Voici la liste des derniers avis du CERT-Renater en 2026 :


18 Mar 2026VULN315Google Chrome : Chrome 146.0.7680.80 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 146.0.7680.80.
18 Mar 2026VULN314Ubuntu : Snapd - Local Privilege Escalation (CVE-2026-3888)Systems running Snapd.
18 Mar 2026VULN313Next.js : Multiple security vulnerabities fixed in Next.jsSystems running Next.js versions prior to 16.1.7, 15.5.13.
18 Mar 2026VULN312Apache : CVE-2025-54920 Apache Spark Spark History Server Code Execution VulnerabilitySystems running Spark versions prior to 3.5.7, 4.0.1.
18 Mar 2026VULN311libexpat : libexpat 2.7.5 fixes multiple security vulnerabilitiesSystems running libexpat versions prior to 2.7.5.
18 Mar 2026VULN310Apache : Multiple vulnerabilities fixed in Apache AirflowSystems running Apache Airflow versions prior to 3.1.8.
18 Mar 2026VULN309Kubernetes : CVE-2026-3864 CSI Driver for NFS path traversal via subDir may delete unintended directoriesSystems running CSI Driver for NFS versions prior to 4.13.1.
17 Mar 2026VULN308OpenSSL : OpenSSL TLS 1.3 server may choose unexpected key agreement group (CVE-2026-2673)Systems running OpenSSL versions prior to 3.6.2, 3.5.6.
17 Mar 2026VULN307Python : Stack overflow and Incomplete control character validation vulnerabilitiesSystems running CPython.
17 Mar 2026VULN306Spring : JSONPath Injection and SQL Injection in Spring AISystems running Spring AI versions prior to 1.0.4, 1.1.3.
17 Mar 2026VULN305Xen : Use after free and Xenstored DoS vulnerabitiesSystems running Xen.
16 Mar 2026VULN304Fabrik : Fabrik 4.6.3 Security ReleaseSystems running Fabrik versions prior to 4.6.3.
13 Mar 2026VULN303Vim : NFA regex engine NULL pointer dereference affects Vim < 9.2.0137Systems running Vim versions prior to 9.2.0137.
13 Mar 2026VULN302Apache : Apache Livy Unauthorized directory access and Restrict file access vulnerabilitiesSystems running Apache Livy versions prior to 0.9.0.
13 Mar 2026VULN301Broadcom : Multiple security vulnerabilities fixed in VMware Tanzu for ValkeySystems running VMware Tanzu for Valkey products.
13 Mar 2026VULN300Splunk : Multiple security vulnerabilities fixed in Splunk productsSystems running Splunk AppDynamics products, Splunk Enterprise versions prior to 10.2.1, 10.0.4, 9.4.9, 9.3.10, Splunk Cloud Platform versions prior to 10.2.2510.7, 10.1.2507.17, 10.0.2503.12, 9.3.2411.124, Splunk Observability Cloud app for Splunk Enterprise versions prior to 10.2.2510.5, 10.1.2507.16, 10.0.2503.12.
12 Mar 2026VULN299Cisco : Cisco Security Advisories Published on March 11, 2026Cisco IOS XR, Systems running Cisco Contact Center Products.
12 Mar 2026VULN298Veeam : Critical Security vulnerabilities fixed in Veeam Backup & ReplicationSystems running Veeam Backup & Replication versions prior to 12.3.2.4465, 13.0.1.2067.
12 Mar 2026VULN297glpi : Remote Code Execution via malicious uploadSystems running glpi (glpi) versions prior to 11.0.5.
12 Mar 2026VULN296GitLab : GitLab Patch Release 18.9.2, 18.8.6, 18.7.6Systems running GitLab versions prior to 18.9.2, 18.8.6, 18.7.6.
12 Mar 2026VULN295Adobe : Security Updates Available for Adobe Illustrator APSB26-18Systems running Adobe Illustrator versions prior to 29.8.5, 30.2.
