|
2026-08-11 |
2026-08-11 |
2026-08-11 |
VU#431093 |
TCG TPM 2.0 reference code found vulnerable to information leakage and
timing side-channel attacks |
|
2026-08-10 |
2026-08-10 |
2026-08-10 |
VU#614868 |
Opencart ecommerce platform contains directory traversal vulnerability |
|
2026-08-07 |
2026-08-07 |
2026-08-07 |
VU#987105 |
The nothings stb TrueType library, up to version 1.26, contains a heap
buffer overflow vulnerability |
|
2026-08-06 |
2026-08-06 |
2026-08-06 |
VU#487613 |
Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS
calendar invitations |
|
2026-07-31 |
2026-07-31 |
2026-07-31 |
VU#243636 |
VPS.org one-click deployment templates contain multiple vulnerabilities |
|
2026-07-30 |
2026-07-30 |
2026-07-30 |
VU#281278 |
SGLang contains six different vulnerabilities including RCE, data
exfiltration, and credential disclosure |
|
2026-07-30 |
2026-07-30 |
2026-07-30 |
VU#790363 |
foreUP golf management platform's web API contains multiple vulnerabilities |
|
2026-07-29 |
2026-07-29 |
2026-07-29 |
VU#293714 |
Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink
Following on macOS (APFS) |
|
2026-07-29 |
2026-07-29 |
2026-07-29 |
VU#305509 |
OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure |
|
2026-07-28 |
2026-07-28 |
2026-07-28 |
VU#141367 |
AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability
in LAN-side management interface |
|
2026-07-23 |
2026-07-23 |
2026-07-23 |
VU#492466 |
Logto Identity Platform has authentication and authorization failures in
core protocol handling |
|
2026-07-22 |
2026-07-22 |
2026-07-22 |
VU#847406 |
Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission
assignment vulnerability |
|
2026-07-22 |
2026-07-22 |
2026-07-22 |
VU#360868 |
Analog Way Picturall Quad Compact Mark II contains a local privilege
escalation vulnerability |
|
2026-07-21 |
2026-07-21 |
2026-07-21 |
VU#762226 |
Plane contains multi-tenant authorization bypass vulnerability |
|
2026-07-16 |
2026-07-16 |
2026-07-17 |
VU#885548 |
Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control
conditions |
|
2026-07-16 |
2026-07-16 |
2026-07-16 |
VU#326070 |
SGLang contains a vulnerable pickle deserialization vulnerability through
the expert-parallel subsystem |
|
2026-07-15 |
2026-07-15 |
2026-07-15 |
VU#529388 |
Privilege escalation vulnerability via unprotected IOCTL interface in
Pegatron Tdelo64.sys |
|
2026-07-15 |
2026-07-15 |
2026-07-15 |
VU#725167 |
node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519
Implementations |
|
2026-07-10 |
2026-07-10 |
2026-07-10 |
VU#564823 |
GNU Wget enables SSRF via unvalidated FTP PASV IPs |
|
2026-07-09 |
2026-07-09 |
2026-07-09 |
VU#152953 |
PayRange Android app version 7.0.7 contains multiple vulnerabilities |
|
2026-07-09 |
2026-07-09 |
2026-07-09 |
VU#734812 |
Xerte Online Toolkit contains an authentication bypass that allows for RCE |
|
2026-07-08 |
2026-07-08 |
2026-07-08 |
VU#849433 |
Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching
and Missing Authorization Controls |
|
2026-07-06 |
2026-07-06 |
2026-07-06 |
VU#213560 |
Tenda firmware (multiple versions) contains hidden authentication backdoor |
|
2026-07-06 |
2026-07-06 |
2026-07-06 |
VU#828543 |
