache Storm Client |
2026-04-13T09:11:06.193Z | 2026-04-14T03:55:31.489Z | |
| cve-2026-33858 | Apache Airflow: Unsafe Deserialization via Legacy Seri… |
Apache Software Foundation |
Apache Airflow |
2026-04-13T14:36:30.956Z | 2026-04-14T03:55:30.291Z | |
| cve-2012-1854 | N/A | Untrusted search path vulnerability in VBE6.dll i… |
n/a |
n/a |
2012-07-10T21:00:00.000Z | 2026-04-14T03:55:29.134Z |
| cve-2026-34621 | 8.6 (v3.1) | Acrobat Reader | Improperly Controlled Modification of… |
Adobe |
Acrobat Reader |
2026-04-11T06:45:43.512Z | 2026-04-14T03:55:27.955Z |
| cve-2026-21643 | 9.1 (v3.1) | An improper neutralization of special elements us… |
Fortinet |
FortiClientEMS |
2026-02-06T08:24:43.877Z | 2026-04-14T03:55:26.806Z |
| cve-2023-36424 | 7.8 (v3.1) | Windows Common Log File System Driver Elevation of Pri… |
Microsoft |
Windows 11 version 22H3 |
2023-11-14T17:57:08.919Z | 2026-04-14T03:55:25.577Z |
| cve-2025-60710 | 7.8 (v3.1) | Host Process for Windows Tasks Elevation of Privilege … |
Microsoft |
Windows 11 Version 24H2 |
2025-11-11T17:59:25.479Z | 2026-04-14T03:55:25.244Z |
| cve-2023-21529 | 8.8 (v3.1) | Microsoft Exchange Server Remote Code Execution Vulner… |
Microsoft |
Microsoft Exchange Server 2019 Cumulative Update 12 |
2023-02-14T19:33:00.590Z | 2026-04-14T03:55:24.065Z |
| cve-2026-6010 | CodeAstro Online Classroom takeassessment2.php sql injection |
CodeAstro |
Online Classroom |
2026-04-10T03:30:14.967Z | 2026-04-14T03:18:56.594Z | |
| cve-2026-6003 | code-projects Simple IT Discussion Forum user.php cros… |
code-projects |
Simple IT Discussion Forum |
2026-04-10T02:15:14.177Z | 2026-04-14T03:17:51.899Z | |
| cve-2026-5996 | Totolink A7100RU CGI cstecgi.cgi setAdvancedInfoShow o… |
Totolink |
A7100RU |
2026-04-10T01:00:18.922Z | 2026-04-14T03:16:32.811Z | |
| cve-2026-5991 | Tenda F451 WrlExtraSet formWrlExtraSet stack-based overflow |
Tenda |
F451 |
2026-04-09T23:45:14.599Z | 2026-04-14T03:15:21.622Z | |
| cve-2026-34424 | 9.3 (v4.0) 9.8 (v3.1) | Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote… |
Nextendweb |
Smart Slider 3 Pro for WordPress |
2026-04-09T22:59:38.306Z | 2026-04-14T03:13:40.678Z |
| cve-2026-5986 | Zod jsVideoUrlParser util.js getTime redos |
Zod |
jsVideoUrlParser |
2026-04-09T22:30:14.639Z | 2026-04-14T03:12:25.849Z | |
| cve-2026-35639 | 8.7 (v4.0) 8.8 (v3.1) | OpenClaw < 2026.3.22 - Privilege Escalation via device… |
OpenClaw |
OpenClaw |
2026-04-09T21:27:08.064Z | 2026-04-14T03:11:11.176Z |
| cve-2026-35633 | 6.9 (v4.0) 5.3 (v3.1) | OpenClaw < 2026.3.22 - Unbounded Memory Allocation via… |
OpenClaw |
OpenClaw |
2026-04-09T21:27:03.600Z | 2026-04-14T03:10:02.033Z |
| cve-2026-35626 | 6.9 (v4.0) 5.3 (v3.1) | OpenClaw < 2026.3.22 - Unauthenticated Resource Exhaus… |
OpenClaw |
OpenClaw |
2026-04-09T21:26:58.441Z | 2026-04-14T03:09:10.668Z |
| cve-2026-26221 | 9.3 (v4.0) 9.8 (v3.1) | Hyland OnBase Timer Services Unauthenticated .NET Remo… |
Hyland |
OnBase Workflow Timer Service |
2026-02-13T15:21:48.928Z | 2026-04-13T23:37:31.178Z |
| cve-2025-0921 | 6.5 (v3.1) | Information Tampering Vulnerability in Multiple Servic… |
Mitsubishi Electric Corporation |
GENESIS64 |
2025-05-15T22:36:37.902Z | 2026-04-13T23:06:00.161Z |
