Recent vulnerabilities


ID CVSS Description Vendor Product Published Updated
CVE-2026-1768
N/A
A permission cache poisoning vulnerability in Dev… Devolutions
Devolutions Server
2026-02-24T19:01:07.640Z 2026-02-24T19:01:07.640Z
CVE-2026-27477
4.6 (4.0)
Mastodon has SSRF via unvalidated FASP Provider base_url mastodon
mastodon
2026-02-24T19:00:20.590Z 2026-02-24T19:00:20.590Z
CVE-2025-1789
5.8 (4.0)
Local privilege escalation in Genetec Update Serv… Genetec Inc.
Genetec Update Service
2026-02-24T18:47:24.913Z 2026-02-24T18:47:24.913Z
CVE-2025-1787
5.8 (4.0)
Local admin could to leak information from the Ge… Genetec Inc.
Genetec Update Service
2026-02-24T18:44:36.705Z 2026-02-24T21:17:58.063Z
CVE-2026-24241
4.3 (3.1)
NVIDIA Delegated Licensing Service for all applia… NVIDIA
DLS component of NVIDIA License System
2026-02-24T18:42:56.703Z 2026-02-24T21:26:40.416Z
CVE-2025-33181
7.3 (3.1)
NVIDIA Cumulus Linux and NVOS products contain a … NVIDIA
Cumulus Linux GA
2026-02-24T18:42:04.490Z 2026-02-24T21:29:14.387Z
CVE-2025-33180
8 (3.1)
NVIDIA Cumulus Linux and NVOS products contain a … NVIDIA
Cumulus Linux GA
2026-02-24T18:41:48.632Z 2026-02-24T21:31:41.482Z
CVE-2025-33179
8 (3.1)
NVIDIA Cumulus Linux and NVOS products contain a … NVIDIA
Cumulus Linux GA
2026-02-24T18:41:32.821Z 2026-02-24T18:41:32.821Z
CVE-2026-26342
8.7 (4.0)
Tattile Smart+ / Vega / Basic <= 1.181.5 Insufficient … Tattile s.r.l.
Smart+
2026-02-24T18:41:09.935Z 2026-02-24T18:41:09.935Z
CVE-2026-26341
9.3 (4.0)
Tattile Smart+ / Vega / Basic <= 1.181.5 Default Credentials Tattile s.r.l.
Smart+
2026-02-24T18:40:54.212Z 2026-02-24T21:33:18.810Z
CVE-2026-26340
8.7 (4.0)
Tattile Smart+ / Vega / Basic <= 1.181.5 Unauthenticat… Tattile s.r.l.
Smart+
2026-02-24T18:40:35.393Z 2026-02-24T21:34:06.523Z
CVE-2026-3105
7.6 (3.1)
SQL Injection in Contact Activity API Sorting Mautic
Mautic
2026-02-24T18:39:03.352Z 2026-02-24T18:39:03.352Z
CVE-2026-26222
10 (4.0)
DocLink .NET Remoting Unauthenticated Arbitrary File R… Beyond Limits Inc.
Altec DocLink
2026-02-24T17:33:12.136Z 2026-02-24T17:36:46.668Z
CVE-2026-25603
6.6 (3.1)
Path Traversal vulnerability in Linksys MR9600, Linksy… Linksys
MR9600
2026-02-24T17:14:36.141Z 2026-02-24T18:13:33.449Z
CVE-2026-27468
4.8 (4.0)
Mastodon may allow unconfirmed FASP to make subscriptions mastodon
mastodon
2026-02-24T17:12:40.349Z 2026-02-24T17:12:40.349Z
CVE-2025-14963
6.2 (4.0)
A vulnerability identified in the Trellix HX Agen… Trellix
Endpoint HX Agent (xAgent)
2026-02-24T17:11:06.812Z 2026-02-25T16:12:50.280Z
CVE-2026-27156
6.1 (3.1)
NiceGUI has XSS via Code Injection zauberzeug
nicegui
2026-02-24T17:00:21.628Z 2026-02-24T17:00:21.628Z
CVE-2025-62512
5.5 (4.0)
Piwigo Vulnerable to User Enumeration via Password Res… Piwigo
Piwigo
2026-02-24T16:43:28.919Z 2026-02-24T16:43:28.919Z
CVE-2024-48928
2.7 (4.0)
Piwigo's secret key can be brute forced Piwigo
Piwigo
2026-02-24T16:39:56.944Z 2026-02-24T16:39:56.944Z
CVE-2026-27590
8.9 (4.0)
Caddy: Unicode case-folding length expansion causes in… caddyserver
caddy
2026-02-24T16:33:41.353Z 2026-02-24T16:33:41.353Z
CVE-2026-27589
6.9 (4.0)
Caddy vulnerable to cross-origin config application vi… caddyserver
caddy
2026-02-24T16:30:52.016Z 2026-02-24T16:31:35.510Z
CVE-2026-27588
7.7 (4.0)
Caddy: MatchHost becomes case-sensitive for large host… caddyserver
caddy
2026-02-24T16:28:28.106Z 2026-02-24T16:28:28.106Z
CVE-2026-27587
7.7 (4.0)
Caddy: MatchPath %xx (escaped-path) branch skips case … caddyserver
caddy
2026-02-24T16:26:40.222Z 2026-02-24T16:26:40.222Z
CVE-2026-27586
8.8 (4.0)
Caddy's mTLS client authentication silently fails open… caddyserver
caddy
2026-02-24T16:08:20.569Z 2026-02-24T16:08:20.569Z
CVE-2026-27585
6.9 (4.0)
Caddy's improper sanitization of glob characters in fi… caddyserver
caddy
2026-02-24T16:06:05.030Z 2026-02-24T16:06:05.030Z
CVE-2026-27571
5.9 (3.1)
nats-server websockets are vulnerable to pre-auth memory DoS nats-io
nats-server
2026-02-24T15:59:17.926Z 2026-02-24T15:59:17.926Z
CVE-2025-13776
8.6 (4.0)
Hard-coded database credentials in Finka software TIK-SOFT
Finka-FK
2026-02-24T15:58:30.096Z 2026-02-24T15:58:30.096Z
CVE-2025-47904
5.7 (4.0)
Unsigned upgrade package Microchip
Time Provider 4100
2026-02-24T15:34:20.905Z 2026-02-24T15:34:20.905Z
CVE-2026-27521
6.9 (4.0)
6.5 (3.1)
Binardat 10G08-0800GSM Network Switch Missing Login Ra… Binardat Ltd.
10G08-0800GSM Network Switch
2026-02-24T15:08:14.170Z 2026-02-24T15:08:14.170Z
CVE-2026-27520
8.7 (4.0)
7.5 (3.1)
Binardat 10G08-0800GSM Network Switch Base64-encoded P… Binardat Ltd.
