Recent vulnerabilities


ID CVSS Description Vendor Product Published Updated
CVE-2026-24241
4.3 (3.1)
NVIDIA Delegated Licensing Service for all applia… NVIDIA
DLS component of NVIDIA License System
2026-02-24T18:42:56.703Z 2026-02-24T21:26:40.416Z
CVE-2025-33181
7.3 (3.1)
NVIDIA Cumulus Linux and NVOS products contain a … NVIDIA
Cumulus Linux GA
2026-02-24T18:42:04.490Z 2026-02-24T21:29:14.387Z
CVE-2025-33180
8 (3.1)
NVIDIA Cumulus Linux and NVOS products contain a … NVIDIA
Cumulus Linux GA
2026-02-24T18:41:48.632Z 2026-02-24T21:31:41.482Z
CVE-2025-33179
8 (3.1)
NVIDIA Cumulus Linux and NVOS products contain a … NVIDIA
Cumulus Linux GA
2026-02-24T18:41:32.821Z 2026-02-24T18:41:32.821Z
CVE-2026-26342
8.7 (4.0)
Tattile Smart+ / Vega / Basic <= 1.181.5 Insufficient … Tattile s.r.l.
Smart+
2026-02-24T18:41:09.935Z 2026-02-24T18:41:09.935Z
CVE-2026-26341
9.3 (4.0)
Tattile Smart+ / Vega / Basic <= 1.181.5 Default Credentials Tattile s.r.l.
Smart+
2026-02-24T18:40:54.212Z 2026-02-24T21:33:18.810Z
CVE-2026-26340
8.7 (4.0)
Tattile Smart+ / Vega / Basic <= 1.181.5 Unauthenticat… Tattile s.r.l.
Smart+
2026-02-24T18:40:35.393Z 2026-02-24T21:34:06.523Z
CVE-2026-3105
7.6 (3.1)
SQL Injection in Contact Activity API Sorting Mautic
Mautic
2026-02-24T18:39:03.352Z 2026-02-24T18:39:03.352Z
CVE-2026-26222
10 (4.0)
DocLink .NET Remoting Unauthenticated Arbitrary File R… Beyond Limits Inc.
Altec DocLink
2026-02-24T17:33:12.136Z 2026-02-24T17:36:46.668Z
CVE-2026-25603
6.6 (3.1)
Path Traversal vulnerability in Linksys MR9600, Linksy… Linksys
MR9600
2026-02-24T17:14:36.141Z 2026-02-24T18:13:33.449Z
CVE-2026-27468
4.8 (4.0)
Mastodon may allow unconfirmed FASP to make subscriptions mastodon
mastodon
2026-02-24T17:12:40.349Z 2026-02-24T17:12:40.349Z
CVE-2025-14963
6.2 (4.0)
A vulnerability identified in the Trellix HX Agen… Trellix
Endpoint HX Agent (xAgent)
2026-02-24T17:11:06.812Z 2026-02-25T16:12:50.280Z
CVE-2026-27156
6.1 (3.1)
NiceGUI has XSS via Code Injection zauberzeug
nicegui
2026-02-24T17:00:21.628Z 2026-02-24T17:00:21.628Z
CVE-2025-62512
5.5 (4.0)
Piwigo Vulnerable to User Enumeration via Password Res… Piwigo
Piwigo
2026-02-24T16:43:28.919Z 2026-02-24T16:43:28.919Z
CVE-2024-48928
2.7 (4.0)
Piwigo's secret key can be brute forced Piwigo
Piwigo
2026-02-24T16:39:56.944Z 2026-02-24T16:39:56.944Z
CVE-2026-27590
8.9 (4.0)
Caddy: Unicode case-folding length expansion causes in… caddyserver
caddy
2026-02-24T16:33:41.353Z 2026-02-24T16:33:41.353Z
CVE-2026-27589
6.9 (4.0)
Caddy vulnerable to cross-origin config application vi… caddyserver
caddy
2026-02-24T16:30:52.016Z 2026-02-24T16:31:35.510Z
CVE-2026-27588
7.7 (4.0)
Caddy: MatchHost becomes case-sensitive for large host… caddyserver
caddy
2026-02-24T16:28:28.106Z 2026-02-24T16:28:28.106Z
CVE-2026-27587
7.7 (4.0)
Caddy: MatchPath %xx (escaped-path) branch skips case … caddyserver
caddy
2026-02-24T16:26:40.222Z 2026-02-24T16:26:40.222Z
CVE-2026-27586
8.8 (4.0)
Caddy's mTLS client authentication silently fails open… caddyserver
caddy
2026-02-24T16:08:20.569Z 2026-02-24T16:08:20.569Z
CVE-2026-27585
6.9 (4.0)
Caddy's improper sanitization of glob characters in fi… caddyserver
caddy
2026-02-24T16:06:05.030Z 2026-02-24T16:06:05.030Z
CVE-2026-27571
5.9 (3.1)
nats-server websockets are vulnerable to pre-auth memory DoS nats-io
nats-server
2026-02-24T15:59:17.926Z 2026-02-24T15:59:17.926Z
CVE-2025-13776
8.6 (4.0)
Hard-coded database credentials in Finka software TIK-SOFT
Finka-FK
2026-02-24T15:58:30.096Z 2026-02-24T15:58:30.096Z
CVE-2025-47904
5.7 (4.0)
Unsigned upgrade package Microchip
Time Provider 4100
2026-02-24T15:34:20.905Z 2026-02-24T15:34:20.905Z
CVE-2026-27521
6.9 (4.0)
6.5 (3.1)
Binardat 10G08-0800GSM Network Switch Missing Login Ra… Binardat Ltd.
10G08-0800GSM Network Switch
2026-02-24T15:08:14.170Z 2026-02-24T15:08:14.170Z
CVE-2026-27520
8.7 (4.0)
7.5 (3.1)
Binardat 10G08-0800GSM Network Switch Base64-encoded P… Binardat Ltd.
10G08-0800GSM Network Switch
2026-02-24T15:07:41.085Z 2026-02-24T15:07:41.085Z
CVE-2026-27519
8.7 (4.0)
7.5 (3.1)
Binardat 10G08-0800GSM Network Switch Hard-coded RC4 E… Binardat Ltd.
10G08-0800GSM Network Switch
2026-02-24T15:07:10.410Z 2026-02-24T15:07:10.410Z
CVE-2026-27518
5.1 (4.0)
4.3 (3.1)
Binardat 10G08-0800GSM Network Switch CSRF Binardat Ltd.
10G08-0800GSM Network Switch
2026-02-24T15:06:39.513Z 2026-02-24T15:06:39.513Z
CVE-2026-27517
5.1 (4.0)
5.4 (3.1)
Binardat 10G08-0800GSM Network Switch XSS Binardat Ltd.
10G08-0800GSM Network Switch
2026-02-24T15:06:08.974Z 2026-02-24T15:06:08.974Z
CVE-2026-27516
8.6 (4.0)
8.1 (3.1)
Binardat 10G08-0800GSM Network Switch Plaintext Passwo… Binardat Ltd.
