Recent vulnerabilities


ID CVSS Description Vendor Product Published Updated
CVE-2026-27607
8.1 (3.1)
RustFS's Missing Post Policy Validation leads to Arbit… rustfs
rustfs
2026-02-25T02:10:28.086Z 2026-02-25T20:06:03.487Z
CVE-2026-27606
8.8 (4.0)
Rollup 4 has Arbitrary File Write via Path Traversal rollup
rollup
2026-02-25T02:08:06.682Z 2026-02-25T20:10:29.816Z
CVE-2026-25135
4.5 (3.1)
OpenEMR's location resource for Group.$export operatio… openemr
openemr
2026-02-25T02:02:14.203Z 2026-02-25T20:17:35.710Z
CVE-2026-3145
4.8 (4.0)
5.3 (3.1)
5.3 (3.0)
libvips matrixload.c vips_foreign_load_matrix_header m… n/a
libvips
2026-02-25T02:02:10.604Z 2026-02-25T20:28:56.023Z
CVE-2026-25131
8.8 (3.1)
OpenEMR has Broken Access Control in Procedures Config… openemr
openemr
2026-02-25T01:55:43.778Z 2026-02-25T20:34:41.500Z
CVE-2026-25127
7 (4.0)
OpenEMR has Broken Access Control on Care Coordination… openemr
openemr
2026-02-25T01:53:15.570Z 2026-02-25T20:44:14.545Z
CVE-2026-25124
6.5 (3.1)
OpenEMR has Broken Access Control in Report/Clients/Me… openemr
openemr
2026-02-25T01:50:22.146Z 2026-02-25T20:50:25.100Z
CVE-2026-24896
6.5 (3.1)
OpenEMR has Broken Access Control that allows unauthor… openemr
openemr
2026-02-25T01:47:59.765Z 2026-02-25T20:58:20.711Z
CVE-2026-24849
10 (3.1)
OpenEMR Arbitrary File Read Vulnerability openemr
openemr
2026-02-25T01:44:30.584Z 2026-02-25T21:05:01.567Z
CVE-2026-24847
6.1 (3.1)
OpenEMR has Open Redirect in Eye Exam Form openemr
openemr
2026-02-25T01:34:35.364Z 2026-02-25T21:08:26.424Z
CVE-2026-2914
8.5 (4.0)
CyberArk Endpoint Privilege Manager Agent version… CyberArk Software, a Palo Alto Networks Company
Endpoint Privilege Manager Agent
2026-02-25T01:33:05.657Z 2026-02-26T04:56:06.367Z
CVE-2026-21443
1.2 (4.0)
OpenEMR allows inconsistent escaping of translation fu… openemr
openemr
2026-02-25T01:23:22.052Z 2026-02-25T21:15:31.995Z
CVE-2025-69231
8.7 (3.1)
OpenEMR has a Stored XSS in GAD-7 Form that Enables Se… openemr
openemr
2026-02-25T01:18:14.722Z 2026-02-25T01:24:15.938Z
CVE-2025-68277
7.2 (4.0)
OpenEMR allows links sent via Secure Messaging to be o… openemr
openemr
2026-02-25T01:13:28.531Z 2026-02-25T01:25:11.772Z
CVE-2025-67752
8.1 (3.1)
OpenEMR Has Disabled SSL Certificate Verification in H… openemr
openemr
2026-02-25T01:09:20.946Z 2026-02-25T01:26:01.604Z
CVE-2026-3137
4.8 (4.0)
5.3 (3.1)
5.3 (3.0)
CodeAstro Food Ordering System food_ordering.exe stack… CodeAstro
Food Ordering System
2026-02-25T00:32:07.501Z 2026-02-25T00:32:07.501Z
CVE-2025-67491
8.5 (4.0)
OpenEMR has Stored XSS in ub04 helper openemr
openemr
2026-02-25T00:31:11.369Z 2026-02-25T01:27:17.978Z
CVE-2026-27598
7.1 (4.0)
Dagu: Path traversal in DAG creation allows arbitrary … dagu-org
dagu
2026-02-25T00:27:40.654Z 2026-02-25T00:27:40.654Z
CVE-2026-3135
6.9 (4.0)
7.3 (3.1)
7.3 (3.0)
itsourcecode News Portal Project add-category.php sql … itsourcecode
News Portal Project
2026-02-25T00:02:08.161Z 2026-02-25T00:02:08.161Z
CVE-2026-26717
N/A
An issue in OpenFUN Richie (LMS) in src/richie/ap… n/a
n/a
2026-02-25T00:00:00.000Z 2026-02-25T16:23:19.179Z
CVE-2025-69771
N/A
An arbitrary file upload vulnerability in the sub… n/a
n/a
2026-02-25T00:00:00.000Z 2026-02-25T15:28:56.880Z
CVE-2026-3134
6.9 (4.0)
7.3 (3.1)
7.3 (3.0)
itsourcecode News Portal Project edit-category.php sql… itsourcecode
News Portal Project
2026-02-24T23:32:11.537Z 2026-02-24T23:32:11.537Z
CVE-2026-3133
6.9 (4.0)
7.3 (3.1)
7.3 (3.0)
itsourcecode Document Management System Login loging.p… itsourcecode
Document Management System
2026-02-24T23:32:08.553Z 2026-02-24T23:32:08.553Z
CVE-2026-26351
4.8 (4.0)
GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php GetSimpleCMS-CE
GetSimpleCMS-CE
2026-02-24T22:05:54.420Z 2026-02-24T22:05:54.420Z
CVE-2026-27117
5.5 (3.1)
bit7z has a path traversal vulnerability rikyoz
bit7z
2026-02-24T21:46:12.714Z 2026-02-24T21:46:12.714Z
CVE-2026-27593
9.3 (3.1)
Statamic is vulnerable to account takeover via passwor… statamic
cms
2026-02-24T21:38:17.354Z 2026-02-24T21:38:17.354Z
CVE-2026-27572
6.9 (4.0)
Wasmtime can panic when adding excessive fields to a `… bytecodealliance
wasmtime
2026-02-24T21:31:50.186Z 2026-02-24T21:31:50.186Z
CVE-2026-27204
6.9 (4.0)
Wasmtime WASI implementations are vulnerable to guest-… bytecodealliance
wasmtime
2026-02-24T21:23:47.007Z 2026-02-24T21:23:47.007Z
CVE-2026-27195
6.9 (4.0)
Wasmtime is vulnerable to panic when dropping a `[Type… bytecodealliance
wasmtime
2026-02-24T21:15:20.366Z 2026-02-24T21:36:54.122Z
CVE-2026-25899
7.5 (3.1)
Fiber is Vulnerable to Denial of Service via Flash Coo… gofiber
fiber
2026-02-24T21:11:17.804Z 2026-02-24T21:37:33.970Z
ID CVSS Description Vendor Product Published Updated
ID Severity Description Published Updated
ghsa-gxcx-qjqp-8vjw
5.3 (3.1)
ImageMagick has memory leak in msl encoder 2026-02-24T15:30:54Z 2026-02-24T15:30:54Z
ghsa-xx53-6qqj-gr7w
9.8 (3.1)
Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence o… 2026-02-24T15:30:33Z 2026-02-25T15:31:37Z
ghsa-xqx8-2c6c-9g3g
4.9 (3.1)
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to… 2026-02-24T15:30:33Z 2026-02-24T18:31:02Z
ghsa-v5qr-j3c6-xxx2
7.5 (3.1)
TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cste… 2026-02-24T15:30:33Z 2026-02-25T18:31:35Z
ghsa-pr9m-7cjw-258w
4.9 (3.1)
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash… 2026-02-24T15:30:33Z 2026-02-24T18:31:02Z
ghsa-pq5g-x5q3-3g25
4.9 (3.1)
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management … 2026-02-24T15:30:33Z 2026-02-24T18:31:02Z
ghsa-mr6q-w873-6jfr
6.3 (3.1)
2.1 (4.0)
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function Se… 2026-02-24T15:30:33Z 2026-02-24T15:30:33Z
ghsa-6pf6-w4c2-rx3f
6.3 (3.1)
2.1 (4.0)
A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code o… 2026-02-24T15:30:33Z 2026-02-24T15:30:33Z
ghsa-58j5-qr69-3544
6.8 (3.1)
The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user aut… 2026-02-24T15:30:33Z 2026-02-24T15:30:33Z
ghsa-3q93-28v9-5x6v
4.9 (3.1)
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a fi… 2026-02-24T15:30:33Z 2026-02-24T18:31:02Z
ghsa-xchm-7954-5wvg
9.8 (3.1)
Use-after-free in the DOM: Window and Location component. This vulnerability affects Firefox < 148,… 2026-02-24T15:30:32Z 2026-02-25T15:31:37Z