12 Mar 2026VULN294Adobe : Security update available for Adobe Acrobat Reader APSB26-26Systems running Adobe Acrobat, Acrobat Reader versions prior to 25.001.21288, Acrobat versions prior to 24.001.30356.
12 Mar 2026VULN293Ivanti : Security Advisory Ivanti DSM (CVE-2026-3483)Systems running Ivanti Desktop and Server Management (DSM) versions prior to 2026.1.1.
12 Mar 2026VULN292Argo Workflows : WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference ModeSystems running argo-workflows (Go) versions prior to 4.0.2, 3.7.11.
12 Mar 2026VULN291GLIBC : nscd client crash on x86_64 under high nscd loadSystems running GNU C Library versions prior to 2.36.
12 Mar 2026VULN290Fortinet : Buffer overflow via fgtupdates serviceSystems running FortiManager versions prior to 7.4.3, 7.2.11.
11 Mar 2026VULN289Fortinet : Security Vulnerabilities fixed in FortiSwitchAXFixedSystems running FortiSwitchAXFixed versions prior to 1.0.2.
11 Mar 2026VULN288HPE : HPE Aruba Networking AOS-CX, Multiple VulnerabilitiesHPE Aruba Networking AOS-CX Software versions prior to 10.17.1001, 10.16.1030, 10.13.1161, 10.10.1180.
11 Mar 2026VULN287WordPress : WordPress 6.9.2 fixes multiple security vulnerabilitiesSystems running WordPress versions prior to 6.9.2.
11 Mar 2026VULN286Traefik : Multiple Security Vulnerabilities fixed in TraefikSystems running Traefik (Go) versions prior to 2.11.40, 3.6.10.
11 Mar 2026VULN285curl : Multiple Security Vulnerabilities fixed in curl 8.19.0Systems running curl versions prior to 8.19.0.
10 Mar 2026VULN284Mozilla : Security Vulnerabilities fixed in Focus for iOS 148.2Systems running Mozilla Focus for iOS versions prior to 148.2.
10 Mar 2026VULN283SAP : SAP Security Patch Day - March 2026Systems running SAP products.
10 Mar 2026VULN282Apache : CVE-2026-23907 Path Traversal in PDFBox ExtractEmbeddedFiles Example CodeSystems running Apache PDFBox versions 2.0.24, 3.0.0 up to and including 2.0.36, 3.0.7.
10 Mar 2026VULN281Apache : CVE-2026-25604 Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication BypassSystems running Apache Airflow AWS Auth Manager versions prior to 9.22.0.
10 Mar 2026VULN280Kubernetes : CVE-2026-3288 ingress-nginx rewrite-target nginx configuration injectionSystems running ingress-nginx versions prior to 1.13.8, 1.14.4, 1.15.0.
10 Mar 2026VULN279Apereo CAS : CAS JWT Authentication Vulnerability DisclosureSystems running Apereo CAS versions prior to 7.2.7.1, 7.3.5.
10 Mar 2026VULN278Rocket.Chat : Critical and high severity vulnerabilities fixed in Rocket.ChatSystems running Rocket.Chat versions prior to 8.0.0, 7.13.3, 7.12.4, 7.11.4, 7.10.7, 7.9.8, 7.8.6.
10 Mar 2026VULN277pac4j : Security advisory for pac4j-jwt (JwtAuthenticator) CVE-2026-29000 critical Authentication BypassSystems running pac4j-jwt versions prior to 4.5.9, 5.7.9, 6.3.3.
10 Mar 2026VULN276ZITADEL : 1-Click Account Takeover via XSS in /saml-post EndpointSystems running ZITADEL versions prior to 4.12.0.
10 Mar 2026VULN275vLLM : SSRF Protection Bypass in vLLMSystems running vllm (pip) versions prior to 0.17.0.
9 Mar 2026VULN274Flowise : Multiple high severity vulnerabilities fixed in FlowiseSystems running Flowise (npm) versions prior to 3.0.13.
9 Mar 2026VULN273GitHub Copilot : GitHub Copilot CLI Dangerous Shell Expansion Patterns Enable Arbitrary Code ExecutionSystems running GitHub Copilot versions prior to 0.0.423.