10G08-0800GSM Network Switch
2026-02-24T15:05:12.384Z 2026-02-24T15:05:12.384Z
ID CVSS Description Vendor Product Published Updated
ID Severity Description Published Updated
ghsa-8jvj-p28h-9gm7
8.6 (3.1)
ImageMagick: Policy bypass through path traversal allows reading restricted content despite secured… 2026-02-24T15:40:06Z 2026-02-24T15:40:06Z
ghsa-vpxv-r9pg-7gpr
6.5 (3.1)
ImageMagick has Global Buffer Overflow (OOB Read) via Negative Pixel Index in UIL and XPM Writer 2026-02-24T15:39:11Z 2026-02-24T15:39:11Z
ghsa-6j5f-24fw-pqp4
6.5 (3.1)
ImageMagick: Heap overflow in sun decoder on 32-bit systems may result in out of bounds write 2026-02-24T15:38:35Z 2026-02-24T15:38:35Z
ghsa-543g-8grm-9cw6
5.3 (3.1)
ImageMagick has Division-by-Zero in YUV sampling factor validation, which leads to crash 2026-02-24T15:37:53Z 2026-02-24T15:37:53Z
ghsa-p863-5fgm-rgq4
5.3 (3.1)
ImageMagick has NULL Pointer Dereference in ClonePixelCacheRepository via crafted image 2026-02-24T15:36:08Z 2026-02-24T15:36:08Z
ghsa-rw6c-xp26-225v
5.7 (3.1)
ImageMagick: Code Injection via PostScript header in ps coders 2026-02-24T15:34:26Z 2026-02-24T15:34:26Z
ghsa-g2pr-qxjg-7r2w
5.3 (3.1)
ImageMagick has memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-r… 2026-02-24T15:33:56Z 2026-02-24T15:33:57Z
ghsa-p33r-fqw2-rqmm
5.3 (3.1)
ImageMagick has NULL pointer dereference in ReadSFWImage after DestroyImageInfo (sfw.c) 2026-02-24T15:32:34Z 2026-02-24T15:32:34Z
ghsa-vhqj-f5cj-9x8h
8.2 (3.1)
ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHD… 2026-02-24T15:31:57Z 2026-02-24T15:31:57Z
ghsa-gxcx-qjqp-8vjw
5.3 (3.1)
ImageMagick has memory leak in msl encoder 2026-02-24T15:30:54Z 2026-02-24T15:30:54Z
ghsa-xx53-6qqj-gr7w
9.8 (3.1)
Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence o… 2026-02-24T15:30:33Z 2026-02-25T15:31:37Z
ghsa-xqx8-2c6c-9g3g
4.9 (3.1)
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to… 2026-02-24T15:30:33Z 2026-02-24T18:31:02Z
ghsa-v5qr-j3c6-xxx2
7.5 (3.1)
TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cste… 2026-02-24T15:30:33Z 2026-02-25T18:31:35Z
ghsa-pr9m-7cjw-258w
4.9 (3.1)
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash… 2026-02-24T15:30:33Z 2026-02-24T18:31:02Z
ghsa-pq5g-x5q3-3g25
4.9 (3.1)
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management … 2026-02-24T15:30:33Z 2026-02-24T18:31:02Z
ghsa-mr6q-w873-6jfr
6.3 (3.1)
2.1 (4.0)
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function Se… 2026-02-24T15:30:33Z 2026-02-24T15:30:33Z
ghsa-6pf6-w4c2-rx3f
6.3 (3.1)
2.1 (4.0)
A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code o… 2026-02-24T15:30:33Z 2026-02-24T15:30:33Z
ghsa-58j5-qr69-3544
6.8 (3.1)
The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user aut… 2026-02-24T15:30:33Z 2026-02-24T15:30:33Z
ghsa-3q93-28v9-5x6v
4.9 (3.1)
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a fi… 2026-02-24T15:30:33Z 2026-02-24T18:31:02Z
ghsa-xchm-7954-5wvg
9.8 (3.1)
Use-after-free in the DOM: Window and Location component. This vulnerability affects Firefox < 148,… 2026-02-24T15:30:32Z 2026-02-25T15:31:37Z
ghsa-wcpx-2xqg-ff43
9.8 (3.1)
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability affects Firefox… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-vxjv-c6cq-74m6
9.8 (3.1)
Mitigation bypass in the Networking: Cache component. This vulnerability affects Firefox < 148 and … 2026-02-24T15:30:32Z 2026-02-25T15:31:37Z
ghsa-q6rm-rhj9-jpg5
9.8 (3.1)
Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148 and Fi… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-p9gc-q2gc-jc6r
4.2 (3.1)
Race condition in the JavaScript: GC component. This vulnerability affects Firefox < 148. 2026-02-24T15:30:32Z 2026-02-24T18:31:02Z
ghsa-p4fg-vw73-vr29
9.8 (3.1)
Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 148 and Fire… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-m8jj-q5xq-4qhp
7.5 (3.1)
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This v… 2026-02-24T15:30:32Z 2026-02-25T21:31:18Z
ghsa-jvc5-7j9r-q4m6
9.8 (3.1)
Same-origin policy bypass in the Networking: JAR component. This vulnerability affects Firefox < 14… 2026-02-24T15:30:32Z 2026-02-25T15:31:37Z
ghsa-hwjj-g6g7-p8cf
9.1 (3.1)
Uninitialized memory in the Graphics: Text component. This vulnerability affects Firefox < 148. 2026-02-24T15:30:32Z 2026-02-25T21:31:18Z
ghsa-hjq8-wc3q-9xf3
9.8 (3.1)
Privilege escalation in the Messaging System component. This vulnerability affects Firefox < 148, F… 2026-02-24T15:30:32Z 2026-02-25T18:31:35Z
ghsa-h79p-mfpr-8qm4
9.8 (3.1)
Use-after-free in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firef… 2026-02-24T15:30:32Z 2026-02-25T15:31:37Z
ID Severity Description Package Published Updated
pysec-2024-221
5.3 (3.1)
aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd i… aiosmtpd 2024-03-12T21:15:58+00:00 2025-01-22T16:23:18.042465+00:00
pysec-2024-44
In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __arr… rpyc 2024-03-12T16:15:00+00:00 2024-03-12T19:19:21.886478+00:00
pysec-2024-45
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to contro… langchain-core 2024-03-04T00:15:00+00:00 2024-03-13T23:20:07.486731+00:00
pysec-2024-43
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to contro… langchain 2024-03-04T00:15:00+00:00 2024-03-05T10:22:15.555734+00:00
pysec-2024-42
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops … apache-airflow 2024-03-01T11:15:00+00:00 2024-03-01T14:20:34.498842+00:00
pysec-2024-245
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated user… apache-airflow 2024-02-29T11:15:08+00:00 2025-05-01T21:22:38.598048+00:00
pysec-2024-162
6.5 (3.1)
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider … scrapy 2024-02-28T00:15:53+00:00 2025-01-14T05:22:21.870348+00:00
pysec-2024-41
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. … diffoscope 2024-02-27T02:15:00+00:00 2024-02-27T07:20:27.954412+00:00
pysec-2024-205
5.3 (3.1)
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using … vyper 2024-02-26T20:19:05+00:00 2025-01-19T19:19:01.519824+00:00
pysec-2024-164
5.3 (3.1)
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an exces… vyper 2024-02-26T20:19:05+00:00 2025-01-16T21:21:41.436934+00:00
pysec-2024-40
orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents. orjson 2024-02-26T16:28:00+00:00 2024-02-26T18:22:26.039698+00:00
pysec-2024-253
pretix before 2024.1.1 mishandles file validation. pretix 2024-02-26T16:28:00+00:00 2025-06-11T15:23:51.683422+00:00
pysec-2024-235
8.1 (3.1)