10G08-0800GSM Network Switch
2026-02-24T15:07:41.085Z 2026-02-24T15:07:41.085Z
ID CVSS Description Vendor Product Published Updated
ID Severity Description Published Updated
ghsa-9wv6-vw4x-jjg6
5.7 (4.0)
Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malic… 2026-02-24T18:31:02Z 2026-02-24T18:31:02Z
ghsa-7c8p-f6jq-w42v
9.8 (3.1)
9.3 (4.0)
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded … 2026-02-24T18:31:02Z 2026-02-24T18:31:02Z
ghsa-69fx-mvcm-v5g3
9.1 (3.1)
9.3 (4.0)
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictabl… 2026-02-24T18:31:02Z 2026-02-24T18:31:02Z
ghsa-4r4r-4jp4-wwf9
9.8 (3.1)
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Executi… 2026-02-24T18:31:02Z 2026-02-25T18:31:35Z
ghsa-3547-c34m-73j3
6.5 (3.1)
6.9 (4.0)
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement ra… 2026-02-24T18:31:02Z 2026-02-25T18:31:36Z
ghsa-qrvq-68c2-7grw
5.9 (3.1)
nats-server websockets are vulnerable to pre-auth memory DoS 2026-02-24T16:04:53Z 2026-02-24T16:04:53Z
ghsa-9fww-8cpr-q66r
6.1 (3.1)
Isso affected by Stored XSS via comment website field 2026-02-24T16:03:04Z 2026-02-24T16:03:04Z
ghsa-v264-xqh4-9xmm
9.9 (3.1)
OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE 2026-02-24T16:00:56Z 2026-02-24T16:00:56Z
ghsa-v2gc-rm6g-wrw9
5.5 (4.0)
Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution 2026-02-24T15:51:07Z 2026-02-24T15:51:07Z
ghsa-w8mw-frc6-r7m8
5.3 (3.1)
ImageMagick: Invalid MSL <map> can result in a use after free 2026-02-24T15:46:49Z 2026-02-24T15:46:49Z
ghsa-gwr3-x37h-h84v
6.2 (3.1)
ImageMagick has a possible infinite loop in its JPEG encoder when using `jpeg:extent` 2026-02-24T15:46:25Z 2026-02-24T15:46:25Z
ghsa-v994-63cg-9wj3
6.2 (3.1)
ImageMagick has infinite loop when writing IPTCTEXT leads to denial of service via crafted profile 2026-02-24T15:46:03Z 2026-02-24T15:46:03Z
ghsa-7355-pwx2-pm84
7.5 (3.1)
ImageMagick: Integer overflow or wraparound and incorrect conversion between numeric types in the i… 2026-02-24T15:45:35Z 2026-02-24T15:45:35Z
ghsa-782x-jh29-9mf7
5.3 (3.1)
ImageMagick: MSL image stack index may fail to refresh, leading to leaked images 2026-02-24T15:45:13Z 2026-02-24T15:45:13Z
ghsa-42p5-62qq-mmh7
5.3 (3.1)
ImageMagick has a heap buffer over-read in its MAP image decoder 2026-02-24T15:44:47Z 2026-02-24T15:44:47Z
ghsa-v7g2-m8c5-mf84
7.5 (3.1)
ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder 2026-02-24T15:44:19Z 2026-02-24T15:44:19Z
ghsa-fwqw-2x5x-w566
5.3 (3.1)
ImageMagick has Use After Free in MSLStartElement in "coders/msl.c" 2026-02-24T15:43:54Z 2026-02-24T15:43:55Z
ghsa-xgm3-v4r9-wfgm
5.3 (3.1)
Image Magick has a Memory Leak in coders/ashlar.c 2026-02-24T15:43:28Z 2026-02-24T15:43:28Z
ghsa-72hf-fj62-w6j4
7.4 (3.1)
ImageMagick: Stack buffer overflow in FTXT reader via oversized integer field 2026-02-24T15:43:02Z 2026-02-24T15:43:02Z
ghsa-xwc6-v6g8-pw2h
5.9 (3.1)
ImageMagick's Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to std… 2026-02-24T15:42:37Z 2026-02-24T15:42:38Z
ghsa-8jvj-p28h-9gm7
8.6 (3.1)
ImageMagick: Policy bypass through path traversal allows reading restricted content despite secured… 2026-02-24T15:40:06Z 2026-02-24T15:40:06Z
ghsa-vpxv-r9pg-7gpr
6.5 (3.1)
ImageMagick has Global Buffer Overflow (OOB Read) via Negative Pixel Index in UIL and XPM Writer 2026-02-24T15:39:11Z 2026-02-24T15:39:11Z
ghsa-6j5f-24fw-pqp4
6.5 (3.1)
ImageMagick: Heap overflow in sun decoder on 32-bit systems may result in out of bounds write 2026-02-24T15:38:35Z 2026-02-24T15:38:35Z
ghsa-543g-8grm-9cw6
5.3 (3.1)
ImageMagick has Division-by-Zero in YUV sampling factor validation, which leads to crash 2026-02-24T15:37:53Z 2026-02-24T15:37:53Z
ghsa-p863-5fgm-rgq4
5.3 (3.1)
ImageMagick has NULL Pointer Dereference in ClonePixelCacheRepository via crafted image 2026-02-24T15:36:08Z 2026-02-24T15:36:08Z
ghsa-rw6c-xp26-225v
5.7 (3.1)
ImageMagick: Code Injection via PostScript header in ps coders 2026-02-24T15:34:26Z 2026-02-24T15:34:26Z
ghsa-g2pr-qxjg-7r2w
5.3 (3.1)
ImageMagick has memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-r… 2026-02-24T15:33:56Z 2026-02-24T15:33:57Z
ghsa-p33r-fqw2-rqmm
5.3 (3.1)
ImageMagick has NULL pointer dereference in ReadSFWImage after DestroyImageInfo (sfw.c) 2026-02-24T15:32:34Z 2026-02-24T15:32:34Z
ghsa-vhqj-f5cj-9x8h
8.2 (3.1)
ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHD… 2026-02-24T15:31:57Z 2026-02-24T15:31:57Z
ghsa-gxcx-qjqp-8vjw
5.3 (3.1)
ImageMagick has memory leak in msl encoder 2026-02-24T15:30:54Z 2026-02-24T15:30:54Z
ID Severity Description Package Published Updated
pysec-2024-166
Nautobot is a Network Source of Truth and Network Automation Platform. A user with permis… nautobot 2024-05-28T23:15:17+00:00 2025-01-18T19:19:06.277166+00:00
pysec-2024-258
In scrapy/scrapy, an issue was identified where the Authorization header is not removed d… scrapy 2024-05-20T08:15:08+00:00 2025-07-15T17:37:50.051730+00:00
pysec-2024-244
7.5 (3.1)
A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a by… mlflow 2024-05-16T09:15:14+00:00 2025-04-08T10:23:25.092581+00:00
pysec-2024-51
A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, whe… mlflow 2024-05-16T09:15:00+00:00 2024-05-16T11:19:52.866536+00:00
pysec-2024-237
9.4 (3.1)
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versio… octoprint 2024-05-14T16:17:12+00:00 2025-03-05T17:22:29.121263+00:00
pysec-2024-185
Nebari through 2024.4.1 prints the temporary Keycloak root password. nebari 2024-05-06T00:15:10+00:00 2025-01-19T04:23:00.951638+00:00
pysec-2024-175
WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because t… wordops 2024-05-06T00:15:10+00:00 2025-01-18T22:21:44.991242+00:00
pysec-2024-255
Gradio before 4.20 allows credential leakage on Windows. gradio 2024-05-05T20:15:07+00:00 2025-06-17T19:21:48.983901+00:00
pysec-2024-233
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consump… python-jose 2024-04-26T00:15:09+00:00 2025-02-18T19:20:15.511369+00:00
pysec-2024-232
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key f… python-jose 2024-04-26T00:15:09+00:00 2025-02-18T19:20:15.468012+00:00
pysec-2024-209
5.3 (3.1)
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions… vyper 2024-04-25T18:15:09+00:00 2025-01-19T19:19:01.689044+00:00
pysec-2024-163
5.3 (3.1)
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Prior to ve… vyper 2024-04-25T18:15:09+00:00 2025-01-14T05:22:23.036505+00:00
pysec-2024-208
5.3 (3.1)