HP Deskjet 2800 Printer Series Webservers contain Missing Authorization
Vulnerability |
|
2026-07-02 |
2026-07-02 |
2026-07-02 |
VU#639124 |
Multiple local privilege escalation vulnerabilities in Little
Orbits GameFirst Anti-Cheat |
|
2026-06-22 |
2026-06-22 |
2026-06-22 |
VU#936962 |
Multiple file parsing vulnerabilities in FastStone Image Viewer 8.3.0.0 |
|
2026-06-22 |
2026-06-22 |
2026-06-22 |
VU#226679 |
Microsoft WinRE allows for bypass of UEFI/BIOS password enforcement |
|
2026-06-18 |
2026-06-18 |
2026-06-18 |
VU#457458 |
Vendor-signed UEFI applications found vulnerable to Secure Boot bypass |
|
2026-06-17 |
2026-06-17 |
2026-06-17 |
VU#380058 |
SignalRGB kernel driver contains improper access control and IOCTL
vulnerabilities |
|
2026-06-11 |
2026-06-11 |
2026-06-11 |
VU#862559 |
crypton-x509-validation Haskell libraries do not enforce X.509
NameConstraints |
|
2026-06-09 |
2026-06-09 |
2026-06-10 |
VU#616257 |
Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypass |
|
2026-06-03 |
2026-06-03 |
2026-06-03 |
VU#595768 |
Securly Chrome Extension contains multiple weak encryption and access
control vulnerabilities |
|
2026-06-02 |
2026-06-02 |
2026-06-02 |
|
Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE
Deployments |
|
2026-06-02 |
2026-06-02 |
2026-06-02 |
|
Appsmiths SQL Query autocomplete renderer contains a cross site scripting
vulnerability |
|
2026-06-02 |
2026-06-02 |
2026-06-02 |
|
Collibra Agent contains improper authentication and path traversal
vulnerabilities |
|
2026-06-01 |
2026-06-01 |
2026-06-01 |
|
PCTCore64.sys Windows kernel driver contains missing access control
vulnerability |
|
2026-05-28 |
2026-05-28 |
2026-05-28 |
VU#780781 |
Casdoor contains multiple authentication bypass and access management
vulnerabilities |
|
2026-05-20 |
2026-05-20 |
2026-05-20 |
VU#980487 |
Local privilege escalation in Linux Kernel (Dirty Frag) |
|
2026-05-18 |
2026-05-18 |
2026-05-18 |
VU#777338 |
SGLang contains two remote code execution and one path traversal
vulnerability |
|
2026-05-11 |
2026-05-11 |
2026-05-11 |
VU#471747 |
dnsmasq contains several vulnerabilities, including attacker DNS redirect,
privilege escalation, and heap manipulation |
|
2026-05-11 |
2026-05-11 |
2026-05-11 |
VU#937808 |
Casdoor contains Arbitrary File Write vulnerability |
|
2026-05-08 |
2026-05-08 |
2026-05-08 |
VU#260001 |
Linux kernel contains local privilege escalation vulnerability (Copy Fail) |
|
2026-04-23 |
2026-04-23 |
2026-04-23 |
VU#748485 |
Unauthenticated configuration modification vulnerability in Central Office
Services - Content Hosting Component |
|
2026-04-22 |
2026-04-22 |
2026-04-22 |
VU#518910 |
Ollama GGUF Quantization Remote Memory Leak |
|
2026-04-21 |
2026-04-21 |
2026-04-21 |
VU#890999 |
Radware Alteon has a reflected XSS vulnerability that can execute JavaScript
in the host browser |
|
2026-04-21 |
2026-04-21 |
2026-04-21 |
VU#414811 |
Terrarium contains a vulnerability that allows arbitrary code execution |
|
2026-04-20 |
2026-04-20 |
2026-04-20 |
VU#915947 |
SGLang is vulnerable to remote code execution when rendering chat templates
from a model file |
|
2026-04-09 |
2026-04-09 |
2026-04-09 |
VU#536588 |
Multiple Heap Buffer Overflows in Orthanc DICOM Server |
|
2026-04-02 |