With the following crawler configuration: ```python from bs4 import BeautifulSoup as Sou… langchain-exa 2024-02-26T16:27:49+00:00 2025-02-26T02:48:56.937312+00:00
pysec-2024-39
Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Var… fastecdsa 2024-02-24T05:15:00+00:00 2024-02-24T07:19:09.418536+00:00
pysec-2024-241
9.6 (3.1)
Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untru… mlflow 2024-02-23T22:15:55+00:00 2025-04-08T10:23:24.946136+00:00
pysec-2024-240
9.6 (3.1)
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This … mlflow 2024-02-23T22:15:55+00:00 2025-04-08T10:23:24.900947+00:00
pysec-2024-223
9.1 (3.1)
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds … onnx 2024-02-23T18:15:50+00:00 2025-01-22T16:23:22.060512+00:00
pysec-2024-222
7.5 (3.1)
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Trav… onnx 2024-02-23T18:15:50+00:00 2025-01-22T16:23:21.994731+00:00
pysec-2024-249
6.1 (3.1)
### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload f… label-studio 2024-02-22T22:15:47+00:00 2025-05-19T11:22:35.312280+00:00
pysec-2024-226
7.8 (3.1)
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analy… pymatgen 2024-02-21T17:15:09+00:00 2025-02-06T00:34:28.734730+00:00
pysec-2024-225
7.5 (3.1)
cryptography is a package designed to expose cryptographic primitives and recipes to Pyth… cryptography 2024-02-21T17:15:09+00:00 2025-02-06T00:34:24.427679+00:00
pysec-2024-155
7.5 (3.1)
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) … cbor2 2024-02-19T23:15:07+00:00 2025-01-14T05:22:09.226388+00:00
pysec-2024-107
5.0 (3.1)
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modif… exiv2 2024-02-12T23:15:00+00:00 2024-10-23T00:00:00+00:00
pysec-2024-106
5.0 (3.1)
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modif… exiv2 2024-02-12T23:15:00+00:00 2024-10-23T00:00:00+00:00
pysec-2024-104
5.3 (3.1)
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of … jwcrypto 2024-02-12T14:15:00+00:00 2024-10-10T17:22:00.587279+00:00
pysec-2024-37
6.5 (3.1)
nonebot2 is a cross-platform Python asynchronous chatbot framework written in Python. Thi… nonebot2 2024-02-09T23:15:00+00:00 2024-02-16T16:22:37.389642+00:00
pysec-2024-125
7.5 (3.1)
DIRAC is a distributed resource framework. In affected versions any user could get a toke… dirac 2024-02-09T00:15:00+00:00 2024-11-21T14:22:45.495938+00:00
pysec-2024-150
9.8 (3.1)
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can … vyper 2024-02-07T17:15:00+00:00 2024-11-21T14:23:03.024978+00:00
pysec-2024-28
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 be… django 2024-02-06T22:16:00+00:00 2024-02-07T00:25:46.826634+00:00
pysec-2024-36
5.5 (3.1)
An information disclosure flaw was found in ansible-core due to a failure to respect the … ansible-core 2024-02-06T12:15:00+00:00 2024-02-14T07:20:09.911618+00:00
ID Description Type
ID Description Updated
ID Description Published Updated
mal-2026-796 Malicious code in @rdxportal/ui-components (npm) 2026-02-06T11:10:48Z 2026-02-06T16:19:56Z
mal-2026-795 Malicious code in @opposhop/nuxt-ssr-cache (npm) 2026-02-06T11:10:47Z 2026-02-06T16:19:56Z
mal-2026-792 Malicious code in @meli-lint/eslint-config-base (npm) 2026-02-06T11:10:47Z 2026-02-06T16:19:56Z
mal-2026-794 Malicious code in @meli-lint/eslint-config-tests-jest (npm) 2026-02-06T11:10:46Z 2026-02-06T16:19:56Z
mal-2026-793 Malicious code in @meli-lint/eslint-config-base-ts (npm) 2026-02-06T11:10:46Z 2026-02-06T16:19:56Z
mal-2026-791 Malicious code in @hashicorp-internal/vault-reporting (npm) 2026-02-06T11:10:46Z 2026-02-06T16:19:56Z
mal-2026-790 Malicious code in p7zip-full (PyPI) 2026-02-06T09:30:38Z 2026-02-06T09:30:38Z
mal-2026-789 Malicious code in syf-typings (npm) 2026-02-06T07:06:46Z 2026-02-06T21:46:29Z
mal-2026-787 Malicious code in @sporting-life/sportinglife-be (npm) 2026-02-06T04:07:15Z 2026-02-06T16:19:56Z
mal-2026-788 Malicious code in @sporting-life/sportinglife-betslip-sdk (npm) 2026-02-06T03:57:32Z 2026-02-06T16:19:56Z
mal-2026-786 Malicious code in @rsgweb/locale-tools (npm) 2026-02-06T03:46:00Z 2026-02-06T16:19:56Z
mal-2026-785 Malicious code in ppe-test (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-784 Malicious code in monkey-tags (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-783 Malicious code in adobe_pipeline_test (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-782 Malicious code in ac-polyfills (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-781 Malicious code in ac-feature (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-780 Malicious code in ac-element-engagement (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-779 Malicious code in ac-dom-styles (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-778 Malicious code in ac-dom-nodes (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-777 Malicious code in ac-dom-events (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-776 Malicious code in ac-checksum (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-775 Malicious code in ac-array (npm) 2026-02-06T02:07:02Z 2026-02-06T02:07:02Z
mal-2026-774 Malicious code in adminbypasser (PyPI) 2026-02-06T01:15:08Z 2026-02-06T01:15:08Z
mal-2026-773 Malicious code in ethers-lint (npm) 2026-02-05T21:21:25Z 2026-02-06T03:05:23Z
mal-2026-771 Malicious code in test-npm-style (npm) 2026-02-05T19:06:12Z 2026-02-06T03:05:27Z
mal-2026-770 Malicious code in xpack-per-user (npm) 2026-02-05T18:36:26Z 2026-02-06T03:05:27Z
mal-2026-768 Malicious code in debug-logger-utils (npm) 2026-02-05T17:31:41Z 2026-02-06T03:05:23Z
mal-2026-767 Malicious code in 0xhash-utils (npm) 2026-02-05T17:29:50Z 2026-02-06T03:05:21Z
mal-2026-769 Malicious code in https-servers (npm) 2026-02-05T17:28:15Z 2026-02-06T03:05:24Z
mal-2026-766 Malicious code in greeter-pro-test (PyPI) 2026-02-05T16:40:51Z 2026-02-05T16:40:56Z
ID Description Published Updated
bit-mastodon-2025-67500 Mastodon Error Handling Discrepancy Enables Private Status Existence Enumeration 2025-12-11T11:41:16.693Z 2026-01-08T18:07:34.629Z
bit-django-2025-64460 Potential denial-of-service vulnerability in XML serializer text extraction 2025-12-11T11:37:12.400Z 2025-12-11T12:06:55.559Z
bit-python-2025-12084 Quadratic complexity in node ID cache clearing 2025-12-10T17:49:06.243Z 2026-01-27T09:14:53.416Z
bit-libpython-2025-12084 Quadratic complexity in node ID cache clearing 2025-12-10T17:41:46.450Z 2026-01-27T09:14:53.416Z
bit-gitlab-2024-9183 Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab 2025-12-09T12:02:49.276Z 2025-12-11T12:06:55.559Z
bit-apache-2025-66200 Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo 2025-12-09T11:38:20.150Z 2025-12-09T12:08:00.393Z