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions… vyper 2024-04-25T18:15:08+00:00 2025-01-19T19:19:01.647736+00:00
pysec-2024-207
5.3 (3.1)
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions… vyper 2024-04-25T18:15:08+00:00 2025-01-19T19:19:01.605918+00:00
pysec-2024-206
5.3 (3.1)
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions… vyper 2024-04-25T18:15:08+00:00 2025-01-19T19:19:01.566553+00:00
pysec-2024-246
5.3 (3.1)
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in… vyper 2024-04-25T17:15:50+00:00 2025-05-05T19:21:20.899426+00:00
pysec-2024-50
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, … matrix-synapse 2024-04-23T18:15:00+00:00 2024-04-23T21:18:51.688096+00:00
pysec-2024-250
Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csr… torch 2024-04-19T21:15:08+00:00 2025-06-03T15:23:56.072490+00:00
pysec-2024-252
PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in t… torch 2024-04-17T19:15:07+00:00 2025-06-10T19:22:08.948962+00:00
pysec-2024-251
Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in… torch 2024-04-17T19:15:07+00:00 2025-06-10T03:12:59.077932+00:00
pysec-2024-243
9.3 (3.1)
mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs… mlflow 2024-04-16T00:15:12+00:00 2025-04-08T10:23:25.044416+00:00
pysec-2024-254
4.2 (3.1)
A session fixation vulnerability exists in the zenml-io/zenml application, where JWT toke… zenml 2024-04-16T00:15:11+00:00 2025-06-13T00:48:41.806476+00:00
pysec-2024-247
9.9 (3.1)
A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically… zenml 2024-04-16T00:15:11+00:00 2025-05-12T15:23:53.861001+00:00
pysec-2024-49
Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be e… lektor 2024-03-27T06:15:00+00:00 2024-03-27T11:18:36.506150+00:00
pysec-2024-257
7.5 (3.1)
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessm… mobsf 2024-03-22T23:15:07+00:00 2025-06-30T15:23:50.085549+00:00
pysec-2024-234
9.8 (3.1)
Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jup… jupyter-server-proxy 2024-03-20T20:15:08+00:00 2025-02-21T18:23:35.992501+00:00
pysec-2024-48
Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial o… black 2024-03-19T05:15:00+00:00 2024-03-19T11:18:50.379002+00:00
pysec-2024-179
4.8 (3.1)
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versio… octoprint 2024-03-18T22:15:07+00:00 2025-01-19T01:52:24.377662+00:00
pysec-2024-47
In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.te… django 2024-03-15T20:15:00+00:00 2024-03-15T23:20:34.975097+00:00
pysec-2024-46
Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenti… apache-airflow 2024-03-14T09:15:00+00:00 2024-03-14T11:19:09.515892+00:00
ID Description Type
ID Description Updated
ID Description Published Updated
mal-2026-824 Malicious code in dev-pipline-test (PyPI) 2026-02-10T07:48:33Z 2026-02-10T07:48:33Z
mal-2026-825 Malicious code in devtools-webhook-cicd-utils (PyPI) 2026-02-10T07:42:45Z 2026-02-10T07:42:45Z
mal-2026-823 Malicious code in ntoutils (PyPI) 2026-02-10T07:25:38Z 2026-02-10T07:25:38Z
mal-2026-821 Malicious code in jwtdotenv (npm) 2026-02-09T17:27:19Z 2026-02-23T04:21:33Z
mal-2026-820 Malicious code in json-web-sources (npm) 2026-02-09T17:25:32Z 2026-02-23T04:21:33Z
mal-2026-819 Malicious code in json-mapping-sources (npm) 2026-02-09T17:25:32Z 2026-02-23T04:21:33Z
mal-2026-822 Malicious code in react-svg-handler (npm) 2026-02-09T17:16:37Z 2026-02-23T04:21:35Z
mal-2026-818 Malicious code in thecorrectjames (PyPI) 2026-02-09T16:25:34Z 2026-02-09T16:25:50Z
mal-2026-817 Malicious code in ctf-pipline-test (PyPI) 2026-02-09T15:35:47Z 2026-02-09T16:28:03Z
mal-2026-816 Malicious code in @skyeng/libs (npm) 2026-02-09T15:12:24Z 2026-02-23T04:21:31Z
mal-2026-814 Malicious code in http-notifier-test (PyPI) 2026-02-09T09:29:06Z 2026-02-09T09:29:06Z
mal-2026-815 Malicious code in skydeo (PyPI) 2026-02-09T09:12:05Z 2026-02-09T09:12:05Z
mal-2026-813 Malicious code in teligram (PyPI) 2026-02-08T22:19:04Z 2026-02-08T22:19:04Z
mal-2026-812 Malicious code in hardixx-code (PyPI) 2026-02-08T21:21:34Z 2026-02-08T22:46:48Z
mal-2026-811 Malicious code in grokwrapper (PyPI) 2026-02-08T10:34:16Z 2026-02-08T10:34:16Z
mal-2026-809 Malicious code in ccxt-bullish (PyPI) 2026-02-08T07:47:19Z 2026-02-08T07:47:19Z
mal-2026-810 Malicious code in thread-pipeline-test (PyPI) 2026-02-08T07:41:19Z 2026-02-08T07:41:19Z
mal-2026-808 Malicious code in carcent (PyPI) 2026-02-06T15:23:01Z 2026-02-06T15:23:01Z
mal-2026-807 Malicious code in web3-sinon (npm) 2026-02-06T14:44:08Z 2026-02-06T18:21:39Z
mal-2026-806 Malicious code in web3-chain-sinon (npm) 2026-02-06T14:44:08Z 2026-02-06T18:21:39Z
mal-2026-805 Malicious code in aligned-arrays (npm) 2026-02-06T14:24:56Z 2026-02-06T16:19:56Z
mal-2025-193012 Malicious code in gridifies (PyPI) 2026-02-06T14:04:11Z 2026-02-14T18:48:58Z
mal-2026-804 Malicious code in breadcrumb-service (npm) 2026-02-06T12:30:53Z 2026-02-06T16:19:57Z
mal-2026-803 Malicious code in moveworks-pipeline-test (PyPI) 2026-02-06T11:36:06Z 2026-02-06T11:36:06Z
mal-2026-802 Malicious code in @sbseg-plugin/qbo-web-app-ui (npm) 2026-02-06T11:10:48Z 2026-02-06T16:19:56Z
mal-2026-801 Malicious code in @rsgweb/utils (npm) 2026-02-06T11:10:48Z 2026-02-06T16:19:56Z
mal-2026-800 Malicious code in @rsgweb/tina (npm) 2026-02-06T11:10:48Z 2026-02-06T16:19:56Z
mal-2026-799 Malicious code in @rsgweb/rockstar-account (npm) 2026-02-06T11:10:48Z 2026-02-06T16:19:56Z
mal-2026-798 Malicious code in @rsgweb/modules-core-www-page (npm) 2026-02-06T11:10:48Z 2026-02-06T16:19:56Z
mal-2026-797 Malicious code in @rsgweb/modules-core-feedback (npm) 2026-02-06T11:10:48Z 2026-02-06T16:19:56Z
ID Description Published Updated
bit-elk-2025-68385 Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 2025-12-20T11:36:36.041Z 2025-12-24T12:08:49.467Z
bit-elasticsearch-2025-68384 Elasticsearch Allocation of Resources Without Limits or Throttling 2025-12-20T11:36:34.496Z 2025-12-20T12:06:39.262Z
bit-mongodb-2025-14847 Zlib compressed protocol header length confusion may allow memory read 2025-12-19T11:15:49.277Z 2025-12-30T00:15:51.160Z
bit-gitlab-2025-8405 Improper Encoding or Escaping of Output in GitLab 2025-12-18T12:06:48.009Z 2025-12-18T12:08:20.703Z
bit-gitlab-2025-4097 Allocation of Resources Without Limits or Throttling in GitLab 2025-12-18T12:05:44.981Z 2025-12-18T12:08:20.703Z
bit-gitlab-2025-14157 Allocation of Resources Without Limits or Throttling in GitLab 2025-12-18T12:04:46.334Z 2025-12-18T12:08:20.703Z