ghsa-wcpx-2xqg-ff43
9.8 (3.1)
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability affects Firefox… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-vxjv-c6cq-74m6
9.8 (3.1)
Mitigation bypass in the Networking: Cache component. This vulnerability affects Firefox < 148 and … 2026-02-24T15:30:32Z 2026-02-25T15:31:37Z
ghsa-q6rm-rhj9-jpg5
9.8 (3.1)
Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148 and Fi… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-p9gc-q2gc-jc6r
4.2 (3.1)
Race condition in the JavaScript: GC component. This vulnerability affects Firefox < 148. 2026-02-24T15:30:32Z 2026-02-24T18:31:02Z
ghsa-p4fg-vw73-vr29
9.8 (3.1)
Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 148 and Fire… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-m8jj-q5xq-4qhp
7.5 (3.1)
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This v… 2026-02-24T15:30:32Z 2026-02-25T21:31:18Z
ghsa-jvc5-7j9r-q4m6
9.8 (3.1)
Same-origin policy bypass in the Networking: JAR component. This vulnerability affects Firefox < 14… 2026-02-24T15:30:32Z 2026-02-25T15:31:37Z
ghsa-hwjj-g6g7-p8cf
9.1 (3.1)
Uninitialized memory in the Graphics: Text component. This vulnerability affects Firefox < 148. 2026-02-24T15:30:32Z 2026-02-25T21:31:18Z
ghsa-hjq8-wc3q-9xf3
9.8 (3.1)
Privilege escalation in the Messaging System component. This vulnerability affects Firefox < 148, F… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-h79p-mfpr-8qm4
9.8 (3.1)
Use-after-free in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firef… 2026-02-24T15:30:32Z 2026-02-25T15:31:37Z
ghsa-h4vm-j32v-95qm
9.8 (3.1)
Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148. 2026-02-24T15:30:32Z 2026-02-25T21:31:18Z
ghsa-gvhp-5j8m-528x
9.8 (3.1)
Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148. 2026-02-24T15:30:32Z 2026-02-25T21:31:18Z
ghsa-gjwv-rvwj-p62j
9.8 (3.1)
Incorrect boundary conditions in the Web Audio component. This vulnerability affects Firefox < 148,… 2026-02-24T15:30:32Z 2026-02-25T18:31:34Z
ghsa-g9cv-cvhp-755f
9.8 (3.1)
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 148 and Fire… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-fvj5-5qvq-g8wf
8.8 (3.1)
Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148. 2026-02-24T15:30:32Z 2026-02-24T21:31:45Z
ghsa-cgrc-pwqf-64v8
9.8 (3.1)
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects Firefox… 2026-02-24T15:30:32Z 2026-02-25T15:31:37Z
ghsa-c5fj-xq9f-fjxm
9.8 (3.1)
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148 and Fir… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-c3q8-4689-m4p6
9.8 (3.1)
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148. 2026-02-24T15:30:32Z 2026-02-25T21:31:18Z
ghsa-94rx-4fcc-c849
9.8 (3.1)
Incorrect boundary conditions in the Networking: JAR component. This vulnerability affects Firefox … 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ID Severity Description Package Published Updated
pysec-2024-147
5.3 (3.1)
Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack m… vyper 2024-02-05T21:15:00+00:00 2024-11-21T14:23:02.864019+00:00
pysec-2024-38
7.5 (3.1)
FastAPI is a web framework for building APIs with Python 3.8+ based on standard Python ty… fastapi 2024-02-05T15:15:00+00:00 2024-02-16T18:22:32.607118+00:00
pysec-2024-148
5.3 (3.1)
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. When calls … vyper 2024-02-02T17:15:00+00:00 2024-11-21T14:23:02.917464+00:00
pysec-2024-35
5.4 (3.1)
Versions of the package dash-core-components before 2.13.0; all versions of the package d… dash 2024-02-02T05:15:00+00:00 2024-02-10T07:18:43.563257+00:00
pysec-2024-149
9.8 (3.1)
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions… vyper 2024-02-01T17:15:00+00:00 2024-11-21T14:23:02.970591+00:00
pysec-2024-29
4.9 (3.1)
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1… octoprint 2024-01-31T18:15:00+00:00 2024-02-08T07:19:40.535297+00:00
pysec-2024-127
5.3 (3.1)
Label Studio is a popular open source data labeling tool. The vulnerability affects all v… label-studio 2024-01-31T17:15:00+00:00 2024-11-21T14:22:53.294472+00:00
pysec-2024-151
5.3 (3.1)
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compi… vyper 2024-01-30T21:15:00+00:00 2024-11-21T14:23:03.091183+00:00
pysec-2024-34
9.8 (3.1)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like … vantage6-server 2024-01-30T16:15:00+00:00 2024-02-08T20:20:16.896186+00:00
pysec-2024-33
9.8 (3.1)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like … vantage6-node 2024-01-30T16:15:00+00:00 2024-02-08T20:20:16.842528+00:00
pysec-2024-32
4.3 (3.1)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like … vantage6 2024-01-30T16:15:00+00:00 2024-02-08T18:22:28.342089+00:00
pysec-2024-31
3.7 (3.1)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like … vantage6 2024-01-30T16:15:00+00:00 2024-02-08T18:22:28.276390+00:00
pysec-2024-30
8.8 (3.1)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like … vantage6 2024-01-30T16:15:00+00:00 2024-02-08T18:22:28.210087+00:00
pysec-2024-25
9.8 (3.1)
DuckDB <=0.9.2 and DuckDB extension-template <=0.9.2 are vulnerable to malicious extensio… duckdb 2024-01-30T01:16:00+00:00 2024-02-06T00:25:51.550516+00:00
pysec-2024-27
9.8 (3.1)
CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI componen… crate 2024-01-30T01:15:00Z 2025-01-30T22:47:57.847403Z
pysec-2024-26
6.5 (3.1)
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-… aiohttp 2024-01-29T23:15:00+00:00 2024-02-06T20:20:18.162431+00:00
pysec-2024-24
7.5 (3.1)
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When usin… aiohttp 2024-01-29T23:15:00+00:00 2024-02-05T20:20:47.716944+00:00
pysec-2024-21
8.8 (3.1)
A vulnerability classified as critical was found in van_der_Schaar LAB TemporAI 0.0.3. Af… temporai 2024-01-26T17:15:00+00:00 2024-02-01T18:22:23.971296+00:00
pysec-2024-14
Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated … apache-airflow 2024-01-24T13:15:00+00:00 2024-01-24T16:22:57.416385+00:00
pysec-2024-13
Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attac… apache-airflow 2024-01-24T13:15:00+00:00 2024-01-24T16:22:57.352530+00:00