bit-apache-2025-65082 Apache HTTP Server: CGI environment variable override 2025-12-09T11:38:18.501Z 2025-12-09T12:08:00.393Z
bit-apache-2025-59775 Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF 2025-12-09T11:38:16.754Z 2025-12-09T12:08:00.393Z
bit-apache-2025-58098 Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... 2025-12-09T11:38:15.033Z 2025-12-09T12:08:00.393Z
bit-apache-2025-55753 Apache HTTP Server: mod_md (ACME), unintended retry intervals 2025-12-09T11:38:13.178Z 2025-12-09T12:08:00.393Z
bit-pgbouncer-2025-12819 Untrusted search path in auth_query connection in PgBouncer 2025-12-06T11:44:20.875Z 2025-12-28T12:07:40.562Z
bit-mongodb-2025-13507 Time-series operations may cause internal BSON size limit to be exceed 2025-12-06T11:42:49.537Z 2025-12-06T12:06:23.267Z
bit-mongodb-2025-12893 Improper Certificate Validation May Allow Successful TLS Handshaking Despite Invalid Extended Key Usage Fields in MongoDB Server 2025-12-06T11:42:47.994Z 2025-12-06T12:06:23.267Z
bit-mongodb-2025-11979 Use-after-free in the MongoDB server query planner may lead to crash or undefined behavior 2025-12-06T11:42:46.232Z 2025-12-06T12:06:23.267Z
bit-golang-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 2025-12-06T11:41:09.464Z 2025-12-06T12:06:23.267Z
bit-envoy-2025-66220 Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte 2025-12-06T11:38:21.122Z 2025-12-09T12:08:00.393Z
bit-envoy-2025-64763 Envoy forwards early CONNECT data in TCP proxy mode 2025-12-06T11:38:19.488Z 2025-12-09T12:08:00.393Z
bit-envoy-2025-64527 Envoy crashes when JWT authentication is configured with the remote JWKS fetching 2025-12-06T11:38:17.923Z 2025-12-09T12:08:00.393Z
bit-python-2025-6075 Quadratic complexity in os.path.expandvars() with user-controlled template 2025-12-05T11:13:34.373Z 2025-12-05T11:40:36.013Z
bit-python-2025-13837 Out-of-memory when loading Plist 2025-12-05T11:13:08.742Z 2025-12-23T12:07:14.245Z
bit-python-2025-13836 Excessive read buffering DoS in http.client 2025-12-05T11:13:05.077Z 2026-01-27T09:14:53.416Z
bit-libpython-2025-6075 Quadratic complexity in os.path.expandvars() with user-controlled template 2025-12-05T11:08:28.184Z 2025-12-05T11:40:36.013Z
bit-libpython-2025-13837 Out-of-memory when loading Plist 2025-12-05T11:07:43.325Z 2025-12-23T12:07:14.245Z
bit-libpython-2025-13836 Excessive read buffering DoS in http.client 2025-12-05T11:07:36.854Z 2026-01-27T09:14:53.416Z
bit-golang-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 2025-12-04T11:41:52.637Z 2025-12-04T12:07:39.656Z
bit-activemq-2025-27533 Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation 2025-12-03T14:35:40.173Z 2025-12-03T15:08:24.036Z
bit-activemq-2023-46604 Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack 2025-12-03T14:35:38.733Z 2025-12-03T15:08:24.036Z
bit-activemq-2022-41678 Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE 2025-12-03T14:35:37.010Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-26117 ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind 2025-12-03T14:35:35.296Z 2025-12-03T15:08:24.036Z
bit-activemq-2021-21351 XStream is vulnerable to an Arbitrary Code Execution attack 2025-12-03T14:35:33.786Z 2025-12-03T15:08:24.036Z
ID Description Published Updated
drupal-contrib-2023-019 2023-05-31T13:22:44.000Z 2023-08-10T13:56:55.000Z
drupal-contrib-2023-018 2023-05-31T13:20:43.000Z 2023-08-10T13:56:48.000Z
drupal-contrib-2023-017 2023-05-31T13:18:52.000Z 2023-08-10T13:57:22.000Z
drupal-contrib-2023-016 2023-05-31T13:14:25.000Z 2023-08-10T13:58:03.000Z
drupal-contrib-2023-014 2023-05-03T15:44:12.000Z 2023-08-10T13:58:54.000Z
drupal-contrib-2023-013 2023-04-12T16:09:25.000Z 2023-08-10T14:19:21.000Z
drupal-contrib-2023-012 2023-03-29T17:44:58.000Z 2023-08-10T14:19:50.000Z
drupal-contrib-2023-011 2023-03-15T17:40:02.000Z 2023-08-10T15:37:51.000Z
drupal-contrib-2023-010 2023-03-15T17:22:57.000Z 2023-08-10T14:20:35.000Z
drupal-contrib-2023-009 2023-03-08T17:46:44.000Z 2023-08-10T14:20:59.000Z
drupal-contrib-2023-008 2023-03-01T17:38:09.000Z 2023-08-10T14:21:21.000Z
drupal-contrib-2023-007 2023-03-01T17:11:03.000Z 2023-08-10T14:22:08.000Z
drupal-contrib-2023-006 2023-03-01T15:15:08.000Z 2023-08-10T14:22:32.000Z
drupal-contrib-2023-005 2023-02-01T16:13:42.000Z 2023-08-10T14:23:38.000Z
drupal-contrib-2023-004 2023-01-18T17:49:04.000Z 2023-08-10T14:23:53.000Z
drupal-contrib-2023-003 2023-01-18T17:36:56.000Z 2023-08-10T14:25:39.000Z
drupal-contrib-2023-002 2023-01-18T17:28:05.000Z 2023-08-10T14:25:24.000Z
drupal-contrib-2023-001 2023-01-11T17:15:37.000Z 2023-08-10T14:25:04.000Z
drupal-contrib-2022-062 2022-11-30T15:34:03.000Z 2023-08-10T18:25:13.000Z
drupal-contrib-2022-061 2022-11-30T15:28:44.000Z 2023-08-10T18:25:19.000Z
drupal-contrib-2022-060 2022-11-30T15:20:10.000Z 2023-08-10T18:23:08.000Z
drupal-contrib-2022-059 2022-10-19T20:28:24.000Z 2023-08-10T18:22:23.000Z
drupal-contrib-2022-058 2022-10-12T19:41:07.000Z 2023-08-10T19:30:04.000Z
drupal-contrib-2022-056 2022-09-07T17:06:06.000Z 2023-08-10T19:28:12.000Z
drupal-contrib-2022-055 2022-09-07T17:04:31.000Z 2023-08-10T19:27:28.000Z
drupal-contrib-2022-054 2022-09-07T16:57:28.000Z 2023-08-10T19:26:43.000Z
drupal-contrib-2022-053 2022-08-24T18:21:02.000Z 2023-08-10T19:26:24.000Z
drupal-contrib-2022-052 2022-08-10T15:09:36.000Z 2023-08-10T19:25:47.000Z
drupal-contrib-2022-051 2022-07-27T17:07:39.000Z 2023-08-10T19:25:28.000Z
drupal-contrib-2022-050 2022-07-27T17:03:38.000Z 2023-08-10T19:24:22.000Z
ID Description Updated
ID Description Published Updated
jvndb-2024-013260 Multiple vulnerabilities in Edgecross Basic Software for Windows 2024-11-22T10:59+09:00 2025-11-04T16:41+09:00
jvndb-2024-000120 "Kura Sushi Official App Produced by EPARK" for Android uses a hard-coded cryptographic key 2024-11-20T13:56+09:00 2024-11-20T13:56+09:00
jvndb-2024-012941 Multiple vulnerabilities in Rakuten Turbo 5G 2024-11-19T10:41+09:00 2024-11-19T10:41+09:00
jvndb-2024-000119 Multiple vulnerabilities in FitNesse 2024-11-15T13:37+09:00 2024-11-20T11:18+09:00
jvndb-2024-012461 Multiple vulnerabilities in SoftBank Mesh Wi-Fi router RP562B 2024-11-13T14:26+09:00 2024-11-26T16:11+09:00
jvndb-2024-000118 WordPress Plugin "VK All in One Expansion Unit" vulnerable to cross-site scripting 2024-11-13T13:50+09:00 2024-11-13T13:50+09:00
jvndb-2024-012017 Trend Micro Deep Security 20 Agent for Windows vulnerable to improper access control 2024-11-06T11:00+09:00 2024-11-06T11:00+09:00