bit-gitlab-2025-13978 Generation of Error Message Containing Sensitive Information in GitLab 2025-12-18T12:04:44.454Z 2025-12-18T12:08:20.703Z
bit-gitlab-2025-12734 Improper Encoding or Escaping of Output in GitLab 2025-12-18T12:04:35.112Z 2025-12-18T12:08:20.703Z
bit-gitlab-2025-12716 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab 2025-12-18T12:04:33.134Z 2025-12-18T12:08:20.703Z
bit-gitlab-2025-12562 Allocation of Resources Without Limits or Throttling in GitLab 2025-12-18T12:04:25.675Z 2025-12-18T12:08:20.703Z
bit-gitlab-2025-12029 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab 2025-12-18T12:04:20.332Z 2025-12-18T12:08:20.703Z
bit-gitlab-2025-11984 Authentication Bypass Using an Alternate Path or Channel in GitLab 2025-12-18T12:04:14.698Z 2025-12-18T12:08:20.703Z
bit-gitlab-2025-11247 Authorization Bypass Through User-Controlled Key in GitLab 2025-12-18T12:03:59.823Z 2025-12-18T12:08:20.703Z
bit-parse-2025-68150 Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter 2025-12-18T11:46:18.950Z 2026-01-08T18:07:34.629Z
bit-parse-2025-68115 Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables 2025-12-18T11:46:17.211Z 2026-01-08T18:07:34.629Z
bit-parse-2025-67727 Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management 2025-12-18T11:46:15.637Z 2026-01-08T18:07:34.629Z
bit-kibana-2025-37732 Kibana Cross-site Scripting via the Integration Package Upload Functionality 2025-12-18T11:40:39.003Z 2025-12-18T12:08:20.703Z
bit-elk-2025-37732 Kibana Cross-site Scripting via the Integration Package Upload Functionality 2025-12-18T11:37:43.350Z 2025-12-18T12:08:20.703Z
bit-elasticsearch-2025-37731 Elasticsearch Improper Authentication 2025-12-18T11:37:43.121Z 2025-12-19T12:06:33.755Z
bit-airflow-2025-66388 Apache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI 2025-12-16T14:37:51.384Z 2025-12-16T15:14:22.118Z
bit-mongodb-2025-12657 Malformed KMIP response may result in access violation 2025-12-13T11:42:23.275Z 2025-12-13T12:05:53.698Z
bit-django-2025-13372 Potential SQL injection in FilteredRelation column aliases on PostgreSQL 2025-12-13T11:36:31.883Z 2025-12-13T12:05:53.698Z
bit-mongodb-2025-14345 Cross-Shard Failovers May Lead to Partial Transaction Commit in MongoDB Server 2025-12-12T17:42:48.437Z 2025-12-12T18:06:16.411Z
bit-jenkins-2025-67639 2025-12-12T11:23:52.749Z 2025-12-12T11:51:34.315Z
bit-jenkins-2025-67638 2025-12-12T11:23:47.516Z 2025-12-12T11:51:34.315Z
bit-jenkins-2025-67637 2025-12-12T11:23:42.761Z 2025-12-12T11:51:34.315Z
bit-jenkins-2025-67636 2025-12-12T11:23:36.617Z 2025-12-12T11:51:34.315Z
bit-jenkins-2025-67635 2025-12-12T11:23:31.286Z 2025-12-12T11:51:34.315Z
bit-mongodb-2025-13644 MongoDB may be susceptible to Invariant Failure due to batched delete 2025-12-12T11:19:13.963Z 2026-01-08T18:07:34.629Z
bit-mongodb-2025-13643 MongoDB Server may allow queries to be terminated by unauthorized users 2025-12-12T11:19:08.903Z 2026-01-08T18:07:34.629Z
ID Description Published Updated
drupal-contrib-2023-052 2023-11-15T14:24:12.000Z 2023-11-15T17:19:15.000Z
drupal-contrib-2023-051 2023-11-08T15:33:12.000Z 2023-11-08T17:10:24.000Z
drupal-contrib-2023-050 2023-11-08T15:30:45.000Z 2023-11-08T17:10:18.000Z
drupal-contrib-2023-049 2023-11-01T16:56:37.000Z 2023-11-06T14:25:23.000Z
drupal-contrib-2023-048 2023-10-04T15:41:34.000Z 2023-10-04T16:35:18.000Z
drupal-contrib-2023-047 2023-09-27T16:33:34.000Z 2023-09-28T21:17:46.000Z
drupal-contrib-2023-045 2023-09-13T15:47:17.000Z 2023-09-13T17:42:33.000Z
drupal-contrib-2023-044 2023-09-06T16:33:36.000Z 2023-09-18T14:27:44.000Z
drupal-contrib-2023-043 2023-09-06T15:23:32.000Z 2023-09-06T16:48:26.000Z
drupal-contrib-2023-042 2023-08-30T16:23:18.000Z 2023-08-30T18:51:57.000Z
drupal-contrib-2023-041 2023-08-30T16:22:06.000Z 2023-08-30T18:51:23.000Z
drupal-contrib-2023-040 2023-08-23T17:24:02.000Z 2023-08-23T18:28:12.000Z
drupal-contrib-2023-039 2023-08-23T17:06:18.000Z 2023-08-23T18:28:35.000Z
drupal-contrib-2023-038 2023-08-23T17:00:14.000Z 2023-08-23T18:47:17.000Z
drupal-contrib-2023-037 2023-08-23T16:54:32.000Z 2023-08-23T18:29:48.000Z
drupal-contrib-2023-035 2023-08-23T14:54:52.000Z 2023-08-23T18:45:59.000Z
drupal-contrib-2023-034 2023-08-23T14:51:16.000Z 2023-08-23T18:45:47.000Z
drupal-contrib-2023-033 2023-08-02T18:59:27.000Z 2023-08-02T19:52:35.000Z
drupal-contrib-2023-032 2023-07-26T19:19:38.000Z 2023-07-26T20:00:09.000Z
drupal-contrib-2023-031 2023-07-26T19:15:46.000Z 2023-07-27T16:05:03.000Z
drupal-contrib-2023-030 2023-07-12T18:19:42.000Z 2023-07-12T18:39:39.000Z
drupal-contrib-2023-029 2023-06-28T17:34:47.000Z 2023-07-31T21:18:37.000Z
drupal-contrib-2023-028 2023-06-28T17:21:37.000Z 2023-07-31T21:17:11.000Z
drupal-contrib-2023-027 2023-06-28T17:15:03.000Z 2023-07-31T21:17:46.000Z
drupal-contrib-2023-026 2023-06-28T17:11:07.000Z 2023-08-10T13:49:56.000Z
drupal-contrib-2023-025 2023-06-28T17:10:15.000Z 2023-10-26T13:22:52.000Z
drupal-contrib-2023-024 2023-06-28T17:03:36.000Z 2023-08-10T13:40:55.000Z
drupal-contrib-2023-023 2023-06-28T17:02:13.000Z 2023-08-10T13:53:00.000Z
drupal-contrib-2023-021 2023-06-21T17:03:14.000Z 2023-08-10T13:53:57.000Z
drupal-contrib-2023-020 2023-06-14T14:52:36.000Z 2023-08-10T13:54:32.000Z
ID Description Updated
ID Description Published Updated
jvndb-2025-000011 Multiple vulnerabilities in FileMegane 2025-02-13T13:39+09:00 2025-02-13T13:39+09:00
jvndb-2025-000010 acmailer vulnerable to cross-site scripting 2025-02-12T15:05+09:00 2025-02-12T15:05+09:00
jvndb-2025-001017 Multiple vulnerabilities in STEALTHONE D220/D340/D440 2025-02-06T18:27+09:00 2025-02-06T18:27+09:00
jvndb-2025-001016 OMRON NJ/NX series vulnerable to path traversal 2025-02-06T18:27+09:00 2025-05-08T17:44+09:00
jvndb-2025-001018 Improper restriction of XML external entity reference (XXE) vulnerability in OMRON NB-Designer 2025-02-06T18:26+09:00 2025-02-06T18:26+09:00
jvndb-2025-000008 Multiple vulnerabilities in Defense Platform Home Edition 2025-02-05T14:06+09:00 2025-02-05T14:06+09:00
jvndb-2025-000009 WordPress Plugin "Activity Log WinterLock" vulnerable to cross-site request forgery 2025-02-04T13:58+09:00 2025-02-04T13:58+09:00
jvndb-2025-001244 Clickjacking Vulnerability in JP1/ServerConductor/Deployment Manager 2025-01-30T18:19+09:00 2025-01-30T18:19+09:00
jvndb-2025-000007 SXF Common Library vulnerable to improper input data handling 2025-01-29T14:57+09:00 2025-01-29T14:57+09:00