pysec-2024-128
6.1 (3.1)
Label Studio, an open source data labeling tool had a remote import feature allowed users… label-studio 2024-01-24T00:15:00+00:00 2024-11-21T14:22:53.406222+00:00
pysec-2024-126
5.4 (3.1)
Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have… label-studio 2024-01-23T23:15:00+00:00 2024-11-21T14:22:53.235341+00:00
pysec-2024-23
5.3 (3.1)
Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limite… whoogle-search 2024-01-23T18:15:00+00:00 2024-02-02T07:18:33.382718+00:00
pysec-2024-22
6.1 (3.1)
TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese cha… tuitse-tsusin 2024-01-23T18:15:00+00:00 2024-02-01T22:21:01.486817+00:00
pysec-2024-20
9.8 (3.1)
Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `eleme… whoogle-search 2024-01-23T18:15:00+00:00 2024-01-30T18:22:32.803340+00:00
pysec-2024-19
6.1 (3.1)
Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `elem… whoogle-search 2024-01-23T18:15:00+00:00 2024-01-29T22:21:01.226431+00:00
pysec-2024-18
9.8 (3.1)
Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `wind… whoogle-search 2024-01-23T18:15:00+00:00 2024-01-29T22:21:01.170723+00:00
pysec-2024-16
5.4 (3.1)
Nautobot is a Network Source of Truth and Network Automation Platform built as a web appl… nautobot 2024-01-23T00:15:00+00:00 2024-01-29T20:20:58.065227+00:00
pysec-2024-9
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCod… metagpt 2024-01-22T01:15:00+00:00 2024-01-22T07:20:28.329958+00:00
pysec-2024-12
LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feat… llama-index 2024-01-22T01:15:00Z 2024-02-10T01:22:25.611009Z
ID Description Type
ID Description Updated
ID Description Published Updated
mal-2026-773 Malicious code in ethers-lint (npm) 2026-02-05T21:21:25Z 2026-02-06T03:05:23Z
mal-2026-771 Malicious code in test-npm-style (npm) 2026-02-05T19:06:12Z 2026-02-06T03:05:27Z
mal-2026-770 Malicious code in xpack-per-user (npm) 2026-02-05T18:36:26Z 2026-02-06T03:05:27Z
mal-2026-768 Malicious code in debug-logger-utils (npm) 2026-02-05T17:31:41Z 2026-02-06T03:05:23Z
mal-2026-767 Malicious code in 0xhash-utils (npm) 2026-02-05T17:29:50Z 2026-02-06T03:05:21Z
mal-2026-769 Malicious code in https-servers (npm) 2026-02-05T17:28:15Z 2026-02-06T03:05:24Z
mal-2026-766 Malicious code in greeter-pro-test (PyPI) 2026-02-05T16:40:51Z 2026-02-05T16:40:56Z
mal-2026-765 Malicious code in optimizer-cpu (npm) 2026-02-05T16:05:05Z 2026-02-06T03:05:25Z
mal-2026-764 Malicious code in chai-as-advanced (npm) 2026-02-05T14:54:55Z 2026-02-06T03:05:23Z
mal-2026-763 Malicious code in web3-meme-tool (PyPI) 2026-02-05T14:33:05Z 2026-02-05T14:33:05Z
mal-2026-762 Malicious code in metadata-checker (PyPI) 2026-02-05T14:30:34Z 2026-02-05T15:20:28Z
mal-2026-761 Malicious code in digital-checkout (npm) 2026-02-05T14:22:06Z 2026-02-06T03:05:23Z
mal-2026-760 Malicious code in @helloflex/widget-next-sdk (npm) 2026-02-05T12:44:37Z 2026-02-06T03:05:22Z
mal-2026-759 Malicious code in pipelinepoision-test (PyPI) 2026-02-05T08:43:35Z 2026-02-05T08:43:35Z
mal-2026-772 Malicious code in conp-dats-editor (npm) 2026-02-05T08:16:03Z 2026-02-06T03:05:23Z
mal-2026-757 Malicious code in internallib_v157 (npm) 2026-02-05T02:24:51Z 2026-02-06T03:05:24Z
mal-2026-758 Malicious code in tailwindcss-forms-starter (npm) 2026-02-05T02:03:44Z 2026-02-06T03:05:26Z
mal-2026-756 Malicious code in cat-retail-app (npm) 2026-02-05T01:58:59Z 2026-02-06T03:05:23Z
mal-2026-755 Malicious code in @jes4l/react-pkg (npm) 2026-02-05T01:57:08Z 2026-02-06T03:05:22Z
mal-2026-751 Malicious code in express_update (npm) 2026-02-05T01:50:12Z 2026-02-06T03:05:23Z
mal-2026-753 Malicious code in log-symbols_updated (npm) 2026-02-05T01:50:11Z 2026-02-06T03:05:25Z
mal-2026-752 Malicious code in locate-path_updated (npm) 2026-02-05T01:50:11Z 2026-02-06T03:05:25Z
mal-2026-749 Malicious code in @purecore/rabbitmq (npm) 2026-02-05T01:28:01Z 2026-02-06T03:05:22Z
mal-2026-750 Malicious code in dspmobile (npm) 2026-02-05T01:07:59Z 2026-02-06T03:05:23Z
mal-2026-754 Malicious code in tailwindcss-animation-modern (npm) 2026-02-05T01:06:23Z 2026-02-06T03:05:26Z
mal-2026-747 Malicious code in react-vite-sync (npm) 2026-02-04T23:44:25Z 2026-02-06T03:05:26Z
mal-2026-748 Malicious code in web3-chain-sync (npm) 2026-02-04T23:44:24Z 2026-02-06T03:05:27Z
mal-2026-746 Malicious code in react-count-sync (npm) 2026-02-04T23:44:24Z 2026-02-06T03:05:26Z
mal-2026-745 Malicious code in statssol (PyPI) 2026-02-04T19:47:20Z 2026-02-04T19:47:20Z
mal-2026-742 Malicious code in dcf-commons (npm) 2026-02-04T17:26:21Z 2026-02-06T03:05:23Z
ID Description Published Updated
bit-activemq-2021-21350 XStream is vulnerable to an Arbitrary Code Execution attack 2025-12-03T14:35:32.295Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21349 A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host 2025-12-03T14:35:30.789Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21348 XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos) 2025-12-03T14:35:29.299Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21347 XStream is vulnerable to an Arbitrary Code Execution attack 2025-12-03T14:35:27.664Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21346 XStream is vulnerable to an Arbitrary Code Execution attack 2025-12-03T14:35:26.027Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21345 XStream is vulnerable to a Remote Command Execution attack 2025-12-03T14:35:24.382Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21344 XStream is vulnerable to an Arbitrary Code Execution attack 2025-12-03T14:35:22.678Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21343 XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights 2025-12-03T14:35:21.073Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21342 A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host 2025-12-03T14:35:19.481Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21341 XStream can cause a Denial of Service 2025-12-03T14:35:17.881Z 2025-12-03T15:08:24.036Z
bit-activemq-2020-26217 Remote Code Execution in XStream 2025-12-03T14:35:16.352Z 2025-12-03T15:08:24.036Z
bit-activemq-2020-1941 2025-12-03T14:35:14.779Z 2025-12-03T15:08:24.036Z