jvndb-2024-011833 Incorrect authorization vulnerability in OMRON Sysmac Studio 2024-11-05T15:29+09:00 2024-11-05T15:29+09:00
jvndb-2024-011747 Command injection vulnerability in Trend Micro Cloud Edge 2024-11-01T14:28+09:00 2024-11-01T14:28+09:00
jvndb-2024-011744 REST-APIs unintentionally enabled in Century Systems FutureNet NXR series routers 2024-11-01T13:49+09:00 2024-11-01T13:49+09:00
jvndb-2024-000117 Stack-based buffer overflow vulnerability in multiple laser printers and MFPs which implement Ricoh Web Image Monitor 2024-10-31T16:44+09:00 2025-05-19T17:59+09:00
jvndb-2024-000116 Hikvision network camera security enhancement to prevent cleartext transmission of Dynamic DNS credentials 2024-10-30T15:07+09:00 2024-10-30T15:07+09:00
jvndb-2024-011256 Multiple vulnerabilities in Sharp and Toshiba Tec MFPs 2024-10-28T17:33+09:00 2024-10-28T17:33+09:00
jvndb-2024-000115 Chatwork Desktop Application (Windows) uses a potentially dangerous function 2024-10-28T14:29+09:00 2024-10-28T14:29+09:00
jvndb-2024-000114 Multiple vulnerabilities in baserCMS 2024-10-25T15:07+09:00 2025-02-18T15:35+09:00
jvndb-2024-010802 Multiple SQL injection vulnerabilities in Trend Micro Deep Discovery Inspector 2024-10-22T13:02+09:00 2024-10-22T13:02+09:00
jvndb-2024-000106 Multiple vulnerabilities in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software 2024-10-21T11:58+09:00 2024-11-21T11:37+09:00
jvndb-2024-000113 N-LINE vulnerable to HTML injection 2024-10-18T14:48+09:00 2024-10-25T16:48+09:00
jvndb-2024-000112 MUSASI version 3 performing authentication on client-side 2024-10-18T14:40+09:00 2024-10-25T16:55+09:00
jvndb-2024-000111 SHIRASAGI vulnerable to path traversal 2024-10-16T14:12+09:00 2024-10-23T17:35+09:00
jvndb-2024-000110 Multiple vulnerabilities in Exment 2024-10-11T14:13+09:00 2024-10-11T14:13+09:00
jvndb-2024-000109 baserCMS plugin "BurgerEditor" vulnerable to directory listing 2024-10-10T14:57+09:00 2024-11-06T14:45+09:00
jvndb-2024-009667 Multiple vulnerabilities in JTEKT ELECTRONICS Kostac PLC Programming Software 2024-10-03T13:42+09:00 2024-10-03T13:42+09:00
jvndb-2024-000108 Apache Tomcat improper handling of TLS handshake process data 2024-10-01T17:51+09:00 2024-10-01T17:51+09:00
jvndb-2024-009498 Vulnerability in Cosminexus 2024-10-01T16:01+09:00 2024-10-01T16:01+09:00
jvndb-2024-009481 Insecure initial password configuration issue in SEIKO EPSON Web Config 2024-10-01T14:14+09:00 2024-11-12T10:25+09:00
jvndb-2024-000107 RevoWorks Cloud vulnerable to unintended process execution 2024-09-30T15:17+09:00 2024-09-30T15:17+09:00
jvndb-2024-003932 File Permissions Vulnerability in Hitachi Ops Center Common Services 2024-09-30T14:15+09:00 2024-09-30T14:15+09:00
jvndb-2024-000105 Multiple vulnerabilities in Smart-tab 2024-09-30T14:14+09:00 2024-09-30T14:14+09:00
jvndb-2024-009396 SNMP service is enabled by default in Sharp NEC Display Solutions projectors 2024-09-30T12:46+09:00 2024-09-30T12:46+09:00
ID Description Updated
ID Description
ID Description Published Updated
cnvd-2026-07111 IBM Concert竞争条件漏洞 2026-01-14 2026-01-23
cnvd-2026-06812 D-Link DWR-M920 sub_423848函数缓冲区溢出漏洞 2026-01-14 2026-01-23
cnvd-2026-06811 D-Link DWR-M920 sub_464794函数缓冲区溢出漏洞 2026-01-14 2026-01-23
cnvd-2026-06810 D-Link DWR-M920命令注入漏洞 2026-01-14 2026-01-23
cnvd-2026-06809 D-Link DWR-M920 sub_42261C函数堆栈缓冲区溢出漏洞 2026-01-14 2026-01-23
cnvd-2026-06094 Tenda M3 /goform/setInternetLanInfo文件堆缓冲区溢出漏洞 2026-01-14 2026-01-21
cnvd-2026-05329 Complete Online Beauty Parlor Management System /search-invoices.php文件跨站脚本漏洞 2026-01-14 2026-01-21
cnvd-2026-04917 Refugee Food Management System SQL注入漏洞 2026-01-14 2026-01-19
cnvd-2026-04665 FastAdmin SQL注入漏洞 2026-01-14 2026-01-16
cnvd-2026-04664 Panda3d栈溢出漏洞 2026-01-14 2026-01-16
cnvd-2026-04542 PHPEMS竞争条件问题漏洞 2026-01-14 2026-01-16
cnvd-2026-04185 D-Link DWR-M920命令注入漏洞 2026-01-14 2026-01-16
cnvd-2026-04184 D-Link DSL-124访问控制错误漏洞 2026-01-14 2026-01-16
cnvd-2026-07960 Soda PDF Desktop权限提升漏洞 2026-01-09 2026-01-27
cnvd-2026-07959 Soda PDF Desktop越界读取信息泄露漏洞(CNVD-2026-07959) 2026-01-09 2026-01-27
cnvd-2026-07958 Soda PDF Desktop内存损坏信息泄露漏洞 2026-01-09 2026-01-27
cnvd-2026-07957 Soda PDF Desktop越界读取信息泄露漏洞 2026-01-09 2026-01-27
cnvd-2026-07554 WordPress插件Wallet System for WooCommerce信息泄露漏洞 2026-01-09 2026-01-28
cnvd-2026-07241 Google Chrome策略执行不足漏洞 2026-01-09 2026-01-22
cnvd-2026-06139 JeecgBoot getDeptRoleByUserId函数信息泄露漏洞 2026-01-09 2026-01-22
cnvd-2026-06138 JeecgBoot loadDatarule函数授权问题漏洞 2026-01-09 2026-01-22
cnvd-2026-06137 JeecgBoot queryPageList函数授权问题漏洞 2026-01-09 2026-01-22
cnvd-2026-06136 JeecgBoot getDeptRoleList函数授权问题漏洞 2026-01-09 2026-01-22
cnvd-2026-06135 JeecgBoot getParameterMap函数授权问题漏洞 2026-01-09 2026-01-22
cnvd-2026-06134 JeecgBoot /datarule文件授权问题漏洞 2026-01-09 2026-01-22
cnvd-2026-06133 JeecgBoot getPositionUserList函数授权问题漏洞 2026-01-09 2026-01-22
cnvd-2026-06132 JeecgBoot queryDepartPermission函数授权问题漏洞 2026-01-09 2026-01-22
cnvd-2026-06111 Soda PDF Desktop越界读取漏洞 2026-01-09 2026-01-21
cnvd-2026-06110 Soda PDF Desktop代码执行漏洞(CNVD-2026-06110) 2026-01-09 2026-01-21
cnvd-2026-06108 Soda PDF Desktop代码执行漏洞(CNVD-2026-06108) 2026-01-09 2026-01-21
ID Description Published Updated
bdu:2026-01454 Уязвимость функции rcu_tasks_rude_wait_gp() модуля kernel/rcu/tasks.h ядра операционной с… 09.02.2026 09.02.2026
bdu:2026-01453 Уязвимость функции gfs2_show_options() модуля fs/gfs2/super.c файловой системы GFS2 ядра … 09.02.2026 09.02.2026
bdu:2026-01452 Уязвимость функции show_ipi_list() модуля arch/loongarch/kernel/smp.c поддержки архитекту… 09.02.2026 09.02.2026
bdu:2026-01451 Уязвимость функции ucsi_read_message_in() модуля drivers/usb/typec/ucsi/ucsi.c драйвера п… 09.02.2026 09.02.2026
bdu:2026-01450 Уязвимость определения структуры imx8mp_blk_ctrl_domain_data{} модуля drivers/pmdomain/im… 09.02.2026 09.02.2026
bdu:2026-01449 Уязвимость функции free_netvsc_device() модуля drivers/net/hyperv/netvsc.c драйвера подде… 09.02.2026 09.02.2026
bdu:2026-01448 Уязвимость функции iwl_txq_reclaim() модуля drivers/net/wireless/intel/iwlwifi/queue/tx.c… 09.02.2026 09.02.2026
bdu:2026-01447 Уязвимость функции x86_android_tablet_remove() модуля drivers/platform/x86/x86-android-ta… 09.02.2026 09.02.2026
bdu:2026-01446 Уязвимость функции __ext4_fill_super() модуля fs/ext4/super.c ядра операционной системы L… 09.02.2026 09.02.2026
bdu:2026-01445 Уязвимость функции ena_com_cdesc_rx_pkt_get() модуля drivers/net/ethernet/amazon/ena/ena_… 09.02.2026 09.02.2026
bdu:2026-01444 Уязвимость функции scrub_submit_extent_sector_read() модуля fs/btrfs/scrub.c поддержки фа… 09.02.2026 09.02.2026