jvndb-2025-001238 Multiple out-of-bounds write vulnerabilities in Canon Office/Small Office Multifunction Printers and Laser Printers 2025-01-29T13:41+09:00 2025-05-27T16:06+09:00
jvndb-2025-000006 WordPress Plugin "Simple Image Sizes" vulnerable to cross-site scripting 2025-01-28T13:44+09:00 2025-01-28T13:44+09:00
jvndb-2025-000005 EXIF Viewer Classic vulnerable to cross-site scripting 2025-01-27T14:25+09:00 2025-01-27T14:25+09:00
jvndb-2025-000004 Multiple vulnerabilities in I-O DATA router UD-LT2 2025-01-22T13:55+09:00 2025-02-20T15:55+09:00
jvndb-2025-000003 FortiWeb vulnerable to SQL injection 2025-01-21T15:59+09:00 2025-01-21T15:59+09:00
jvndb-2025-001027 Linux Ratfor vulnerable to stack-based buffer overflow 2025-01-16T13:27+09:00 2025-01-16T13:27+09:00
jvndb-2025-000001 PLANEX COMMUNICATIONS MZK-DP300N vulnerable to cross-site scripting 2025-01-08T17:08+09:00 2025-01-08T17:08+09:00
jvndb-2024-015471 Trend Micro Deep Security 20.0 Agent (for Windows) vulnerable to uncontrolled search path element 2024-12-25T11:28+09:00 2024-12-25T11:28+09:00
jvndb-2024-015393 Multiple security updates for Trend Micro Apex One and Apex One as a Service (December 2024) 2024-12-23T12:52+09:00 2024-12-23T12:52+09:00
jvndb-2024-014918 Authentication Bypass Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer 2024-12-17T15:23+09:00 2024-12-17T15:23+09:00
jvndb-2024-000128 Multiple vulnerabilities in SHARP routers 2024-12-17T07:54+09:00 2024-12-17T07:54+09:00
jvndb-2024-000127 "Shonen Jump+" App for Android fails to restrict custom URL schemes properly 2024-12-16T15:07+09:00 2024-12-16T15:07+09:00
jvndb-2024-014825 WordPress Plugin "My WP Customize Admin/Frontend" vulnerable to cross-site scripting 2024-12-16T13:57+09:00 2024-12-16T13:57+09:00
jvndb-2024-014793 Multiple vulnerabilities in FXC AE1021 and AE1021PE 2024-12-16T11:51+09:00 2024-12-16T11:51+09:00
jvndb-2024-014079 Trend Micro Deep Security Agent for Windows and Deep Security Notifier on DSVA vulnerable to OS command injection 2024-12-06T12:11+09:00 2024-12-06T12:11+09:00
jvndb-2024-000125 Multiple vulnerabilities in I-O DATA routers UD-LT1 and UD-LT1/EX 2024-12-04T15:22+09:00 2024-12-18T15:20+09:00
jvndb-2024-000124 Multiple vulnerabilities in UNIVERGE IX/IX-R/IX-V series routers 2024-12-02T16:38+09:00 2024-12-02T16:38+09:00
jvndb-2024-000123 Multiple FCNT Android devices vulnerable to authentication bypass 2024-11-29T15:30+09:00 2024-11-29T15:30+09:00
jvndb-2024-013702 Multiple vulnerabilities in FUJI ELECTRIC products 2024-11-29T14:42+09:00 2024-11-29T14:42+09:00
jvndb-2024-000122 HAProxy vulnerable to HTTP request/response smuggling 2024-11-27T14:36+09:00 2024-11-27T14:36+09:00
jvndb-2024-000121 WordPress Plugin "WP Admin UI Customize" vulnerable to cross-site scripting 2024-11-26T13:57+09:00 2024-11-26T13:57+09:00
ID Description Updated
ID Description
ID Description Published Updated
cnvd-2026-06086 Tenda AX1806 sub_65B5C函数栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06085 Tenda AX1806 sub_65B5C函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06084 Tenda AX1806 sub_65A28函数栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06082 GPAC vobsub_get_subpic_duration函数缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06081 GPAC uncv_parse_config函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06080 GPAC dump_ttxt_sample函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06079 GPAC pcmreframe_flush_packet函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06078 GPAC oggdmx_parse_tags函数越界读取漏洞 2026-01-19 2026-01-21
cnvd-2026-06077 GPAC avi_parse_input_file函数堆缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06076 GPAC ghi_dmx_declare_opid_bin函数堆缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06075 GPAC越界读取漏洞 2026-01-19 2026-01-21
cnvd-2026-06074 GPAC vorbis_to_intern函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06073 GPAC堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-05118 Kentico Xperience跨站脚本漏洞(CNVD-2026-05118) 2026-01-19 2026-01-20
cnvd-2026-04539 Tenda AX-1806路由器栈溢出漏洞 2026-01-16 2026-01-16
cnvd-2026-09797 Apache SIS XML外部实体注入漏洞 2026-01-15 2026-02-04
cnvd-2026-04663 PHPEMS跨站请求伪造漏洞 2026-01-15 2026-01-16
cnvd-2026-04541 Open5GS GTPv2-C拒绝服务漏洞 2026-01-15 2026-01-16
cnvd-2026-04540 Open5GS GTPv2-C F-TEID s11-handler.c sgwc_s11_handle_create_session_request拒绝服务漏洞 2026-01-15 2026-01-16
cnvd-2026-09798 Apache NiFi代码问题漏洞(CNVD-2026-09798) 2026-01-14 2026-02-04
cnvd-2026-08442 iccDEV SIccCalcOp::ArgsPushed函数类型混淆漏洞 2026-01-14 2026-01-26
cnvd-2026-08441 iccDEV CIccProfileXml::ParseBasic函数类型混淆漏洞 2026-01-14 2026-01-26
cnvd-2026-08440 iccDEV CIccTagXmlTagData::ToXml函数类型混淆漏洞 2026-01-14 2026-01-26
cnvd-2026-08439 iccDEV CIccTag:IsTypeCompressed函数类型混淆漏洞 2026-01-14 2026-01-26
cnvd-2026-08438 iccDEV ToXmlCurve函数类型混淆漏洞 2026-01-14 2026-01-26
cnvd-2026-08437 iccDEV CIccSegmentedCurveXml::ToXml函数类型混淆漏洞 2026-01-14 2026-01-26
cnvd-2026-08436 iccDEV icStatusCMM::CIccEvalCompare::EvaluateProfile函数类型混淆漏洞 2026-01-14 2026-01-26
cnvd-2026-07956 iccDEV CIccProfileXml::ParseBasic函数堆缓冲区溢出漏洞 2026-01-14 2026-01-27
cnvd-2026-07955 iccDEV SIccCalcOp::Describe函数堆缓冲区溢出漏洞 2026-01-14 2026-01-27
cnvd-2026-07112 IBM Concert信息泄露漏洞 2026-01-14 2026-01-23
ID Description Published Updated
bdu:2026-01498 Уязвимость функции si_parse_power_table() ядра операционной системы Linux, позволяющая на… 09.02.2026 09.02.2026
bdu:2026-01497 Уязвимость плагина Rule Based Authorization Plugin поискового сервера Apache Solr, позвол… 09.02.2026 09.02.2026
bdu:2026-01496 Уязвимость функции radeon_atombios_fini() модуля drivers/gpu/drm/radeon/radeon_device.c д… 09.02.2026 09.02.2026
bdu:2026-01495 Уязвимость функции fromSetWifiGusetBasic() микропрограммного обеспечения маршрутизаторов … 09.02.2026 09.02.2026
bdu:2026-01494 Уязвимость функции type_show() ядра операционной системы Linux, позволяющая нарушителю ок… 09.02.2026 09.02.2026
bdu:2026-01493 Уязвимость функции sanity_check_curseg() ядра операционной системы Linux, позволяющая нар… 09.02.2026 09.02.2026
bdu:2026-01492 Уязвимость веб-интерфейса сервера для управления программами Fortinet FortiClient Enterpr… 09.02.2026 09.02.2026
bdu:2026-01491 Уязвимость функции fc_exch_abts_resp() ядра операционной системы Linux, позволяющая наруш… 09.02.2026 09.02.2026
bdu:2026-01490 Уязвимость функции ipc_msg_send_request() ядра операционной системы Linux, позволяющая на… 09.02.2026 09.02.2026
bdu:2026-01489 Уязвимость функции OnAssocReq() ядра операционной системы Linux, позволяющая нарушителю о… 09.02.2026 09.02.2026