| cve-2024-1573 | 5.9 (v3.1) | Missing Authentication for Critical Function vuln… |
Mitsubishi Electric Iconics Digital Solutions |
GENESIS64 |
2024-07-04T08:59:44.079Z | 2026-04-13T22:47:17.575Z |
| cve-2020-9715 | N/A | Adobe Acrobat and Reader versions 2020.009.20074 … |
Adobe |
Adobe Acrobat and Reader |
2020-08-19T00:00:00.000Z | 2026-04-13T22:20:25.649Z |
| cve-2026-4519 | 7 (v4.0) | webbrowser.open() allows leading dashes in URLs |
Python Software Foundation |
CPython |
2026-03-20T15:08:32.576Z | 2026-04-13T21:47:40.137Z |
| cve-2025-30650 | 6.7 (v3.1) 8.4 (v4.0) | Junos OS: Privileged local user can gain access to a L… |
Juniper Networks |
Junos OS |
2026-04-08T17:26:35.685Z | 2026-04-13T21:17:19.185Z |
| cve-2026-33736 | Chamilo LMS has an Insecure Direct Object Reference (I… |
chamilo |
chamilo-lms |
2026-04-10T19:03:18.638Z | 2026-04-13T20:55:46.727Z | |
| cve-2026-40168 | Postiz has Server-Side Request Forgery via Redirect By… |
gitroomhq |
postiz-app |
2026-04-10T19:20:16.365Z | 2026-04-13T20:55:15.792Z | |
| cve-2026-40242 | Arcane Unauthenticated SSRF with Conditional Response … |
getarcaneapp |
arcane |
2026-04-10T20:34:12.777Z | 2026-04-13T20:54:36.822Z | |
| cve-2026-40180 | Zip Slip Path Traversal in quarkus-openapi-generator A… |
quarkiverse |
quarkus-openapi-generator |
2026-04-10T19:35:53.440Z | 2026-04-13T20:53:46.782Z | |
| cve-2026-40189 | goshs has a file-based ACL authorization bypass in gos… |
patrickhener |
goshs |
2026-04-10T19:44:54.672Z | 2026-04-13T20:53:02.400Z | |
| cve-2026-6123 | Tenda F451 httpd addressNat fromAddressNat stack-based… |
Tenda |
F451 |
2026-04-12T08:15:11.890Z | 2026-04-13T20:51:33.016Z |
| ID | Description | Updated |
|---|
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| jvndb-2010-000010 | HL-SiteManager vulnerable to SQL injection | 2010-04-02T17:33+09:00 | 2010-04-02T17:33+09:00 |
| jvndb-2010-000009 | Compiere vulnerable to cross-site scripting | 2010-04-02T17:32+09:00 | 2010-04-02T17:32+09:00 |
| jvndb-2010-000008 | Compiere vulnerable to cross-site scripting | 2010-04-02T17:32+09:00 | 2010-04-02T17:32+09:00 |
| jvndb-2010-000007 | PrettyFormMail vulnerable to cross-site scripting | 2010-04-02T17:31+09:00 | 2010-04-02T17:31+09:00 |
| jvndb-2009-000057 | ATOK screen lock bypass vulnerability | 2010-03-23T17:42+09:00 | 2010-03-23T17:42+09:00 |
| jvndb-2009-000018 | Ichitaro series buffer overflow vulnerability | 2010-03-23T17:42+09:00 | 2010-03-23T17:42+09:00 |
| jvndb-2010-001147 | JP1/Cm2/Network Node Manager Remote Console Insecure File Permissions Vulnerability | 2010-03-15T12:21+09:00 | 2010-03-15T12:21+09:00 |
| jvndb-2010-000006 | OpenPNE authentication bypass vulnerability | 2010-03-12T15:29+09:00 | 2010-03-12T15:29+09:00 |
| jvndb-2010-001088 | uCosminexus Portal Framework Cross-Site Scripting Vulnerability | 2010-03-03T12:00+09:00 | 2010-03-03T12:00+09:00 |
| jvndb-2010-000005 | tDiary plugin tb-send.rb vulnerable to cross-site scripting | 2010-02-26T12:45+09:00 | 2010-02-26T12:45+09:00 |
| jvndb-2009-002475 | Buffer Overflow Vulnerability in Cosminexus, Processing Kit for XML and Hitachi Developer's Kit for Java | 2010-02-09T14:03+09:00 | 2010-02-09T14:03+09:00 |