2026-04-02 |
2026-04-02 |
VU#951662 |
MuPDF by Artifex contains integer overflow vulnerability. |
|
2026-03-30 |
2026-03-30 |
2026-03-30 |
VU#655822 |
Kyverno is vulnerable to server-side request forgery (SSRF) |
|
2026-03-30 |
2026-03-26 |
2026-03-26 |
VU#221883 |
CrewAI contains multiple vulnerabilities including SSRF, RCE and local file
read |
|
2026-03-24 |
2026-03-24 |
2026-03-24 |
VU#330121 |
IDrive for Windows contains local privilege escalation vulnerability |
|
2026-03-24 |
2026-03-24 |
2026-03-24 |
VU#577436 |
Hard coded credentials vulnerability in GoHarbor's Harbor |
|
2026-03-16 |
2026-03-16 |
2026-03-16 |
VU#624941 |
LibreChat RAG API contains a log-injection vulnerability |
|
2026-03-12 |
2026-03-12 |
2026-03-12 |
VU#907705 |
Graphql-upload-minimal has a prototype pollution vulnerability. |
|
2026-03-09 |
2004-12-10 |
2026-03-09 |
VU#976247 |
Antivirus and Endpoint Detection and Response Archive Scanning Engines may
not properly scan malformed zip archives |
|
2026-03-05 |
2026-02-18 |
2026-03-05 |
VU#772695 |
A flawed TLS handshake implementation affects Viber Proxy in multiple
platforms |
|
2026-03-02 |
2026-03-02 |
2026-03-02 |
VU#431821 |
MS-Agent does not properly sanitize commands sent to its shell tool,
allowing for RCE |
|
2026-02-12 |
2026-02-12 |
2026-02-12 |
VU#504749 |
PyMuPDF path traversal and arbitrary file write vulnerabilities |
|
2026-02-10 |
2026-02-10 |
2026-02-10 |
VU#458422 |
CASL Ability contains a prototype pollution vulnerability |
|
2026-01-20 |
2026-01-20 |
2026-01-21 |
VU#481830 |
Libheif uncompressed codec lacks bounds check leading to application crash |
|
2026-01-20 |
2026-01-20 |
2026-01-21 |
VU#102648 |
Code injection vulnerability in binary-parser library |
|
2026-01-20 |
2026-01-20 |
2026-01-20 |
VU#458022 |
Open5GS WebUI uses a hard-coded secrets including JSON Web Token signing key |
|
2026-01-20 |
2026-01-20 |
2026-01-20 |
VU#271649 |
Stack-based buffer overflow in libtasn1 versions v4.20.0 and earlier |
|
2026-01-20 |
2026-01-20 |
2026-01-20 |
VU#818729 |
Safetica contains a kernel driver vulnerability |
|
2026-01-20 |
2026-01-20 |
2026-01-20 |
VU#244846 |
Server-Side Template Injection (SSTI) vulnerability exist in Genshi |
|
2026-01-20 |
2026-01-20 |
2026-01-20 |
VU#924114 |
dr_flac contains an integer overflow vulnerability that allows for DoS when
provided a crafted file |
|
2026-01-16 |
2026-01-16 |
2026-01-16 |
VU#383552 |
thelibrarian does not secure its interface, allowing for access to internal
system data |
|
2026-01-16 |
2026-01-16 |
2026-01-16 |
VU#650657 |
Livewire Filemanager contains an insecure .php component that allows for
unauthenticated RCE in Laravel Products |
|
2026-01-15 |
2026-01-15 |
2026-01-15 |
VU#472136 |
Information Leak and DoS Vulnerabilities in Redmi Buds 3 Pro through 6 Pro |
|
2026-01-09 |
2026-01-09 |
2026-01-09 |
VU#361400 |
BeeS Software Solutions BeeS Examination Tool (BET) portal contains SQL
injection vulnerability |
|
2026-01-06 |
2026-01-06 |
2026-01-06 |
VU#295169 |
TOTOLINK EX200 firmware-upload error handling can activate an
unauthenticated root telnet service |
|
2026-01-06 |
2026-01-06 |
2026-01-06 |
VU#420440 |
Vulnerable Python version used in Forcepoint One DLP Client |