9 Mar 2026VULN272GnuPG : New versions of GnuPG, Gpg4win fix critical security bugSystems running GnuPG versions prior to 2.5.17, Gpg4win versions prior to 5.0.1.
9 Mar 2026VULN271Apache : Multiple vulnerabilities fixed in Apache IoTDBSystems running Apache IoTDB versions prior to 1.3.6, 2.0.6.
9 Mar 2026VULN270Apache : Unsafe Pickle Deserialization in apache-airflow-providers-http leading to RCE via HttpOperatorSystems running Apache Airflow Providers Http versions prior to 6.0.0.
9 Mar 2026VULN269Apache : Apache ZooKeeper Sensitive information disclosure and server impersonation vulnerabilitiesSystems running Apache ZooKeeper versions prior to 3.8.6, 3.9.5.
6 Mar 2026VULN268Nextcloud : Remote code execution in Nextcloud Flow via vulnerable Windmill versionSystems running Flow (Nextcloud) versions prior to 1.3.0.
6 Mar 2026VULN267Zabbix : Unauthorized host creation via configuration.import API (CVE-2026-23925)Systems running Zabbix versions prior to 6.0.41, 7.0.18, 7.4.2.
6 Mar 2026VULN266SPIP : Mise à jour de sécurité sortie de SPIP 4.4.13Systems running SPIP versions prior to 4.4.13.
6 Mar 2026VULN265PJSIP : Heap use-after-free in PJSIP presence subscription termination handlerSystems running pjsip presence versions prior to 2.17.
6 Mar 2026VULN264PJSIP : Stack buffer overflow in in pjmedia-codec frameworkSystems running pjmedia-codec versions prior to 2.17.
6 Mar 2026VULN263CPAN Security Group : Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session idSystems running Apache::Session::Generate::MD5 versions prior to 1.94.
6 Mar 2026VULN262CPAN Security Group : Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlibSystems running Compress::Raw::Zlib versions prior to 2.220.
6 Mar 2026VULN261Go : Go 1.26.1 and Go 1.25.8 are releasedSystems running Go versions prior to 1.26.1, 1.25.8.
5 Mar 2026VULN260Google Chrome : Chrome 145.0.7632.159/160 fixes Critical and high-severity security vulnerabilitiesSystems running Chrome versions prior to 145.0.7632.159/160.
5 Mar 2026VULN259node-tar : Hardlink Path Traversal via Drive-Relative LinkpathSystems running tar (npm) versions prior to 7.5.10.
5 Mar 2026VULN258pyload-ng : Arbitrary File Write via Path Traversal in edit_package()Systems running pyload-ng (pip) versions prior to 0.5.0b3.dev97.
5 Mar 2026VULN257Docker : CLI plugins uncontrolled search path element local privilege escalation on WindowsSystems running Docker CLI versions prior to 29.2.0.
4 Mar 2026VULN256Cisco : Cisco Security Advisories Published on March 04, 2026Systems running Cisco products.
4 Mar 2026VULN255HPE : Multiple Vulnerabilities in HPE Aruba Networking Wireless Operating Systems (AOS-8 and AOS-10) for Mobility Conductors, Controllers, Gateways, and Access PointsAOS-10 versions prior to 10.8.0.1, 10.7.2.3, 10.4.1.11, AOS-8 versions prior to 8.13.1.2, 8.12.0.7, 8.10.0.22.
4 Mar 2026VULN254IBM : Vulnerabilities in MongoDB Server might affect IBM Storage Defender Copy Data ManagementSystems running IBM Storage Defender Copy Data Management versions 2.2.0.0 up to and including 2.2.28.0.
4 Mar 2026VULN253IBM : Multiple Vulnerabilities in IBM DevOps BuildSystems running IBM DevOps Build versions prior to 7.1.0.2.
4 Mar 2026VULN252AWS : Issue with AWS-LC an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338)Systems running AWS-LC versions prior to 1.69.0, aws-lc-sys versions prior to 0.38.0, AWS-LC-FIPS versions prior to 3.2.0, aws-lc-sys-fips versions prior to 0.13.12.