bit-activemq-2020-13947 2025-12-03T14:35:13.393Z 2025-12-03T15:08:24.036Z
bit-activemq-2020-13920 2025-12-03T14:35:12.171Z 2025-12-03T15:08:24.036Z
bit-activemq-2020-11998 2025-12-03T14:35:10.504Z 2025-12-03T15:08:24.036Z
bit-flux-2022-39272 Flux2 vulnerable to Denial of Service due to Improper use of metav1.Duration 2025-12-02T17:37:01.043Z 2025-12-02T18:06:28.296Z
bit-flux-2022-36049 Flux2 Helm Controller denial of service 2025-12-02T17:36:59.799Z 2025-12-02T18:06:28.296Z
bit-flux-2022-36035 Flux CLI Workload Injection 2025-12-02T17:36:58.339Z 2025-12-02T18:06:28.296Z
bit-flux-2022-24878 Improper path handling in Kustomization files allows for denial of service 2025-12-02T17:36:56.954Z 2025-12-02T18:06:28.296Z
bit-flux-2022-24877 Improper path handling in kustomization files allows path traversal 2025-12-02T17:36:55.459Z 2025-12-02T18:06:28.296Z
bit-flux-2022-24817 Improper kubeconfig validation allows arbitrary code execution 2025-12-02T17:36:53.808Z 2025-12-02T18:06:28.296Z
bit-gitlab-2025-7449 Allocation of Resources Without Limits or Throttling in GitLab 2025-12-02T12:05:42.978Z 2025-12-11T12:06:55.559Z
bit-gitlab-2025-6195 Direct Request ('Forced Browsing') in GitLab 2025-12-02T12:05:25.518Z 2025-12-11T12:06:55.559Z
bit-gitlab-2025-13611 Insertion of Sensitive Information into Log File in GitLab 2025-12-02T12:03:48.649Z 2025-12-11T12:06:55.559Z
bit-gitlab-2025-12653 Authentication Bypass by Spoofing in GitLab 2025-12-02T12:03:41.060Z 2025-12-11T12:06:55.559Z
bit-gitlab-2025-12571 Allocation of Resources Without Limits or Throttling in GitLab 2025-12-02T12:03:39.208Z 2025-12-11T12:06:55.559Z
bit-cilium-2025-64715 Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic 2025-12-02T11:35:57.032Z 2025-12-06T12:06:23.267Z
bit-gitlab-2025-9825 Missing Authorization in GitLab 2025-11-25T18:25:02.547Z 2025-12-03T12:08:06.927Z
bit-drupal-2025-13083 Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 2025-11-25T17:56:46.824Z 2026-01-10T12:08:11.327Z
bit-drupal-2025-13082 Drupal core - Moderately critical - Defacement - SA-CORE-2025-007 2025-11-25T17:56:45.040Z 2025-11-25T18:26:29.568Z
ID Description Published Updated
drupal-contrib-2022-048 2022-07-13T15:44:42.000Z 2023-08-10T21:36:29.000Z
drupal-contrib-2022-047 2022-06-29T17:25:39.000Z 2023-08-10T21:35:49.000Z
drupal-contrib-2022-046 2022-06-29T16:51:17.000Z 2023-08-10T21:35:30.000Z
drupal-contrib-2022-045 2022-05-25T17:03:55.000Z 2023-08-10T21:35:00.000Z
drupal-contrib-2022-044 2022-05-25T16:53:45.000Z 2023-08-10T21:33:53.000Z
drupal-contrib-2022-043 2022-05-25T16:49:46.000Z 2023-08-10T21:32:49.000Z
drupal-contrib-2022-042 2022-05-25T16:45:17.000Z 2023-08-10T21:02:21.000Z
drupal-contrib-2022-040 2022-05-18T17:13:43.000Z 2023-08-10T21:05:48.000Z
drupal-contrib-2022-038 2022-05-04T16:26:47.000Z 2023-08-10T21:00:44.000Z
drupal-contrib-2022-036 2022-05-04T16:11:07.000Z 2023-08-10T21:43:53.000Z
drupal-contrib-2022-035 2022-05-04T16:06:53.000Z 2023-08-10T21:43:30.000Z
drupal-contrib-2022-032 2022-03-30T18:23:29.000Z 2023-08-10T21:41:21.000Z
drupal-contrib-2022-029 2022-03-09T18:57:52.000Z 2023-08-10T21:39:44.000Z
drupal-contrib-2022-028 2022-03-09T18:28:39.000Z 2023-08-10T21:39:01.000Z
drupal-contrib-2022-027 2022-02-23T17:18:07.000Z 2023-08-10T21:37:54.000Z
drupal-contrib-2022-026 2022-02-23T17:10:52.000Z 2023-08-11T13:50:17.000Z
drupal-contrib-2022-025 2022-02-16T17:07:35.000Z 2023-08-11T13:49:36.000Z
drupal-contrib-2022-024 2022-02-09T15:20:08.000Z 2023-08-11T13:49:13.000Z
drupal-contrib-2022-023 2022-02-09T15:17:56.000Z 2023-08-11T13:48:49.000Z
drupal-contrib-2022-014 2022-01-26T17:18:11.000Z 2023-08-11T13:48:18.000Z
drupal-contrib-2022-021 2022-01-25T18:41:04.000Z 2023-08-11T13:47:07.000Z
drupal-contrib-2022-019 2022-01-25T18:40:00.000Z 2023-10-24T16:11:02.000Z
drupal-contrib-2022-018 2022-01-25T18:39:50.000Z 2023-08-11T13:46:46.000Z
drupal-contrib-2022-017 2022-01-25T18:39:38.000Z 2023-08-11T13:56:08.000Z
drupal-contrib-2022-016 2022-01-25T18:39:26.000Z 2023-10-06T19:27:29.000Z
drupal-contrib-2022-015 2022-01-25T18:39:13.000Z 2023-08-11T14:02:31.000Z
drupal-contrib-2022-013 2022-01-25T18:37:38.000Z 2024-01-25T20:19:13.000Z
drupal-contrib-2022-012 2022-01-25T18:37:20.000Z 2023-08-11T13:55:41.000Z
drupal-contrib-2022-009 2022-01-25T18:36:37.000Z 2023-08-11T14:02:59.000Z
drupal-contrib-2022-008 2022-01-25T18:36:22.000Z 2023-08-11T14:01:01.000Z
ID Description Updated
ID Description Published Updated
jvndb-2024-003932 File Permissions Vulnerability in Hitachi Ops Center Common Services 2024-09-30T14:15+09:00 2024-09-30T14:15+09:00
jvndb-2024-000105 Multiple vulnerabilities in Smart-tab 2024-09-30T14:14+09:00 2024-09-30T14:14+09:00
jvndb-2024-009396 SNMP service is enabled by default in Sharp NEC Display Solutions projectors 2024-09-30T12:46+09:00 2024-09-30T12:46+09:00
jvndb-2024-000104 MF Teacher Performance Management System vulnerable to cross-site scripting 2024-09-27T15:00+09:00 2024-10-10T11:14+09:00
jvndb-2024-000103 The installer of e-Tax software(common program) vulnerable to privilege escalation 2024-09-24T16:12+09:00 2024-09-24T16:12+09:00
jvndb-2024-000102 Multiple NTT EAST Home GateWay/Hikari Denwa routers fail to restrict access permissions 2024-09-24T16:00+09:00 2024-10-18T11:02+09:00
jvndb-2024-000101 Multiple vulnerabilities in PLANEX COMMUNICATIONS network devices 2024-09-24T15:26+09:00 2024-09-24T15:26+09:00
jvndb-2024-008391 Multiple vulnerabilities in TAKENAKA ENGINEERING digital video recorders 2024-09-19T14:07+09:00 2024-09-19T14:07+09:00
jvndb-2024-000100 Multiple vulnerabilities in WordPress plugin "Welcart e-Commerce" 2024-09-18T14:34+09:00 2024-09-18T14:34+09:00
jvndb-2024-000099 Assimp vulnerable to heap-based buffer overflow 2024-09-18T14:20+09:00 2024-09-18T14:20+09:00
jvndb-2020-018328 Falsification and eavesdropping of contents across multiple websites via Web Rehosting services 2024-09-12T12:23+09:00 2024-09-12T12:23+09:00
jvndb-2023-027250 Security Problem in Web Browser Permission Mechanism 2024-09-11T18:19+09:00 2024-09-11T18:19+09:00
jvndb-2020-018327 Malleability attack against executables encrypted by CBC mode with no integrity check 2024-09-11T18:19+09:00 2024-09-11T18:19+09:00