bdu:2026-01488 Уязвимость функции ext4_truncate() модуля fs/ext4/inode.c файловой системы Ext4 ядра опер… 09.02.2026 09.02.2026
bdu:2026-01487 Уязвимость функции swap_inode_boot_loader() модуля fs/ext4/ioctl.c файловой системы Ext4 … 09.02.2026 09.02.2026
bdu:2026-01486 Уязвимость функции pci_device_is_present() модуля drivers/pci/pci.c драйвера устройств PC… 09.02.2026 09.02.2026
bdu:2026-01485 Уязвимость функции ath11k_dp_rx_mon_deliver() модуля drivers/net/wireless/ath/ath11k/dp_r… 09.02.2026 09.02.2026
bdu:2026-01484 Уязвимость функций raid0_run() (drivers/md/raid0.c) и raid10_run() (drivers/md/raid10.c) … 09.02.2026 09.02.2026
bdu:2026-01483 Уязвимость функции _regulator_do_enable() модуля drivers/regulator/core.c драйвера регуля… 09.02.2026 09.02.2026
bdu:2026-01468 Уязвимость библиотеки преобразования путей path-to-regexp, связанная с неэффективной вычи… 09.02.2026 09.02.2026
bdu:2026-01467 Уязвимость сервера для разработки Metro Development Server, связанная с непринятием мер п… 09.02.2026 09.02.2026
bdu:2026-01466 Уязвимость компонента Duo Workflow Service сервиса для взаимодействия с внешними LLM-пров… 09.02.2026 09.02.2026
bdu:2026-01465 Уязвимость функции lookup_ioctl() модуля drivers/md/dm-ioctl.c драйвера поддержки несколь… 09.02.2026 09.02.2026
bdu:2026-01464 Уязвимость функции __mcheck_cpu_apply_quirks() модуля arch/x86/kernel/cpu/mce/core.c подд… 09.02.2026 09.02.2026
bdu:2026-01463 Уязвимость функции nwl_dsi_bridge_mode_set() модуля drivers/gpu/drm/bridge/nwl-dsi.c драй… 09.02.2026 09.02.2026
bdu:2026-01462 Уязвимость функции status_resync() модуля drivers/md/md.c драйвера нескольких устройств (… 09.02.2026 09.02.2026
bdu:2026-01461 Уязвимость функции vb2ops_vdec_queue_setup() модуля drivers/media/platform/mediatek/vcode… 09.02.2026 09.02.2026
bdu:2026-01460 Уязвимость функции nilfs_evict_inode() модуля fs/nilfs2/inode.c файловой системы NILFS2 я… 09.02.2026 09.02.2026
bdu:2026-01459 Уязвимость функции mpi_cmp_ui() модуля lib/crypto/mpi/mpi-cmp.c ядра операционной системы… 09.02.2026 09.02.2026
bdu:2026-01458 Уязвимость функции f2fs_abort_atomic_write() модуля fs/f2fs/segment.c файловой системы F2… 09.02.2026 09.02.2026
bdu:2026-01457 Уязвимость функции nilfs_bmap_lookup_at_level() модуля fs/nilfs2/bmap.c файловой системы … 09.02.2026 09.02.2026
bdu:2026-01456 Уязвимость функции __hfs_bnode_create() модуля fs/hfs/bnode.c файловой системы ядра опера… 09.02.2026 09.02.2026
bdu:2026-01455 Уязвимость функции nilfs_prepare_segment_for_recovery() модуля fs/nilfs2/recovery.c подде… 09.02.2026 09.02.2026
ID Description Published Updated
certfr-2025-avi-1142 Multiples vulnérabilités dans Moxa NPort 2025-12-31T00:00:00.000000 2025-12-31T00:00:00.000000
certfr-2025-avi-1141 Multiples vulnérabilités dans le noyau Linux de Red Hat 2025-12-26T00:00:00.000000 2025-12-26T00:00:00.000000
certfr-2025-avi-1140 Multiples vulnérabilités dans le noyau Linux de SUSE 2025-12-26T00:00:00.000000 2025-12-26T00:00:00.000000
certfr-2025-avi-1139 Multiples vulnérabilités dans le noyau Linux d'Ubuntu 2025-12-26T00:00:00.000000 2025-12-26T00:00:00.000000
certfr-2025-avi-1138 Multiples vulnérabilités dans VMware Tanzu Platform 2025-12-26T00:00:00.000000 2025-12-26T00:00:00.000000
certfr-2025-avi-1137 Multiples vulnérabilités dans les produits IBM 2025-12-26T00:00:00.000000 2025-12-26T00:00:00.000000
certfr-2025-avi-1136 Multiples vulnérabilités dans le noyau Linux de Debian LTS 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1135 Multiples vulnérabilités dans le noyau Linux d'Ubuntu 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1134 Multiples vulnérabilités dans MongoDB Server 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1133 Multiples vulnérabilités dans le noyau Linux de SUSE 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1132 Multiples vulnérabilités dans le noyau Linux de Red Hat 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1131 Multiples vulnérabilités dans les produits IBM 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1130 Multiples vulnérabilités dans les produits Foxit 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1129 Multiples vulnérabilités dans les produits VMware 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1128 Multiples vulnérabilités dans Mozilla Firefox 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1127 Multiples vulnérabilités dans Centreon Web 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1126 Multiples vulnérabilités dans PHP 2025-12-19T00:00:00.000000 2025-12-22T00:00:00.000000
certfr-2025-avi-1125 Vulnérabilité dans les produits NetApp 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1124 Multiples vulnérabilités dans Microsoft Edge 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1123 Multiples vulnérabilités dans les produits Elastic 2025-12-19T00:00:00.000000 2025-12-19T00:00:00.000000
certfr-2025-avi-1122 Multiples vulnérabilités dans Mattermost Server 2025-12-18T00:00:00.000000 2026-01-16T00:00:00.000000
certfr-2025-avi-1121 Vulnérabilité dans Sonicwall Secure Mobile Access 2025-12-18T00:00:00.000000 2025-12-18T00:00:00.000000
certfr-2025-avi-1120 Vulnérabilité dans les produits Cisco 2025-12-18T00:00:00.000000 2025-12-18T00:00:00.000000
certfr-2025-avi-1119 Multiples vulnérabilités dans les produits Synology 2025-12-17T00:00:00.000000 2025-12-17T00:00:00.000000
certfr-2025-avi-1118 Vulnérabilité dans Mozilla Firefox 2025-12-17T00:00:00.000000 2025-12-17T00:00:00.000000
certfr-2025-avi-1117 Multiples vulnérabilités dans GLPI 2025-12-17T00:00:00.000000 2025-12-17T00:00:00.000000
certfr-2025-avi-1116 Multiples vulnérabilités dans Google Chrome 2025-12-17T00:00:00.000000 2025-12-17T00:00:00.000000
certfr-2025-avi-1115 Vulnérabilité dans Trend Micro Apex One 2025-12-16T00:00:00.000000 2025-12-16T00:00:00.000000
certfr-2025-avi-1114 Multiples vulnérabilités dans Tenable Nessus 2025-12-16T00:00:00.000000 2025-12-16T00:00:00.000000
certfr-2025-avi-1113 Multiples vulnérabilités dans Moodle 2025-12-16T00:00:00.000000 2025-12-16T00:00:00.000000
ID Description Published Updated
certa-2011-ale-007 Vulnérabilité dans ftpd et ProFTPD sur FreeBSD 2011-12-02T00:00:00.000000 2011-12-26T00:00:00.000000
certa-2011-ale-006 Exploitation d'une vulnérabilité dans la gestion des polices TrueType sur Windows 2011-11-04T00:00:00.000000 2011-12-14T00:00:00.000000