| jvndb-2009-000068 | Implementations of IPv6 may be vulnerable to denial of service (DoS) attacks | 2009-10-26T15:58+09:00 | 2010-01-25T12:02+09:00 |
| jvndb-2010-000004 | Oracle Application Server vulnerable to cross-site scripting | 2010-01-14T21:24+09:00 | 2010-01-14T21:24+09:00 |
| jvndb-2010-000003 | WebCalenderC3 vulnerable to directory traversal | 2010-01-14T21:24+09:00 | 2010-01-14T21:24+09:00 |
| jvndb-2010-000002 | WebCalenderC3 cross-site scripting vulnerability | 2010-01-14T21:23+09:00 | 2010-01-14T21:23+09:00 |
| jvndb-2010-000001 | Movable Type access restriction bypass vulnerability | 2010-01-06T16:26+09:00 | 2010-01-06T16:26+09:00 |
| jvndb-2008-000009 | Apache Tomcat fails to properly handle cookie value | 2008-05-21T00:00+09:00 | 2010-01-05T12:14+09:00 |
| jvndb-2009-002358 | Fujitsu Interstage and Systemwalker SSL Vulnerabilities | 2009-12-28T11:19+09:00 | 2009-12-28T11:19+09:00 |
| jvndb-2009-002345 | StartTLS not enabled in Hitachi Storage Command Suite products | 2009-12-24T14:32+09:00 | 2009-12-24T14:32+09:00 |
| jvndb-2009-000084 | P forum vulnerable to directory traversal | 2009-12-17T14:18+09:00 | 2009-12-17T14:18+09:00 |
| jvndb-2009-000077 | Active! mail 2003 cookie disclosure vulnerability | 2009-12-15T19:52+09:00 | 2009-12-15T19:52+09:00 |
| jvndb-2009-000076 | Active! mail 2003 session ID disclosure vulnerability | 2009-12-15T19:52+09:00 | 2009-12-15T19:52+09:00 |
| jvndb-2009-000075 | Active! mail 2003 cross-site scripting vulnerability | 2009-12-15T19:52+09:00 | 2009-12-15T19:52+09:00 |
| jvndb-2009-000079 | SEIL/B1 authentication issue | 2009-12-09T19:38+09:00 | 2009-12-09T19:38+09:00 |
| jvndb-2009-000078 | EC-CUBE information disclosure vulnerability | 2009-12-07T14:51+09:00 | 2009-12-07T14:51+09:00 |
| jvndb-2009-000074 | Redmine vulnerable to cross-site request forgery | 2009-11-19T15:45+09:00 | 2009-11-19T15:45+09:00 |
| jvndb-2009-000073 | Redmine vulnerable to cross-site scripting | 2009-11-19T15:45+09:00 | 2009-11-19T15:45+09:00 |
| jvndb-2007-001022 | Apache UTF-7 Encoding Cross-Site Scripting Vulnerability | 2008-05-21T00:00+09:00 | 2009-11-16T11:52+09:00 |
| jvndb-2009-000072 | Roundcube Webmail vulnerable to cross-site request forgery | 2009-11-04T15:27+09:00 | 2009-11-04T15:27+09:00 |
| jvndb-2009-000071 | Roundcube Webmail vulnerable to cross-site request forgery | 2009-11-04T15:27+09:00 | 2009-11-04T15:27+09:00 |
| ID | Description | Updated |
|---|
| ID | Description | Published | Updated |
|---|---|---|---|
| certfr-2024-avi-0022 | Multiples vulnérabilités dans Microsoft .Net | 2024-01-10T00:00:00.000000 | 2024-01-10T00:00:00.000000 |
| certfr-2024-avi-0021 | Multiples vulnérabilités dans Microsoft Windows | 2024-01-10T00:00:00.000000 | 2024-01-10T00:00:00.000000 |
| certfr-2024-avi-0020 | Vulnérabilité dans Microsoft Office | 2024-01-10T00:00:00.000000 | 2024-01-10T00:00:00.000000 |
| certfr-2024-avi-0019 | Multiples vulnérabilités dans les produits Fortinet | 2024-01-10T00:00:00.000000 | 2024-01-10T00:00:00.000000 |
| certfr-2024-avi-0018 | Multiples vulnérabilités dans les produits SAP | 2024-01-10T00:00:00.000000 | 2024-01-10T00:00:00.000000 |
| certfr-2024-avi-0017 | Multiples vulnérabilités dans les produits Intel | 2024-01-10T00:00:00.000000 | 2024-01-10T00:00:00.000000 |