jvndb-2024-000095 Multiple Alps System Integration products and the OEM products vulnerable to cross-site request forgery 2024-09-09T16:40+09:00 2024-09-09T16:40+09:00
jvndb-2024-000096 Pgpool-II vulnerable to information disclosure 2024-09-09T14:58+09:00 2024-09-09T14:58+09:00
jvndb-2024-000094 "@cosme" App fails to restrict custom URL schemes properly 2024-09-09T14:20+09:00 2024-09-09T14:20+09:00
jvndb-2024-000097 WordPress Plugin "Forminator" vulnerable to cross-site scripting 2024-09-09T13:51+09:00 2024-09-09T13:51+09:00
jvndb-2024-000098 Multiple products from KINGSOFT JAPAN vulnerable to path traversal 2024-09-06T15:07+09:00 2024-09-06T15:07+09:00
jvndb-2024-000090 Secure Boot bypass Vulnerability in PRIMERGY 2024-09-06T14:39+09:00 2024-09-06T14:39+09:00
jvndb-2024-000093 WordPress Plugin "Advanced Custom Fields" vulnerable to cross-site scripting 2024-09-04T13:01+09:00 2024-09-04T13:01+09:00
jvndb-2024-007002 Panasonic Control FPWIN Pro7 vulnerable to stack-based buffer overflow 2024-09-02T14:57+09:00 2024-09-02T14:57+09:00
jvndb-2024-000091 IPCOM vulnerable to information disclosure 2024-08-30T14:56+09:00 2024-08-30T14:56+09:00
jvndb-2024-000092 Multiple vulnerabilities in WordPress plugin "Carousel Slider" 2024-08-30T13:58+09:00 2024-08-30T13:58+09:00
jvndb-2024-000089 WindLDR and WindO/I-NV4 store sensitive information in cleartext 2024-08-29T15:08+09:00 2024-09-24T17:14+09:00
jvndb-2024-006787 xfpt vulnerable to stack-based buffer overflow 2024-08-29T14:07+09:00 2024-08-29T14:07+09:00
jvndb-2024-000088 Multiple vulnerabilities in ELECOM wireless LAN routers and access points 2024-08-27T14:40+09:00 2024-11-26T15:17+09:00
jvndb-2024-006646 Authentication Bypass Vulnerability in Hitachi Ops Center Common Services 2024-08-27T12:01+09:00 2024-08-27T12:01+09:00
jvndb-2024-006367 Unquoted Service Path in Hitachi Device Manager 2024-08-26T16:27+09:00 2024-08-26T16:27+09:00
jvndb-2024-000087 BUFFALO wireless LAN routers and wireless LAN repeaters vulnerable to OS command injection 2024-08-23T14:17+09:00 2024-08-23T14:17+09:00
jvndb-2024-000086 Multiple Safie products vulnerable to improper server certificate verification 2024-08-22T13:51+09:00 2024-08-29T12:23+09:00
ID Description Updated
ID Description
ID Description Published Updated
cnvd-2026-06107 Soda PDF Desktop代码执行漏洞 2026-01-09 2026-01-21
cnvd-2026-05016 UTT 520W formUser函数缓冲区溢出漏洞 2026-01-09 2026-01-13
cnvd-2026-05015 UTT 512W formConfigCliForEngineerOnly函数缓冲区溢出漏洞 2026-01-09 2026-01-13
cnvd-2026-05014 Tenda WH450 goform/PPTPUserSetting文件缓冲区溢出漏洞 2026-01-09 2026-01-14
cnvd-2026-04543 Tenda AC23缓冲区溢出漏洞 2026-01-09 2026-01-13
cnvd-2026-03262 Tenda WH450命令注入漏洞 2026-01-09 2026-01-09
cnvd-2026-03261 Echo Specto CM跨站脚本漏洞 2026-01-09 2026-01-13
cnvd-2026-03090 Tenda WH450 goform/PPTPServer文件缓冲区溢出漏洞 2026-01-09 2026-01-09
cnvd-2026-03089 Tenda WH450 goform/PPTPDClient文件缓冲区溢出漏洞 2026-01-09 2026-01-09
cnvd-2026-03088 Tenda WH450 goform/PPTPClient文件缓冲区溢出漏洞 2026-01-09 2026-01-09
cnvd-2026-03087 Tenda WH450 goform/Natlimit文件缓冲区溢出漏洞 2026-01-09 2026-01-09
cnvd-2026-03086 FluentCMS输入验证错误漏洞 2026-01-09 2026-01-09
cnvd-2026-02980 WordPress插件Shortcodes and extra features for Phlox theme信息泄露漏洞 2026-01-09 2026-01-13
cnvd-2026-02887 WordPress ilGhera Support System for WooCommerce plugin未经授权的数据修改漏洞 2026-01-09 2026-01-09
cnvd-2026-02886 WordPress Geo Controller plugin跨站脚本漏洞 2026-01-09 2026-01-09
cnvd-2026-02885 WordPress FS Registration Password plugin权限提升漏洞 2026-01-09 2026-01-09
cnvd-2026-02884 WordPress FlexTable plugin跨站脚本漏洞 2026-01-09 2026-01-09
cnvd-2026-02883 WordPress FastDup plugin路径遍历漏洞 2026-01-09 2026-01-09
cnvd-2026-02882 WordPress Car Rental Manager plugin缺少授权漏洞 2026-01-09 2026-01-09
cnvd-2026-02881 WordPress Calafate plugin文件包含漏洞 2026-01-09 2026-01-09
cnvd-2026-02880 WordPress Better Business Reviews plugin缺少授权漏洞 2026-01-09 2026-01-09
cnvd-2026-02879 WordPress AffiliateX plugin缺少授权漏洞 2026-01-09 2026-01-09
cnvd-2026-02878 WordPress Accordion plugin跨站脚本漏洞 2026-01-09 2026-01-09
cnvd-2026-04470 北京神州视翰科技有限公司远程医疗综合服务平台存在SQL注入漏洞(CNVD-C-2026-35542) 2026-01-08 2026-01-21
cnvd-2026-04457 北京神州视翰科技有限公司多媒体综合业务显示系统存在SQL注入漏洞(CNVD-C-2026-33516) 2026-01-07 2026-01-21
cnvd-2026-06098 Tenda M3 /goform/exeCommand文件堆栈缓冲区溢出漏洞 2026-01-06 2026-01-21
cnvd-2026-06097 Tenda M3 /goform/setAdPushInfo文件堆栈缓冲区溢出漏洞 2026-01-06 2026-01-21
cnvd-2026-06096 Tenda M3 /goform/setAdInfoDetail文件堆缓冲区溢出漏洞 2026-01-06 2026-01-21
cnvd-2026-06095 Tenda M3 /goform/setVlanInfo文件堆栈缓冲区溢出漏洞 2026-01-06 2026-01-21
cnvd-2026-02877 Online Music Site AlbumByCategory.php文件SQL注入漏洞 2026-01-06 2026-01-12
ID Description Published Updated
bdu:2026-01424 Уязвимость DNS-сервера Dnsmasq, связанная с ошибками реализации проверки безопасности для… 09.02.2026 09.02.2026
bdu:2026-01423 Уязвимость функции hci_conn_del() модуля net/bluetooth/hci_conn.c подсистемы Bluetooth яд… 09.02.2026 09.02.2026
bdu:2026-01422 Уязвимость функции DestroyImage компонента MagickCore/image.c консольного графического ре… 09.02.2026 09.02.2026
bdu:2026-01421 Уязвимость функции ReadMVGImage компонента coders/mvg.c консольного графического редактор… 09.02.2026 09.02.2026
bdu:2026-01420 Уязвимость функции WriteMPCImage() компонента coders/mpc.c консольного графического редак… 09.02.2026 09.02.2026
bdu:2026-01419 Уязвимость функции lite_font_map() компонента coders/wmf.c консольного графического редак… 09.02.2026 09.02.2026
bdu:2026-01418 Уязвимость функции mpi3mr_process_cfg_req() модуля drivers/scsi/mpi3mr/mpi3mr_fw.c драйве… 08.02.2026 08.02.2026
bdu:2026-01417 Уязвимость функции usb_shark_probe() модуля drivers/media/radio/radio-shark.c драйвера му… 08.02.2026 08.02.2026
bdu:2026-01416 Уязвимость функции imx_pcie_suspend_noirq() модуля drivers/pci/controller/dwc/pci-imx6.c … 08.02.2026 08.02.2026
bdu:2026-01415 Уязвимость функции virtnet_rq_alloc() модуля drivers/net/virtio_net.c драйвера поддержки … 08.02.2026 08.02.2026
bdu:2026-01414 Уязвимость функции disk_destroy_zone_wplugs_hash_table() модуля block/blk-zoned.c поддерж… 08.02.2026 08.02.2026
bdu:2026-01413 Уязвимость функции can_nocow_file_extent() модуля fs/btrfs/inode.c поддержки файловой сис… 08.02.2026 10.02.2026