bdu:2026-01443 Уязвимость функции nvmf_reg_read32() модуля drivers/nvme/host/fabrics.c драйвера поддержк… 09.02.2026 09.02.2026
bdu:2026-01442 Уязвимость функции kvm_get_mode() модуля arch/arm64/include/asm/kvm_host.h поддержки плат… 09.02.2026 09.02.2026
bdu:2026-01441 Уязвимость компонента RDMA/mlx5 ядра операционной системы Linux, позволяющая нарушителю в… 09.02.2026 09.02.2026
bdu:2026-01440 Уязвимость команды WMI_TXSTATUS_EVENTID ядра операционной системы Linux, позволяющая нару… 09.02.2026 09.02.2026
bdu:2026-01439 Уязвимость компонента smb ядра операционной системы Linux, позволяющая нарушителю оказать… 09.02.2026 09.02.2026
bdu:2026-01438 Уязвимость функции stbi__convert_format библиотек для C/C++ Libstb, позволяющая нарушител… 09.02.2026 09.02.2026
bdu:2026-01437 Уязвимость компонента kdc/do_tgs_req.c сетевого протокола аутентификации Kerberos, позвол… 09.02.2026 09.02.2026
bdu:2026-01436 Уязвимость программной платформы Node.js, связанная с неконтролируемым расходом ресурсов,… 09.02.2026 09.02.2026
bdu:2026-01435 Уязвимость функций Buffer.fill() и Buffer.alloc() программной платформы Node.js, позволяю… 09.02.2026 09.02.2026
bdu:2026-01434 Уязвимость компонентов node_http2 программной платформы Node.js, позволяющая нарушителю в… 09.02.2026 09.02.2026
bdu:2026-01433 Уязвимость сетевого протокола аутентификации Kerberos, связанная с непринятием мер по ней… 09.02.2026 09.02.2026
bdu:2026-01432 Уязвимость сетевого протокола аутентификации Kerberos, связанная с недостатком использова… 09.02.2026 09.02.2026
bdu:2026-01431 Уязвимость программной платформы для разработки и управления веб-приложениями Symfony, св… 09.02.2026 09.02.2026
bdu:2026-01430 Уязвимость функции url.parse() программной платформы Node.js, позволяющая нарушителю оказ… 09.02.2026 09.02.2026
bdu:2026-01429 Уязвимость компонентов http программной платформы Node.js, позволяющая нарушителю вызвать… 09.02.2026 09.02.2026
bdu:2026-01428 Уязвимость кодировки UCS-2 программной платформы Node.js, позволяющая нарушителю вызвать … 09.02.2026 09.02.2026
bdu:2026-01427 Уязвимость функции GetImagePixelCache компонента MagickCore/cache.c консольного графическ… 09.02.2026 09.02.2026
bdu:2026-01426 Уязвимость функции WriteTIFFImage компонента coders/tiff.c консольного графического редак… 09.02.2026 09.02.2026
bdu:2026-01425 Уязвимость функции MontageImageCommand компонента MagickWand/montage.c консольного графич… 09.02.2026 09.02.2026
ID Description Published Updated
certfr-2025-avi-1112 Multiples vulnérabilités dans les produits Elastic 2025-12-15T00:00:00.000000 2025-12-15T00:00:00.000000
certfr-2025-avi-1111 Multiples vulnérabilités dans Roundcube 2025-12-15T00:00:00.000000 2026-01-05T00:00:00.000000
certfr-2025-avi-1110 Multiples vulnérabilités dans les produits Apple 2025-12-15T00:00:00.000000 2025-12-15T00:00:00.000000
certfr-2025-avi-1109 Vulnérabilité dans strongSwan 2025-12-15T00:00:00.000000 2025-12-15T00:00:00.000000
certfr-2025-avi-1108 Multiples vulnérabilités dans les produits IBM 2025-12-12T00:00:00.000000 2025-12-12T00:00:00.000000
certfr-2025-avi-1107 Multiples vulnérabilités dans le noyau Linux de SUSE 2025-12-12T00:00:00.000000 2025-12-12T00:00:00.000000
certfr-2025-avi-1106 Multiples vulnérabilités dans le noyau Linux d'Ubuntu 2025-12-12T00:00:00.000000 2025-12-12T00:00:00.000000
certfr-2025-avi-1105 Multiples vulnérabilités dans le noyau Linux de Red Hat 2025-12-12T00:00:00.000000 2025-12-12T00:00:00.000000
certfr-2025-avi-1104 Vulnérabilité dans Microsoft Windows Admin Center 2025-12-12T00:00:00.000000 2025-12-12T00:00:00.000000
certfr-2025-avi-1103 Multiples vulnérabilités dans Microsoft Edge 2025-12-12T00:00:00.000000 2025-12-15T00:00:00.000000
certfr-2025-avi-1102 Multiples vulnérabilités dans les produits NetApp 2025-12-12T00:00:00.000000 2025-12-12T00:00:00.000000
certfr-2025-avi-1101 Multiples vulnérabilités dans les produits Netgate 2025-12-12T00:00:00.000000 2025-12-12T00:00:00.000000
certfr-2025-avi-1100 Multiples vulnérabilités dans les produits Atlassian 2025-12-12T00:00:00.000000 2025-12-12T00:00:00.000000
certfr-2025-avi-1099 Multiples vulnérabilités dans les produits Mozilla 2025-12-11T00:00:00.000000 2025-12-11T00:00:00.000000
certfr-2025-avi-1098 Vulnérabilité dans Broadcom Carbon Black Cloud 2025-12-11T00:00:00.000000 2025-12-11T00:00:00.000000
certfr-2025-avi-1097 Vulnérabilité dans les produits Mitel 2025-12-11T00:00:00.000000 2026-01-06T00:00:00.000000
certfr-2025-avi-1096 Multiples vulnérabilités dans Google Chrome 2025-12-11T00:00:00.000000 2025-12-15T00:00:00.000000
certfr-2025-avi-1095 Multiples vulnérabilités dans GitLab 2025-12-11T00:00:00.000000 2025-12-11T00:00:00.000000
certfr-2025-avi-1094 Multiples vulnérabilités dans les produits Microsoft 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1093 Vulnérabilité dans Microsoft Azure Monitor Agent 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1092 Multiples vulnérabilités dans Microsoft Windows 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1091 Multiples vulnérabilités dans Microsoft Office 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1090 Vulnérabilité dans les produits Moxa 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1089 Vulnérabilité dans les produits Bitdefender 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1088 Multiples vulnérabilités dans Ivanti Endpoint Manager (EPM) 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1087 Multiples vulnérabilités dans les produits Mozilla 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1086 Multiples vulnérabilités dans les produits Intel 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1085 Multiples vulnérabilités dans les produits Adobe 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1084 Multiples vulnérabilités dans les produits Fortinet 2025-12-10T00:00:00.000000 2025-12-10T00:00:00.000000
certfr-2025-avi-1083 Multiples vulnérabilités dans les produits Siemens 2025-12-09T00:00:00.000000 2025-12-09T00:00:00.000000
ID Description Published Updated
certa-2009-ale-021 Vulnérabilité dans Adobe Illustrator 2009-12-10T00:00:00.000000 2010-01-08T00:00:00.000000
certa-2009-ale-020 Vulnérabilité dans Internet Explorer 2009-11-21T00:00:00.000000 2009-12-09T00:00:00.000000
certa-2009-ale-019 Vulnérabilité dans Windows 7 et Windows Server 2008 R2 2009-11-16T00:00:00.000000 2010-06-10T00:00:00.000000
certa-2009-ale-018 Vulnérabilité dans Adobe Reader et Adobe Acrobat 2009-10-09T00:00:00.000000 2009-10-14T00:00:00.000000
certa-2009-ale-017 Vulnérabilités dans l'implémentation TCP/IP de divers produits 2009-09-09T00:00:00.000000 2013-02-19T00:00:00.000000