certa-2011-ale-005 Exploitation malveillante d'une fonctionnalité du protocole SSL afin de provoquer un déni de service 2011-10-27T00:00:00.000000 2011-10-27T00:00:00.000000
certa-2011-ale-004 Vulnérabilités dans Apple iOS 2011-07-05T00:00:00.000000 2011-07-18T00:00:00.000000
certa-2011-ale-003 Vulnérabilité dans Adobe Flash Player, Adobe Reader et Acrobat 2011-04-12T00:00:00.000000 2011-06-20T00:00:00.000000
certa-2011-ale-002 Vulnérabilité dans Adobe Flash Player, Adobe Reader et Acrobat 2011-03-15T00:00:00.000000 2011-03-22T00:00:00.000000
certa-2011-ale-001 Vulnérabilité dans le moteur de rendu graphique de Windows 2011-01-05T00:00:00.000000 2011-02-10T00:00:00.000000
certa-2010-ale-021 Vulnérabilité dans Microsoft Internet Explorer 2010-12-22T00:00:00.000000 2011-02-09T00:00:00.000000
certa-2010-ale-020 Vulnérabilité dans Adobe Reader et Acrobat 2010-11-05T00:00:00.000000 2010-11-17T00:00:00.000000
certa-2010-ale-019 Vulnérabilité dans Microsoft Internet Explorer 2010-11-03T00:00:00.000000 2010-12-17T00:00:00.000000
certa-2010-ale-018 Vulnérabilité dans Adobe Flash Player, Adobe Reader et Acrobat 2010-10-28T00:00:00.000000 2010-11-18T00:00:00.000000
certa-2010-ale-017 Vulnérabilité dans Mozilla Firefox 2010-10-27T00:00:00.000000 2010-10-28T00:00:00.000000
certa-2010-ale-016 Vulnérabilité Adobe Shockwave Player 2010-10-22T00:00:00.000000 2010-10-29T00:00:00.000000
certa-2010-ale-015 Vulnérabilité dans Adobe Flash Player 2010-09-14T00:00:00.000000 2010-09-21T00:00:00.000000
certa-2010-ale-014 Vulnérabilité dans Adobe Reader et Adobe Acrobat 2010-09-09T00:00:00.000000 2010-10-06T00:00:00.000000
certa-2010-ale-013 Vulnérabilité dans le contrôle ActiveX Apple QuickTime 2010-08-31T00:00:00.000000 2010-09-17T00:00:00.000000
certa-2010-ale-012 Vulnérabilité dans Adobe Reader et Adobe Acrobat 2010-08-06T00:00:00.000000 2010-08-20T00:00:00.000000
certa-2010-ale-011 Vulnérabilités dans Apple iOS 2010-08-04T00:00:00.000000 2010-08-12T00:00:00.000000
certa-2010-ale-010 Vulnérabilité dans le Shell de Microsoft Windows 2010-07-19T00:00:00.000000 2010-08-03T00:00:00.000000
certa-2010-ale-009 Exploitation par un code malveillant d'une vulnérabilité Microsoft Windows non corrigée 2010-07-16T00:00:00.000000 2010-08-03T00:00:00.000000
certa-2010-ale-008 Vulnérabilité dans le Centre d'aide et de support Windows 2010-06-10T00:00:00.000000 2010-07-15T00:00:00.000000
certa-2010-ale-007 Vulnérabilité Shockwave Flash pour les produits Adobe 2010-06-05T00:00:00.000000 2010-06-30T00:00:00.000000
certa-2010-ale-006 Vulnérabilité de Safari 2010-05-14T00:00:00.000000 2010-05-27T00:00:00.000000
certa-2010-ale-005 Vulnérabilité dans Java Deployment Toolkit 2010-04-09T00:00:00.000000 2010-04-16T00:00:00.000000
certa-2010-ale-004 Vulnérabilité dans Microsoft Internet Explorer 2010-03-10T00:00:00.000000 2010-03-31T00:00:00.000000
certa-2010-ale-003 Vulnérabilité dans Microsoft VBScript 2010-03-02T00:00:00.000000 2010-04-13T00:00:00.000000
certa-2010-ale-002 Vulnérabilité dans le sous-système MS-DOS de Microsoft Windows 2010-01-21T00:00:00.000000 2010-02-10T00:00:00.000000
certa-2010-ale-001 Vulnérabilité dans Microsoft Internet Explorer 2010-01-15T00:00:00.000000 2010-01-22T00:00:00.000000
certa-2009-ale-023 Vulnérabilité dans Adobe Reader et Adobe Acrobat 2009-12-15T00:00:00.000000 2010-01-13T00:00:00.000000
certa-2009-ale-022 Vulnérabilité dans TANDBERG MXP 2009-12-11T00:00:00.000000 2009-12-11T00:00:00.000000
ID Description Published Updated
osv-2025-175 UNKNOWN READ in insert_free 2025-02-28T00:12:26.919208Z 2025-02-28T00:12:26.919553Z
osv-2025-174 Heap-use-after-free in gc_trace 2025-02-28T00:12:25.140274Z 2025-02-28T00:12:25.140618Z
osv-2025-173 UNKNOWN READ in chunk_obj_alloc 2025-02-28T00:11:40.566459Z 2025-02-28T00:11:40.566797Z
osv-2025-169 Stack-buffer-overflow in utf8_in2 2025-02-27T00:07:08.029075Z 2025-02-27T00:07:08.029655Z
osv-2025-165 Index-out-of-bounds in dwg_decode_eed 2025-02-26T00:17:27.930225Z 2025-02-26T00:17:27.930707Z
osv-2025-162 Heap-buffer-overflow in snmp_in_options 2025-02-24T00:15:40.967551Z 2025-03-18T00:30:24.116747Z
osv-2025-161 Heap-buffer-overflow in se_add_pair 2025-02-24T00:15:33.662895Z 2025-03-18T00:37:12.676515Z
osv-2025-160 UNKNOWN WRITE in ndpi_free_flow_data 2025-02-24T00:07:49.495615Z 2025-02-24T00:07:49.495976Z
osv-2025-156 Check failed in CheckUnwind 2025-02-23T00:16:50.073196Z 2025-02-23T00:16:50.073520Z
osv-2025-154 UNKNOWN READ in ndpi_strdup 2025-02-23T00:13:05.487818Z 2025-02-23T00:13:05.488183Z
osv-2025-149 UNKNOWN READ in processClientServerHello 2025-02-23T00:00:50.236281Z 2025-02-23T00:00:50.236700Z
osv-2025-148 Heap-buffer-overflow in setup_engineID 2025-02-23T00:00:36.951152Z 2025-03-18T00:22:22.817245Z
osv-2025-147 UNKNOWN WRITE in ndpi_free_flow_data 2025-02-22T00:18:07.814416Z 2025-02-22T00:18:07.814726Z
osv-2025-145 Heap-buffer-overflow in ___interceptor_strncat 2025-02-22T00:14:15.620085Z 2025-02-22T00:14:15.620535Z
osv-2025-133 Stack-buffer-overflow in se_read_conf 2025-02-17T00:02:18.986364Z 2025-03-18T00:27:33.917908Z
osv-2025-132 Heap-use-after-free in netsnmp_hex_to_binary 2025-02-17T00:01:01.920904Z 2025-03-18T00:33:26.648884Z
osv-2025-131 Heap-buffer-overflow in vips_foreign_save_heif_write_block 2025-02-16T00:13:44.282887Z 2025-03-18T00:32:21.245932Z
osv-2025-127 Object-size in unpack_dsd_samples 2025-02-15T00:16:56.314634Z 2025-02-15T00:16:56.315060Z
osv-2025-124 Use-of-uninitialized-value in get_word 2025-02-15T00:09:23.967012Z 2025-02-15T00:09:23.967345Z
osv-2025-119 Heap-buffer-overflow in snmp_config_when 2025-02-14T00:15:08.375253Z 2025-03-18T00:37:43.437021Z
osv-2025-114 Index-out-of-bounds in ada_fuzz_header.h 2025-02-14T00:11:24.754671Z 2025-02-14T00:11:24.755045Z
osv-2025-113 Heap-buffer-overflow in snmp_log_options 2025-02-14T00:01:45.812592Z 2025-03-18T00:35:43.690001Z
osv-2025-111 Stack-buffer-overflow in absl::debugging_internal::ParseLocalNameSuffix 2025-02-13T00:15:36.403252Z 2025-02-13T00:15:36.403744Z
osv-2022-1292 Heap-buffer-overflow in LibRaw::phase_one_correct 2025-02-10T00:13:32.671074Z 2025-02-10T00:13:32.671487Z
osv-2025-108 Use-of-uninitialized-value in decimate_dsd_run 2025-02-10T00:12:35.140061Z 2025-02-10T00:12:35.140400Z
osv-2025-107 Use-of-uninitialized-value in get_words_lossless 2025-02-10T00:06:27.370789Z 2025-02-10T00:06:27.371196Z
osv-2025-105 Heap-use-after-free in unpack_dsd_samples 2025-02-10T00:00:59.046535Z 2025-02-10T00:00:59.047010Z