bdu:2026-01412 Уязвимость функции ksmbd_conn_init_server_callbacks() модуля fs/smb/server/connection.c п… 08.02.2026 08.02.2026
bdu:2026-01411 Уязвимость функции cow_file_range() модуля fs/btrfs/inode.c поддержки файловой системы bt… 08.02.2026 08.02.2026
bdu:2026-01410 Уязвимость функции sdw_hda_dai_hw_params() модуля sound/soc/sof/intel/hda-dai.c поддержки… 08.02.2026 08.02.2026
bdu:2026-01409 Уязвимость функции lookup_inline_extent_backref() модуля fs/btrfs/extent-tree.c файловой … 08.02.2026 08.02.2026
bdu:2026-01408 Уязвимость функции nfsd_net_init() модуля fs/nfsd/nfsctl.c поддержки сетевой файловой сис… 08.02.2026 08.02.2026
bdu:2026-01407 Уязвимость функции vimc_streamer_pipeline_terminate() модуля drivers/media/test-drivers/v… 08.02.2026 08.02.2026
bdu:2026-01406 Уязвимость функции parse_durable_handle_context() модуля fs/smb/server/smb2pdu.c поддержк… 08.02.2026 08.02.2026
bdu:2026-01405 Уязвимость функции veth_pool_store() модуля drivers/net/ethernet/ibm/ibmveth.c драйвера п… 08.02.2026 08.02.2026
bdu:2026-01404 Уязвимость функции v9fs_vfs_mkdir_dotl() модуля fs/9p/vfs_inode_dotl.c файловой системы я… 08.02.2026 08.02.2026
bdu:2026-01403 Уязвимость функции get_pat_info() модуля arch/x86/mm/pat/memtype.c платформы x86 ядра опе… 08.02.2026 08.02.2026
bdu:2026-01402 Уязвимость функции old_deviceless() модуля net/bridge/br_ioctl.c реализации сетевых функц… 08.02.2026 08.02.2026
bdu:2026-01401 Уязвимость функции ath12k_dp_mon_rx_parse_status_tlv() модуля drivers/net/wireless/ath/at… 08.02.2026 08.02.2026
bdu:2026-01400 Уязвимость функции hibernate_compressor_param_set() модуля kernel/power/hibernate.c ядра … 08.02.2026 08.02.2026
bdu:2026-01399 Уязвимость функции dwc_pcie_register_dev() модуля drivers/perf/dwc_pcie_pmu.c драйвера по… 08.02.2026 08.02.2026
bdu:2026-01398 Уязвимость функции xgene_hwmon_probe() модуля drivers/hwmon/xgene-hwmon.c драйвера монито… 08.02.2026 08.02.2026
bdu:2026-01397 Уязвимость функции gfs2_dinode_in() модуля fs/gfs2/dir.c файловой системы GFS2 ядра опера… 08.02.2026 08.02.2026
bdu:2026-01396 Уязвимость функций hfs_find_init() (fs/hfs/bfind.c) и hfs_btree_open() (fs/hfs/btree.c) ф… 08.02.2026 08.02.2026
bdu:2026-01395 Уязвимость функции tpm2_init_space() модуля drivers/char/tpm/tpm2-space.c драйвера поддер… 08.02.2026 08.02.2026
ID Description Published Updated
certfr-2025-avi-1082 Multiples vulnérabilités dans les produits Microsoft 2025-12-09T00:00:00.000000 2025-12-09T00:00:00.000000
certfr-2025-avi-1081 Vulnérabilité dans Citrix XenServer 2025-12-09T00:00:00.000000 2025-12-09T00:00:00.000000
certfr-2025-avi-1080 Multiples vulnérabilités dans VMware Tanzu RabbitMQ 2025-12-09T00:00:00.000000 2025-12-09T00:00:00.000000
certfr-2025-avi-1079 Multiples vulnérabilités dans les produits SAP 2025-12-09T00:00:00.000000 2025-12-09T00:00:00.000000
certfr-2025-avi-1078 Multiples vulnérabilités dans les produits Microsoft 2025-12-08T00:00:00.000000 2025-12-08T00:00:00.000000
certfr-2025-avi-1077 Multiples vulnérabilités dans Traefik 2025-12-08T00:00:00.000000 2025-12-08T00:00:00.000000
certfr-2025-avi-1076 Multiples vulnérabilités dans MISP 2025-12-08T00:00:00.000000 2025-12-24T00:00:00.000000
certfr-2025-avi-1075 Multiples vulnérabilités dans le noyau Linux d'Ubuntu 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1074 Multiples vulnérabilités dans le noyau Linux de Red Hat 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1073 Multiples vulnérabilités dans le noyau Linux de SUSE 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1072 Multiples vulnérabilités dans les produits IBM 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1071 Multiples vulnérabilités dans Apache HTTP Server 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1070 Multiples vulnérabilités dans Microsoft CBL Mariner 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1069 Multiples vulnérabilités dans Microsoft Edge 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1068 Vulnérabilité dans Python 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1067 Vulnérabilité dans Apache Struts 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1066 Multiples vulnérabilités dans les produits Nextcloud 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1065 Multiples vulnérabilités dans NetApp ONTAP 2025-12-05T00:00:00.000000 2025-12-05T00:00:00.000000
certfr-2025-avi-1064 Multiples vulnérabilités dans les produits Microsoft 2025-12-04T00:00:00.000000 2025-12-04T00:00:00.000000
certfr-2025-avi-1063 Multiples vulnérabilités dans les produits Splunk 2025-12-04T00:00:00.000000 2025-12-04T00:00:00.000000
certfr-2025-avi-1062 Multiples vulnérabilités dans Wireshark 2025-12-04T00:00:00.000000 2025-12-04T00:00:00.000000
certfr-2025-avi-1061 Vulnérabilité dans PostgreSQL PgBouncer 2025-12-04T00:00:00.000000 2025-12-04T00:00:00.000000
certfr-2025-avi-1060 Multiples vulnérabilités dans Python 2025-12-03T00:00:00.000000 2025-12-03T00:00:00.000000
certfr-2025-avi-1059 Multiples vulnérabilités dans Google Pixel 2025-12-03T00:00:00.000000 2025-12-03T00:00:00.000000
certfr-2025-avi-1058 Multiples vulnérabilités dans Google Chrome 2025-12-03T00:00:00.000000 2025-12-03T00:00:00.000000
certfr-2025-avi-1057 Multiples vulnérabilités dans les produits VMware 2025-12-02T00:00:00.000000 2025-12-02T00:00:00.000000
certfr-2025-avi-1056 Multiples vulnérabilités dans Google Android 2025-12-02T00:00:00.000000 2025-12-02T00:00:00.000000
certfr-2025-avi-1055 Multiples vulnérabilités dans Zabbix 2025-12-01T00:00:00.000000 2025-12-01T00:00:00.000000
certfr-2025-avi-1054 Multiples vulnérabilités dans les produits VMware 2025-12-01T00:00:00.000000 2025-12-01T00:00:00.000000
certfr-2025-avi-1053 Vulnérabilité dans Stormshield Network VPN Client 2025-12-01T00:00:00.000000 2025-12-01T00:00:00.000000
ID Description Published Updated
certa-2008-ale-008 Vulnérabilité du navigateur Safari 2008-06-02T00:00:00.000000 2008-06-20T00:00:00.000000
certa-2008-ale-007 Multiples vulnérabilités dans Apple iCal 2008-05-23T00:00:00.000000 2008-05-29T00:00:00.000000
certa-2008-ale-006 Vulnérabilités dans HP OpenView NNM 2008-04-18T00:00:00.000000 2010-06-10T00:00:00.000000
certa-2008-ale-005 Vulnérabilité dans Microsoft Jet Database Engine 2008-03-25T00:00:00.000000 2008-05-14T00:00:00.000000