certa-2009-ale-016 Vulnérabilité de SMBv2 dans Microsoft Windows 2009-09-09T00:00:00.000000 2009-10-13T00:00:00.000000
certa-2009-ale-015 Vulnérabilités du serveur FTP de Microsoft IIS 2009-09-01T00:00:00.000000 2009-10-14T00:00:00.000000
certa-2009-ale-014 Multiples vulnérabilités du client de messagerie Mozilla Thunderbird 2009-08-07T00:00:00.000000 2013-02-05T00:00:00.000000
certa-2009-ale-013 Vulnérabilité Shockwave Flash pour les produits Adobe 2009-07-23T00:00:00.000000 2009-07-31T00:00:00.000000
certa-2009-ale-012 Vulnérabilité dans Mozilla Firefox 2009-07-15T00:00:00.000000 2009-07-17T00:00:00.000000
certa-2009-ale-011 Vulnérabilité dans Microsoft Office Web Components Control 2009-07-13T00:00:00.000000 2009-08-12T00:00:00.000000
certa-2009-ale-010 Vulnérabilité dans le contrôle ActiveX Microsoft Video 2009-07-07T00:00:00.000000 2009-07-15T00:00:00.000000
certa-2009-ale-009 Vulnérabilité dans Microsoft DirectShow 2009-05-29T00:00:00.000000 2009-07-14T00:00:00.000000
certa-2009-ale-008 Vulnérabilité Java de Mac OS X 2009-05-20T00:00:00.000000 2009-06-17T00:00:00.000000
certa-2009-ale-007 Vulnérabilité WebDAV sous Microsoft IIS 2009-05-18T00:00:00.000000 2009-06-10T00:00:00.000000
certa-2009-ale-006 Multiples vulnérabilités dans Adobe Reader et Adobe Acrobat 2009-04-28T00:00:00.000000 2009-05-13T00:00:00.000000
certa-2009-ale-005 Vulnérabilité de PowerPoint 2009-04-03T00:00:00.000000 2009-05-13T00:00:00.000000
certa-2009-ale-004 Vulnérabilité dans Mozilla Firefox 2009-03-27T00:00:00.000000 2009-03-30T00:00:00.000000
certa-2009-ale-003 Vulnérabilité dans Apple Mac OS X 2009-03-24T00:00:00.000000 2009-06-02T00:00:00.000000
certa-2009-ale-002 Vulnérabilité dans Microsoft Excel 2009-02-25T00:00:00.000000 2009-04-15T00:00:00.000000
certa-2009-ale-001 Vulnérabilité dans l'interprétation JBIG2 des produits Adobe 2009-02-20T00:00:00.000000 2009-03-20T00:00:00.000000
certa-2008-ale-017 Vulnérabilité dans Microsoft SQL Server 2008-12-12T00:00:00.000000 2009-02-11T00:00:00.000000
certa-2008-ale-016 Vulnérabilité dans Microsoft Internet Explorer 2008-12-10T00:00:00.000000 2008-12-17T00:00:00.000000
certa-2008-ale-015 Vulnérabilité dans le convertisseur de texte de WordPad 2008-12-10T00:00:00.000000 2009-04-15T00:00:00.000000
certa-2008-ale-014 Vulnérabilité dans Opera 2008-11-20T00:00:00.000000 2009-01-06T00:00:00.000000
certa-2008-ale-013 Vulnérabilité du service sadmind de Sun Solaris 2008-10-17T00:00:00.000000 2013-02-21T00:00:00.000000
certa-2008-ale-012 Vulnérabilité dans Microsoft Windows 2008-10-10T00:00:00.000000 2009-04-15T00:00:00.000000
certa-2008-ale-011 Vulnérabilité dans Oracle BEA WebLogic Server 2008-07-24T00:00:00.000000 2008-08-08T00:00:00.000000
certa-2008-ale-010 Vulnérabilité dans Microsoft Word 2008-07-09T00:00:00.000000 2008-08-13T00:00:00.000000
certa-2008-ale-009 Vulnérabilité dans Microsoft Access Snapshot Viewer 2008-07-08T00:00:00.000000 2008-08-13T00:00:00.000000
ID Description Published Updated
osv-2025-88 Segv on unknown address in ___interceptor_free 2025-02-02T00:16:16.201801Z 2025-02-02T00:16:16.202130Z
osv-2025-85 Segv on unknown address in ndpi_free_flow_data 2025-02-02T00:13:42.076001Z 2025-02-02T00:13:42.076373Z
osv-2025-84 Segv on unknown address in Flow::processExtraDissectedInformation 2025-02-02T00:12:09.563391Z 2025-02-02T00:12:09.563778Z
osv-2025-81 Segv on unknown address in ndpi_serialize_string_string 2025-02-02T00:02:52.946833Z 2025-02-02T00:02:52.947083Z
osv-2025-80 Segv on unknown address in ndpi_snprintf 2025-02-02T00:00:58.798346Z 2025-02-02T00:00:58.798951Z
osv-2025-74 Stack-buffer-overflow in xmlValidateElementContent 2025-01-29T00:13:55.386256Z 2025-01-29T00:13:55.386629Z
osv-2024-1427 Heap-buffer-overflow in extract_mediaip 2025-01-28T00:14:30.487391Z 2025-03-18T00:41:33.426387Z
osv-2025-68 UNKNOWN READ in std::__1::__function::__func<cv::PngDecoder::compose_frame 2025-01-28T00:00:46.845996Z 2025-02-05T14:25:02.989469Z
osv-2025-63 Stack-buffer-underflow in gs_type1_interpret 2025-01-27T00:10:00.833706Z 2025-01-27T00:10:00.834151Z
osv-2025-62 UNKNOWN READ in RDKit::Dict::reset 2025-01-27T00:01:51.692636Z 2026-01-30T14:29:51.817835Z
osv-2025-61 Heap-buffer-overflow in oatpp::json::Utils::escapeString 2025-01-27T00:00:09.905879Z 2025-01-27T00:00:09.906561Z
osv-2024-1424 Heap-buffer-overflow in extract_candidate 2025-01-25T00:17:13.787335Z 2025-01-25T14:25:05.188301Z
osv-2024-1423 Security exception in java.base/java.util.Arrays.copyOfRange 2025-01-25T00:03:24.362190Z 2025-01-25T00:03:24.362579Z
osv-2025-54 UNKNOWN READ in Assimp::SceneCombiner::CopyScene 2025-01-22T00:15:23.827419Z 2025-03-18T00:29:47.108675Z
osv-2025-52 Use-of-uninitialized-value in icalmemory_strdup 2025-01-22T00:07:34.573371Z 2025-01-22T00:07:34.573823Z
osv-2025-51 Heap-buffer-overflow in std::__1::__function::__func<cv::PngDecoder::compose_frame 2025-01-22T00:03:50.355443Z 2025-01-24T14:26:07.849301Z
osv-2025-50 Heap-double-free in r_crbtree_free 2025-01-20T00:16:43.389094Z 2025-01-20T00:16:43.389604Z
osv-2025-45 Security exception in POIHDGFFuzzer 2025-01-19T00:14:10.746839Z 2025-01-19T00:14:10.747322Z
osv-2025-42 Heap-use-after-free in r_list_free 2025-01-19T00:06:58.533546Z 2025-01-19T00:06:58.534017Z
osv-2025-33 UNKNOWN READ in pcpp::RawPacket::insertData 2025-01-16T00:01:14.786268Z 2025-10-22T18:25:08.281167Z
osv-2025-32 UNKNOWN READ in std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<ch 2025-01-16T00:01:09.535772Z 2025-01-16T00:01:09.536403Z
osv-2025-31 Heap-buffer-overflow in Assimp::FBXExporter::WriteObjects 2025-01-15T00:14:05.357161Z 2025-05-17T14:21:13.704657Z
osv-2025-17 Heap-buffer-overflow in cv::PngDecoder::readHeader 2025-01-08T00:14:02.009521Z 2025-01-08T00:14:02.009997Z
osv-2025-16 UNKNOWN READ in png_free_data 2025-01-08T00:13:45.160139Z 2025-01-08T00:13:45.160518Z
osv-2025-13 Security exception in com.puppycrawl.tools.checkstyle.grammar.java.JavaLanguageParser.expr 2025-01-07T00:15:11.722974Z 2025-01-07T00:15:11.723402Z
osv-2025-7 Heap-buffer-overflow in oatpp::json::Utils::escapeUtf8Char 2025-01-07T00:03:42.053605Z 2025-01-07T00:03:42.054132Z
osv-2025-6 Heap-buffer-overflow in next_marker 2025-01-06T00:16:10.036783Z 2025-01-06T00:16:10.037219Z
osv-2025-4 Heap-buffer-overflow in ___interceptor_pthread_create 2025-01-05T00:17:02.263743Z 2025-01-05T00:17:02.264158Z
osv-2025-3 Heap-buffer-overflow in avifImageAddUUIDProperty 2025-01-05T00:10:22.871565Z 2025-01-05T00:10:22.872062Z