| certfr-2024-avi-0016 | Multiples vulnérabilités dans les produits Trend Micro | 2024-01-10T00:00:00.000000 | 2024-01-10T00:00:00.000000 |
| certfr-2024-avi-0015 | Multiples vulnérabilités dans les produits Splunk | 2024-01-10T00:00:00.000000 | 2024-01-10T00:00:00.000000 |
| certfr-2024-avi-0014 | Multiples vulnérabilités dans les produits Siemens | 2024-01-09T00:00:00.000000 | 2024-01-09T00:00:00.000000 |
| certfr-2024-avi-0013 | Multiples vulnérabilités dans les produits Schneider Electric | 2024-01-09T00:00:00.000000 | 2024-01-09T00:00:00.000000 |
| certfr-2024-avi-0012 | Multiples vulnérabilités dans Microsoft Edge | 2024-01-08T00:00:00.000000 | 2024-01-08T00:00:00.000000 |
| certfr-2024-avi-0011 | Multiples vulnérabilités dans les produits Qnap | 2024-01-08T00:00:00.000000 | 2024-01-08T00:00:00.000000 |
| certfr-2024-avi-0010 | Multiples vulnérabilités dans les produits IBM | 2024-01-05T00:00:00.000000 | 2024-01-05T00:00:00.000000 |
| certfr-2024-avi-0009 | Multiples vulnérabilités dans Centreon Web | 2024-01-05T00:00:00.000000 | 2024-01-05T00:00:00.000000 |
| certfr-2024-avi-0008 | Vulnérabilité dans Ivanti Endpoint Manager | 2024-01-05T00:00:00.000000 | 2024-01-05T00:00:00.000000 |
| certfr-2024-avi-0007 | Multiples vulnérabilités dans Wireshark | 2024-01-05T00:00:00.000000 | 2024-01-05T00:00:00.000000 |
| certfr-2024-avi-0006 | Multiples vulnérabilités dans Google Android | 2024-01-04T00:00:00.000000 | 2024-01-04T00:00:00.000000 |
| certfr-2024-avi-0005 | Vulnérabilité dans Wireshark | 2024-01-04T00:00:00.000000 | 2024-01-04T00:00:00.000000 |
| certfr-2024-avi-0004 | Multiples vulnérabilités dans Google Chrome | 2024-01-04T00:00:00.000000 | 2024-01-04T00:00:00.000000 |
| certfr-2024-avi-0003 | Vulnérabilité dans Synology Router Manager | 2024-01-04T00:00:00.000000 | 2024-01-04T00:00:00.000000 |
| certfr-2024-avi-0001 | Vulnérabilité dans StormShield Network Security | 2024-01-02T00:00:00.000000 | 2024-01-03T00:00:00.000000 |
| certfr-2024-avi-0002 | Multiples vulnérabilités dans Moxa OnCell G3150A-LTE Series | 2024-01-02T00:00:00.000000 | 2024-01-02T00:00:00.000000 |
| certfr-2023-avi-1061 | Multiples vulnérabilités dans Apache OpenOffice | 2023-12-29T00:00:00.000000 | 2024-01-02T00:00:00.000000 |
| certfr-2023-avi-1062 | Multiples vulnérabilités dans Juniper Secure Analytics | 2023-12-29T00:00:00.000000 | 2023-12-29T00:00:00.000000 |
| certfr-2023-avi-1060 | Vulnérabilité dans NetApp Active IQ Unified Manager | 2023-12-28T00:00:00.000000 | 2023-12-28T00:00:00.000000 |
| certfr-2023-avi-1059 | Multiples vulnérabilités dans Moxa ioLogik E1200 | 2023-12-26T00:00:00.000000 | 2023-12-26T00:00:00.000000 |
| certfr-2023-avi-1058 | Vulnérabilité dans Stormshield Network Security | 2023-12-26T00:00:00.000000 | 2023-12-26T00:00:00.000000 |
| certfr-2023-avi-1057 | Vulnérabilité dans Postfix | 2023-12-22T00:00:00.000000 | 2023-12-26T00:00:00.000000 |
| certfr-2023-avi-1056 | Vulnérabilité dans Microsoft Edge | 2023-12-22T00:00:00.000000 | 2023-12-22T00:00:00.000000 |
| certfr-2023-avi-1055 | Multiples vulnérabilités dans les produits IBM | 2023-12-22T00:00:00.000000 | 2023-12-22T00:00:00.000000 |