certa-2008-ale-004 Vulnérabilité dans VMware 2008-02-27T00:00:00.000000 2008-04-16T00:00:00.000000
certa-2008-ale-003 Vulnérabilité dans Excel 2008-01-16T00:00:00.000000 2008-03-12T00:00:00.000000
certa-2008-ale-002 Vulnérabilité dans Joomla! 2008-01-14T00:00:00.000000 2008-02-25T00:00:00.000000
certa-2008-ale-001 Vulnérabilité dans Apple QuickTime 2008-01-11T00:00:00.000000 2008-02-07T00:00:00.000000
certa-2007-ale-017 Vulnérabilité dans la gestion RTSP d'Apple QuickTime 2007-11-27T00:00:00.000000 2007-12-14T00:00:00.000000
certa-2007-ale-016 Vulnérabilité d'Oracle 10g 2007-11-16T00:00:00.000000 2007-11-16T00:00:00.000000
certa-2007-ale-015 Vulnérabilité dans le traitement des URI sous Windows 2007-10-10T00:00:00.000000 2007-11-14T00:00:00.000000
certa-2007-ale-014 Vulnérabilité dans Apple QuickTime 2007-09-13T00:00:00.000000 2007-10-12T00:00:00.000000
certa-2007-ale-013 Vulnérabilité dans Mozilla Firefox 2007-07-27T00:00:00.000000 2007-07-31T00:00:00.000000
certa-2007-ale-012 Multiples vulnérabilités dans Mozilla Firefox 2007-06-06T00:00:00.000000 2007-07-18T00:00:00.000000
certa-2007-ale-011 Vulnérabilité du composant d'indexation des serveurs Microsoft IIS 2007-06-06T00:00:00.000000 2013-02-19T00:00:00.000000
certa-2007-ale-010 Vulnérabilité de Microsoft DNS Server 2007-04-16T00:00:00.000000 2007-05-09T00:00:00.000000
certa-2007-ale-009 Vulnérabilité dans BrightStor ARCServe Backup 2007-03-30T00:00:00.000000 2007-04-27T00:00:00.000000
certa-2007-ale-008 Vulnérabilité dans Mirosoft Windows 2007-03-29T00:00:00.000000 2007-04-03T00:00:00.000000
certa-2007-ale-007 Vulnérabilité de Microsoft Windows Explorer 2007-03-09T00:00:00.000000 2008-10-09T00:00:00.000000
certa-2007-ale-006 Vulnérabilité dans le logiciel Microsoft Word 2007-02-16T00:00:00.000000 2007-05-09T00:00:00.000000
certa-2007-ale-005 Vulnérabilité de Sun Solaris 2007-02-12T00:00:00.000000 2008-09-18T00:00:00.000000
certa-2007-ale-004 Vulnérabilité dans Microsoft Office 2007-02-03T00:00:00.000000 2007-02-13T00:00:00.000000
certa-2007-ale-003 Filoutage contre le site voyages-sncf.com 2007-01-15T00:00:00.000000 2007-01-15T00:00:00.000000
certa-2007-ale-002 Vulnérabilité dans Windows 2007-01-12T00:00:00.000000 2007-04-03T00:00:00.000000
certa-2007-ale-001 Vulnérablité dans Apple Quicktime 2007-01-04T00:00:00.000000 2007-01-24T00:00:00.000000
certa-2006-ale-014 Vulnérabilités dans Microsoft Word 2006-12-06T00:00:00.000000 2007-02-14T00:00:00.000000
certa-2006-ale-013 Vulnérabilité de MacOS X 2006-11-23T00:00:00.000000 2007-02-16T00:00:00.000000
certa-2006-ale-012 Vulnérabilité de Microsoft PowerPoint 2006-10-13T00:00:00.000000 2008-10-09T00:00:00.000000
certa-2006-ale-011 Multiples vulnérabilités de produits Microsoft 2006-08-31T00:00:00.000000 2006-10-11T00:00:00.000000
certa-2006-ale-010 Vulnérabilité dans Internet Explorer 2006-08-23T00:00:00.000000 2006-08-25T00:00:00.000000
ID Description Published Updated
osv-2024-1417 Heap-buffer-overflow in cv::PngDecoder::read_from_io 2025-01-02T00:15:00.246767Z 2025-01-02T00:15:00.247102Z
osv-2024-1411 Use-of-uninitialized-value in mark_context 2024-12-29T00:03:28.881713Z 2024-12-29T00:03:28.882100Z
osv-2024-1406 UNKNOWN READ in _TIFFVSetField 2024-12-27T00:16:38.077175Z 2024-12-27T00:16:38.077756Z
osv-2024-1391 Heap-buffer-overflow in gsicc_create_getv2buffer 2024-12-20T00:03:10.307442Z 2024-12-20T00:03:10.308031Z
osv-2024-1388 Security exception in com.google.gson.internal.bind.TypeAdapters$28.write 2024-12-18T00:02:54.357847Z 2024-12-18T00:02:54.358393Z
osv-2024-1380 Index-out-of-bounds in ndpi_search_dns 2024-12-15T00:12:21.687565Z 2024-12-15T00:12:21.687988Z
osv-2024-1375 Index-out-of-bounds in dwg_decode_eed 2024-12-15T00:01:20.442440Z 2025-05-03T14:23:13.369570Z
osv-2024-1372 Bad-cast to Assimp::LogStream from Assimp::OptimizeMeshesProcess 2024-12-14T00:00:14.982156Z 2024-12-14T00:00:14.982614Z
osv-2024-1356 Heap-buffer-overflow in ChunkAssignData 2024-12-10T00:13:56.481718Z 2024-12-10T00:13:56.482170Z
osv-2024-1355 UNKNOWN READ in glslang::TInfoSinkBase::location 2024-12-10T00:08:00.540533Z 2025-12-23T15:50:47.917708Z
osv-2024-1351 Use-of-uninitialized-value in Archive::UnexpEndArcMsg 2024-12-10T00:05:42.992615Z 2024-12-10T00:05:42.992960Z
osv-2024-1348 Heap-buffer-overflow in glslang::HlslGrammar::acceptDeclaration 2024-12-10T00:00:50.788Z 2025-12-23T15:50:48.626100Z
osv-2024-1346 UNKNOWN READ in glslang::HlslTokenStream::advanceToken 2024-12-10T00:00:20.380006Z 2025-12-23T15:50:47.126469Z
osv-2024-1343 Container-overflow in glslang::HlslParseContext::decomposeIntrinsic 2024-11-27T00:13:21.103465Z 2025-12-23T15:50:45.708425Z
osv-2024-1336 Security exception in org.checkerframework.checker.formatter.util.FormatUtil.formatParameterCategories 2024-11-26T00:01:25.736998Z 2024-11-26T00:01:25.737632Z
osv-2024-1332 Negative-size-param in extract_mr_data 2024-11-21T00:04:16.535838Z 2024-11-21T00:04:16.536469Z
osv-2024-1330 Heap-buffer-overflow in zoom_search_again 2024-11-20T00:15:27.562125Z 2024-11-20T14:27:37.875526Z
osv-2024-1326 Heap-buffer-overflow in ndpi_search_mikrotik 2024-11-18T00:12:17.790747Z 2024-11-18T00:12:17.791146Z
osv-2024-1324 Heap-buffer-overflow in Assimp::FBXExporter::WriteObjects 2024-11-18T00:01:13.979270Z 2024-11-18T00:01:13.979758Z
osv-2024-1322 Security exception in com.alibaba.fastjson2.JSONReader.readObject 2024-11-18T00:00:16.618504Z 2025-03-18T00:24:17.881614Z
osv-2024-1320 Heap-buffer-overflow in process_page_ 2024-11-17T00:15:09.627790Z 2024-11-17T00:15:09.628193Z
osv-2024-1312 Heap-buffer-overflow in jv_string_vfmt 2024-11-15T00:16:08.928897Z 2025-03-05T14:20:12.622041Z
osv-2024-1310 Use-of-uninitialized-value in decompress_yuv.cc 2024-11-15T00:03:32.569897Z 2024-11-15T00:03:32.570195Z
osv-2024-1297 Heap-buffer-overflow in rijndaelSetupEncrypt 2024-11-09T00:13:03.370689Z 2024-11-09T00:13:03.371200Z
osv-2024-1293 Use-of-uninitialized-value in k5_hashtab_add 2024-11-08T00:16:09.025852Z 2024-11-08T00:16:09.026399Z
osv-2024-1282 Segv on unknown address in udiv 2024-11-05T00:16:47.572692Z 2024-11-05T00:16:47.573042Z
osv-2024-1279 Heap-buffer-overflow in opj_j2k_read_tile_header 2024-11-05T00:12:57.052133Z 2024-11-05T00:12:57.052585Z