osv-2025-1 Segv on unknown address in avif_fuzztest_properties@PropertiesAvifFuzzTest.PropsValid 2025-01-04T00:00:30.888504Z 2025-01-04T00:00:30.889140Z
ID Description Published Updated
rustsec-2024-0357 `MemBio::get_buf` has undefined behavior with empty buffers 2024-07-21T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0405 op_panic in the base runtime can force a panic in the runtime's containing thread 2024-07-18T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0403 op_panic in the base runtime can force a panic in the runtime's containing thread 2024-07-18T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0393 Ambiguous challenge derivation 2024-07-18T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0392 Ambiguous challenge derivation 2024-07-18T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0391 Ambiguous challenge derivation 2024-07-18T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0356 `UserIdentity::is_verified` not checking verification status of own user identity while performing the check 2024-07-18T12:00:00Z 2024-07-19T10:11:38Z
rustsec-2024-0355 gix-path can use a fake program files location 2024-07-18T12:00:00Z 2024-07-18T16:46:06Z
rustsec-2024-0354 Usage of non-constant time base64 decoder could lead to leakage of secret key material 2024-07-17T12:00:00Z 2024-07-18T11:24:58Z
rustsec-2024-0369 phonenumber: panic on parsing crafted phonenumber inputs 2024-07-07T12:00:00Z 2024-09-05T13:40:37Z
rustsec-2024-0442 Dump Undefined Memory by `JitDumpFile` 2024-07-06T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0389 `openslide` is unmaintained 2024-07-03T12:00:00Z 2024-11-10T13:42:14Z
rustsec-2024-0387 `opentelemetry_api` has been merged into the `opentelemetry` crate 2024-07-03T12:00:00Z 2024-11-10T13:29:25Z
rustsec-2024-0347 Incorrect usage of `#[repr(packed)]` 2024-07-01T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0346 Incorrect usage of `#[repr(packed)]` 2024-07-01T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0388 `derivative` is unmaintained; consider using an alternative 2024-06-26T12:00:00Z 2024-11-10T13:34:40Z
rustsec-2024-0345 Low severity (DoS) vulnerability in sequoia-openpgp 2024-06-26T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0395 The maintainer of chrono-english is unresponsive 2024-06-24T12:00:00Z 2024-11-10T20:38:56Z
rustsec-2024-0344 Timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub` 2024-06-18T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0394 mmap unmaintained 2024-06-10T12:00:00Z 2024-11-10T14:06:58Z
rustsec-2024-0343 Reduced entropy due to inadequate character set usage 2024-06-03T12:00:00Z 2024-06-15T13:11:33Z
rustsec-2024-0353 Refs and paths with reserved Windows device names access the devices 2024-05-22T12:00:00Z 2024-07-08T15:14:36Z
rustsec-2024-0352 Refs and paths with reserved Windows device names access the devices 2024-05-22T12:00:00Z 2024-07-08T15:14:36Z
rustsec-2024-0351 Refs and paths with reserved Windows device names access the devices 2024-05-22T12:00:00Z 2024-07-08T15:14:36Z
rustsec-2024-0350 Traversal outside working tree enables arbitrary code execution 2024-05-22T12:00:00Z 2024-07-08T15:12:43Z
rustsec-2024-0349 Traversal outside working tree enables arbitrary code execution 2024-05-22T12:00:00Z 2024-07-08T15:12:43Z
rustsec-2024-0348 Traversal outside working tree enables arbitrary code execution 2024-05-22T12:00:00Z 2024-07-08T15:12:43Z
rustsec-2024-0406 BTreeMap memory leak when deallocating nodes with overflows 2024-05-17T12:00:00Z 2024-12-04T12:44:24Z
rustsec-2024-0340 Tor path lengths too short when "full Vanguards" configured 2024-05-15T12:00:00Z 2025-10-28T06:02:18Z
rustsec-2024-0339 Tor path lengths too short when "Vanguards lite" configured 2024-05-15T12:00:00Z 2024-05-21T02:12:32Z
ID Description Published Updated
alsa-2025:23062 Moderate: ruby:3.3 security update 2025-12-10T00:00:00Z 2026-01-05T20:45:40Z
alsa-2025:23052 Important: tomcat9 security update 2025-12-10T00:00:00Z 2025-12-17T11:36:41Z
alsa-2025:23050 Important: tomcat security update 2025-12-10T00:00:00Z 2025-12-17T11:40:04Z
alsa-2025:23049 Important: tomcat security update 2025-12-10T00:00:00Z 2025-12-17T11:42:14Z
alsa-2025:23048 Important: tomcat security update 2025-12-10T00:00:00Z 2025-12-11T14:01:21Z
alsa-2025:23035 Important: firefox security update 2025-12-10T00:00:00Z 2025-12-12T10:16:15Z
alsa-2025:23034 Important: firefox security update 2025-12-10T00:00:00Z 2025-12-12T10:14:54Z
alsa-2025:23008 Moderate: mysql8.4 security update 2025-12-10T00:00:00Z 2025-12-12T10:13:50Z
alsa-2025:22865 Moderate: kernel security update 2025-12-08T00:00:00Z 2025-12-17T11:46:25Z
alsa-2025:22854 Moderate: kernel security update 2025-12-08T00:00:00Z 2025-12-10T08:12:35Z
alsa-2025:22801 Moderate: kernel security update 2025-12-08T00:00:00Z 2025-12-08T13:53:19Z
alsa-2025:22800 Moderate: kernel-rt security update 2025-12-08T00:00:00Z 2025-12-08T13:58:04Z
alsa-2025:22790 Important: webkit2gtk3 security update 2025-12-08T00:00:00Z 2025-12-08T14:01:28Z
alsa-2025:22789 Important: webkit2gtk3 security update 2025-12-08T00:00:00Z 2025-12-08T13:59:43Z
alsa-2025:22760 Important: abrt security update 2025-12-04T00:00:00Z 2025-12-10T10:40:28Z
alsa-2025:22668 Moderate: go-toolset:rhel8 security update 2025-12-03T00:00:00Z 2025-12-05T08:01:54Z
alsa-2025:22660 Moderate: systemd security update 2025-12-03T00:00:00Z 2025-12-04T13:25:23Z
alsa-2025:22417 Important: gimp:2.8 security update 2025-12-01T00:00:00Z 2025-12-04T13:28:20Z
alsa-2025:22405 Moderate: kernel security update 2025-12-01T00:00:00Z 2025-12-08T12:22:10Z
alsa-2025:22395 Moderate: kernel security update 2025-12-01T00:00:00Z 2025-12-15T12:44:56Z
alsa-2025:22394 Moderate: qt6-qtsvg security update 2025-12-01T00:00:00Z 2025-12-05T07:42:49Z
alsa-2025:22388 Moderate: kernel security update 2025-12-01T00:00:00Z 2025-12-03T11:59:02Z
alsa-2025:22387 Moderate: kernel-rt security update 2025-12-01T00:00:00Z 2025-12-03T12:01:56Z
alsa-2025:22376 Moderate: libxml2 security update 2025-12-01T00:00:00Z 2025-12-03T12:03:31Z
alsa-2025:22363 Important: firefox security update 2025-12-01T00:00:00Z 2025-12-03T12:05:25Z
alsa-2025:22361 Moderate: qt6-qtquick3d security update 2025-12-01T00:00:00Z 2025-12-05T07:43:58Z
alsa-2025:22175 Important: expat security update 2025-11-26T00:00:00Z 2025-12-03T12:07:34Z
alsa-2025:22063 Moderate: cups security update 2025-11-25T00:00:00Z 2025-11-28T13:48:35Z
alsa-2025:22012 Important: buildah security update 2025-11-25T00:00:00Z 2025-12-05T07:44:58Z
alsa-2025:22011 Important: buildah security update 2025-11-25T00:00:00Z 2025-11-25T12:06:57Z