osv-2025-93 Heap-buffer-overflow in lj_strfmt_pushvf 2025-02-05T00:18:14.584575Z 2025-07-23T14:24:29.384461Z
osv-2025-92 Null-dereference READ in session_startup 2025-02-05T00:18:00.385170Z 2025-12-20T14:25:08.038174Z
osv-2025-90 Null-dereference READ in ubsan_GetStackTrace 2025-02-03T00:02:54.185593Z 2025-12-20T14:15:37.974751Z
ID Description Published Updated
rustsec-2024-0376 Remotely exploitable Denial of Service in Tonic 2024-10-01T12:00:00Z 2025-09-11T07:02:22Z
rustsec-2024-0375 `atty` is unmaintained 2024-09-25T12:00:00Z 2024-09-26T12:26:22Z
rustsec-2024-0374 Segmentation fault due to use of uninitialized memory 2024-09-22T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0427 get-size-derive is unmaintained 2024-09-15T12:00:00Z 2024-12-22T09:01:06Z
rustsec-2024-0425 get-size is unmaintained 2024-09-15T12:00:00Z 2024-12-22T09:01:06Z
rustsec-2024-0404 Unsoundness in anstream 2024-09-08T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0443 webp crate may expose memory contents when encoding an image 2024-09-06T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0371 gix-path improperly resolves configuration path reported by Git 2024-09-06T12:00:00Z 2024-09-07T01:48:33Z
rustsec-2024-0372 Memory leak when calling a canister method via `ic_cdk::call` 2024-09-05T12:00:00Z 2024-09-07T18:23:36Z
rustsec-2024-0386 strason is unmaintained 2024-09-04T12:00:00Z 2024-11-10T13:16:48Z
rustsec-2024-0383 bcc is unmaintained 2024-09-04T12:00:00Z 2024-11-10T12:53:21Z
rustsec-2024-0382 hwloc is unmaintained 2024-09-04T12:00:00Z 2024-11-10T12:52:40Z
rustsec-2024-0373 `Endpoint::retry()` calls can lead to panicking 2024-09-02T12:00:00Z 2024-09-08T01:47:13Z
rustsec-2024-0368 olm-sys: wrapped library unmaintained, potentially vulnerable 2024-09-02T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0384 `instant` is unmaintained 2024-09-01T12:00:00Z 2024-11-10T13:10:28Z
rustsec-2024-0370 proc-macro-error is unmaintained 2024-09-01T12:00:00Z 2024-09-09T12:08:37Z
rustsec-2024-0367 gix-path uses local config across repos when it is the highest scope 2024-08-31T12:00:00Z 2024-09-03T22:23:51Z
rustsec-2024-0366 CWA-2023-004: Excessive number of function parameters in compiled Wasm 2024-08-27T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0385 `cw0` is unmaintained 2024-08-26T12:00:00Z 2024-11-10T13:12:32Z
rustsec-2024-0365 Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts 2024-08-23T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0364 gitoxide-core does not neutralize special characters for terminals 2024-08-22T12:00:00Z 2024-08-22T23:15:02Z
rustsec-2024-0363 Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts 2024-08-15T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0444 Uncaught exception when transitioning the state of `AsyncGenerator` objects from within a property getter of `then` 2024-08-14T12:00:00Z 2025-12-19T06:15:15Z
rustsec-2024-0390 minitrace is Unmaintained 2024-08-14T12:00:00Z 2024-11-10T13:54:21Z
rustsec-2024-0361 CWA-2024-004: Gas mispricing in cosmwasm-vm 2024-08-08T12:00:00Z 2024-08-08T17:11:37Z
rustsec-2024-0362 Stack overflow when parsing specially crafted JSON ABI strings 2024-07-30T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0446 Shell expansion in custom commands 2024-07-26T12:00:00Z 2025-12-22T13:54:49Z
rustsec-2024-0360 `XmpFile::close` can trigger UB 2024-07-26T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0359 The kstring integration in gix-attributes is unsound 2024-07-24T12:00:00Z 2025-01-19T00:36:24Z
rustsec-2024-0358 Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files 2024-07-23T12:00:00Z 2025-10-28T06:02:18Z
ID Description Published Updated
alsa-2025:23479 Moderate: openssh security update 2025-12-17T00:00:00Z 2025-12-21T20:05:20Z
alsa-2025:23383 Moderate: curl security update 2025-12-16T00:00:00Z 2025-12-22T14:12:06Z
alsa-2025:23382 Moderate: binutils security update 2025-12-16T00:00:00Z 2025-12-22T14:14:14Z
alsa-2025:23343 Moderate: binutils security update 2025-12-16T00:00:00Z 2025-12-22T13:47:22Z
alsa-2025:23342 Moderate: python3.9 security update 2025-12-16T00:00:00Z 2025-12-22T13:45:25Z
alsa-2025:23336 Moderate: gcc-toolset-13-binutils security update 2025-12-16T00:00:00Z 2025-12-22T13:43:11Z
alsa-2025:23326 Moderate: skopeo security update 2025-12-16T00:00:00Z 2025-12-22T13:49:03Z
alsa-2025:23325 Moderate: podman security update 2025-12-16T00:00:00Z 2025-12-22T13:50:22Z
alsa-2025:23323 Moderate: python3.12 security update 2025-12-16T00:00:00Z 2025-12-22T13:52:25Z
alsa-2025:23309 Moderate: php:8.3 security update 2025-12-16T00:00:00Z 2025-12-22T13:55:21Z
alsa-2025:23306 Moderate: binutils security update 2025-12-16T00:00:00Z 2025-12-22T13:58:22Z
alsa-2025:23295 Moderate: podman security update 2025-12-16T00:00:00Z 2025-12-22T13:57:14Z
alsa-2025:23294 Moderate: skopeo security update 2025-12-16T00:00:00Z 2025-12-22T13:59:22Z
alsa-2025:23279 Important: kernel security update 2025-12-16T00:00:00Z 2026-01-05T20:25:38Z
alsa-2025:23241 Important: kernel security update 2025-12-16T00:00:00Z 2026-01-05T20:29:24Z
alsa-2025:23210 Important: keylime security update 2025-12-15T00:00:00Z 2025-12-17T13:58:57Z
alsa-2025:23201 Important: keylime security update 2025-12-15T00:00:00Z 2025-12-22T14:00:47Z
alsa-2025:23142 Important: wireshark security update 2025-12-11T00:00:00Z 2025-12-12T10:27:48Z
alsa-2025:23141 Moderate: ruby security update 2025-12-11T00:00:00Z 2026-01-05T20:34:29Z
alsa-2025:23139 Moderate: libsoup3 security update 2025-12-11T00:00:00Z 2025-12-12T10:26:40Z
alsa-2025:23137 Moderate: mysql:8.4 security update 2025-12-11T00:00:00Z 2025-12-12T10:24:42Z
alsa-2025:23134 Moderate: mysql:8.0 security update 2025-12-11T00:00:00Z 2025-12-12T10:33:42Z
alsa-2025:23128 Important: firefox security update 2025-12-11T00:00:00Z 2025-12-12T10:19:27Z
alsa-2025:23111 Moderate: mysql:8.4 security update 2025-12-11T00:00:00Z 2025-12-17T11:32:52Z
alsa-2025:23109 Moderate: mysql security update 2025-12-11T00:00:00Z 2025-12-12T10:21:57Z
alsa-2025:23088 Moderate: grafana security update 2025-12-11T00:00:00Z 2025-12-12T10:18:20Z
alsa-2025:23087 Moderate: grafana security update 2025-12-11T00:00:00Z 2025-12-15T12:37:43Z
alsa-2025:23086 Moderate: luksmeta security update 2025-12-11T00:00:00Z 2025-12-11T13:43:22Z
alsa-2025:23083 Important: wireshark security update 2025-12-10T00:00:00Z 2025-12-12T10:17:19Z
alsa-2025:23063 Moderate: ruby:3.3 security update 2025-12-10T00:00:00Z 2026-01-05T20:38:49Z