osv-2024-1274 Segv on unknown address in yara_yyparse 2024-11-05T00:04:03.220856Z 2025-06-03T14:42:15.782999Z
osv-2024-1272 Segv on unknown address in std::__1::ios_base::~ios_base 2024-11-05T00:03:30.787980Z 2025-04-17T14:38:30.981292Z
osv-2022-1288 Stack-buffer-overflow in bool SmilesParseOps::parser::parse_atom_props<std::__1::__wrap_iter<char const*> 2024-11-04T00:16:22.516312Z 2026-01-30T14:23:19.786593Z
ID Description Published Updated
rustsec-2024-0342 Degraded secret zeroization capabilities 2024-05-02T12:00:00Z 2024-05-20T15:25:56Z
rustsec-2024-0338 Arithmetic overflows in cosmwasm-std 2024-04-24T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0337 The crate `zip_next` has been renamed to `zip`. 2024-04-20T12:00:00Z 2024-04-24T14:13:51Z
rustsec-2024-0336 `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input 2024-04-19T12:00:00Z 2024-04-20T02:21:14Z
rustsec-2024-0335 gix-transport indirect code execution via malicious username 2024-04-13T12:00:00Z 2024-07-02T23:39:37Z
rustsec-2024-0333 `rsa-export` is unmaintained 2024-04-06T12:00:00Z 2024-04-12T16:29:46Z
rustsec-2024-0334 `libp2p-tokio-socks5` is unmaintained 2024-04-05T12:00:00Z 2024-04-12T16:31:39Z
rustsec-2024-0332 Degradation of service in h2 servers with CONTINUATION Flood 2024-04-03T12:00:00Z 2024-04-11T16:16:20Z
rustsec-2024-0441 Panic when using a dropped extenref-typed element segment 2024-04-02T12:00:00Z 2025-05-02T08:23:27Z
rustsec-2024-0331 Puccinier is unmainted. 2024-03-31T12:00:00Z 2024-03-31T14:44:37Z
rustsec-2024-0429 Unsoundness in `Iterator` and `DoubleEndedIterator` impls for `glib::VariantStrIter` 2024-03-30T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0320 yaml-rust is unmaintained. 2024-03-20T12:00:00Z 2024-11-01T12:31:51Z
rustsec-2024-0341 Slow loris vulnerability with default configuration 2024-03-15T12:00:00Z 2024-05-21T02:12:32Z
rustsec-2024-0407 Fails to ensure slice elements match the slice's declared type 2024-03-05T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0021 Parts of Report are dropped as the wrong type during downcast 2024-03-05T12:00:00Z 2024-04-11T16:16:20Z
rustsec-2024-0420 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0419 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0418 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0417 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0416 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0415 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0414 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0413 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0412 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0411 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0410 gtk-rs GTK3 bindings - no longer maintained 2024-03-04T12:00:00Z 2024-12-09T12:29:00Z
rustsec-2024-0019 Tokens for named pipes may be delivered after deregistration 2024-03-04T12:00:00Z 2024-03-04T17:51:31Z
rustsec-2024-0020 Stack buffer overflow with whoami on several Unix platforms 2024-02-28T12:00:00Z 2024-04-11T16:16:20Z
rustsec-2024-0017 Non-idiomatic use of iterators leads to use after free 2024-02-28T12:00:00Z 2024-04-11T16:16:20Z
rustsec-2024-0018 ObjectPool creates uninitialized memory when freeing objects 2024-02-27T12:00:00Z 2024-04-11T16:16:20Z
ID Description Published Updated
alsa-2025:22005 Moderate: go-rpm-macros security update 2025-11-25T00:00:00Z 2025-11-25T10:51:18Z
alsa-2025:21977 Moderate: libssh security update 2025-11-24T00:00:00Z 2025-11-25T12:04:18Z
alsa-2025:21974 Important: mingw-expat security update 2025-11-24T00:00:00Z 2025-12-01T07:55:50Z
alsa-2025:21968 Important: gimp security update 2025-11-24T00:00:00Z 2025-12-01T07:58:09Z
alsa-2025:21936 Important: valkey security update 2025-11-24T00:00:00Z 2025-12-05T08:20:47Z
alsa-2025:21931 Moderate: kernel security update 2025-11-24T00:00:00Z 2025-12-05T08:40:44Z
alsa-2025:21926 Moderate: kernel security update 2025-11-24T00:00:00Z 2025-12-01T08:01:07Z
alsa-2025:21920 Moderate: kernel-rt security update 2025-11-24T00:00:00Z 2025-11-25T09:25:12Z
alsa-2025:21917 Moderate: kernel security update 2025-11-24T00:00:00Z 2025-11-25T09:27:51Z
alsa-2025:21916 Important: valkey security update 2025-11-24T00:00:00Z 2025-12-01T08:02:48Z
alsa-2025:21881 Important: thunderbird security update 2025-11-20T00:00:00Z 2025-11-25T09:29:54Z
alsa-2025:21843 Important: thunderbird security update 2025-11-20T00:00:00Z 2025-11-24T10:41:50Z
alsa-2025:21816 Moderate: delve and golang security update 2025-11-20T00:00:00Z 2025-11-24T12:49:17Z
alsa-2025:21815 Moderate: delve and golang security update 2025-11-20T00:00:00Z 2025-11-20T10:59:53Z
alsa-2025:21776 Important: expat security update 2025-11-19T00:00:00Z 2025-11-20T09:03:52Z
alsa-2025:21702 Important: podman security update 2025-11-18T00:00:00Z 2025-11-19T10:51:29Z
alsa-2025:21693 Important: haproxy security update 2025-11-18T00:00:00Z 2025-11-19T10:52:41Z
alsa-2025:21691 Important: haproxy security update 2025-11-18T00:00:00Z 2025-11-24T12:50:19Z
alsa-2025:21628 Critical: lasso security update 2025-11-17T00:00:00Z 2025-11-19T10:11:06Z
alsa-2025:21462 Critical: lasso security update 2025-11-17T00:00:00Z 2025-11-19T09:40:25Z
alsa-2025:21398 Moderate: kernel security update 2025-11-17T00:00:00Z 2025-11-19T14:49:27Z
alsa-2025:21397 Moderate: kernel-rt security update 2025-11-17T00:00:00Z 2025-11-19T14:52:45Z
alsa-2025:21281 Important: firefox security update 2025-11-13T00:00:00Z 2025-11-25T09:59:17Z
alsa-2025:21280 Important: firefox security update 2025-11-13T00:00:00Z 2025-11-24T12:36:14Z
alsa-2025:21255 Moderate: openssl security update 2025-11-13T00:00:00Z 2025-12-01T08:04:03Z
alsa-2025:21248 Moderate: openssl security update 2025-11-13T00:00:00Z 2025-11-25T09:31:36Z
alsa-2025:21232 Important: container-tools:rhel8 security update 2025-11-13T00:00:00Z 2025-11-20T10:07:52Z
alsa-2025:21220 Important: podman security update 2025-11-13T00:00:00Z 2025-11-25T10:45:01Z
alsa-2025:21142 Important: python-kdcproxy security update 2025-11-12T00:00:00Z 2025-11-24T12:51:27Z
alsa-2025:21140 Important: idm:DL1 security update 2025-11-12T00:00:00Z 2025-11-20T09:13:27Z