4 Mar 2026VULN251HPE : HPE AutoPass License Server (APLS), Remote Authentication Bypass VulnerabilitySystems running HPE AutoPass License Server versions prior to 9.19.
4 Mar 2026VULN250Apache : Apache Artemis, Apache ActiveMQ Artemis Auth bypass for Core downstream federationSystems running Apache Artemis versions prior to 2.52.0, Apache ActiveMQ Artemis.
4 Mar 2026VULN249Apache : Apache ActiveMQ MQTT control packet remaining length field is not properly validatedSystems running Apache ActiveMQ versions prior to 5.19.2, 6.1.9, 6.2.1.
4 Mar 2026VULN248Openstack : Remote code execution through Vitrage query parserSystems running Openstack Vitrage versions <12.0.1, ==13.0.0, ==14.0.0, ==15.0.0.
3 Mar 2026VULN247Django : Django security releases issued 6.0.3, 5.2.12, and 4.2.29Systems running Django versions prior to 6.0.3, 5.2.12, and 4.2.29.
3 Mar 2026VULN246OpenSSF : Active Exploitation of Weak GitHub Actions ConfigurationsSystems running GitHub Actions.
3 Mar 2026VULN245qwik : Unauthenticated RCE via server$ DeserializationSystems running qwik (npm) versions prior to 1.19.1.
2 Mar 2026VULN243jackson-core : Number Length Constraint Bypass in Async Parser Leads to Potential Denial-of-Service (DoS) ConditionSystems running jackson-core (Maven) versions prior to 2.18.6, 2.21.1, 3.1.0.
2 Mar 2026VULN242phpmyfaq : Unauthenticated Account Creation via WebAuthn Prepare EndpointSystems running phpmyfaq (Composer) versions prior to 4.0.18.
2 Mar 2026VULN241Vitess : Critical and high severity Security vulnerabilities fixed in VitessSystems running vitess (Go) versions prior to 22.0.4, 23.0.3.
2 Mar 2026VULN240langflow : Critical Remote Code Execution in CSV AgentSystems running langflow (pypi) versions prior to 1.8.0.
27 Feb 2026VULN239elastic : Multiple Security vulnerabilities fixed in KibanaSystems running Kibana versions prior to 9.3.1, 8.19.12, 9.2.6.
27 Feb 2026VULN238IBM : IBM QRadar SIEM is vulnerable to using components with known vulnerabilitiesSystems running IBM QRadar SIEM versions prior to 7.5.0 UP14 IF05.
27 Feb 2026VULN237Drupal : UI Icons - Critical - Cross-site Scripting - SA-CONTRIB-2026-010Systems running UI Icons for Drupal versions prior to 1.0.1, 1.1.1.
27 Feb 2026VULN236Drupal : SAML SSO - Service Provider - Critical - Cross-site scriptingSystems running SAML SSO - Service Provider for Drupal versions prior to 3.1.3.
27 Feb 2026VULN235Elastic : Synthetics Recorder 1.4.15 Security Update (ESA-2026-16) - CVE-2025-6554 and CVE-2025-7657Systems running Elastic Synthetics Recorder versions prior to 1.4.15.
27 Feb 2026VULN234Google ChromeOS : Multiple security vulnerabilities fixed in Google ChromeOSSystems running ChromeOS / ChromeOS Flex versions prior to 16552.47.0.
27 Feb 2026VULN233koa : Host Header Injection via `ctx.hostname`Systems running koa (npm) versions prior to 3.1.2, 2.16.4.
27 Feb 2026VULN232Juniper : Junos OS Evolved: PTX Series : A vulnerability allows a unauthenticated, network-based attacker to execute code as root (CVE-2026-21902)Junos OS Evolved on PTX Series versions prior to 25.4R1-S1-EVO, 25.4R2-EVO*, 26.2R1-EVO*.
27 Feb 2026VULN231ImageMagick : ImageMagick Multiple security vulnerabilitiesSystems running ImageMagick (C/C++) versions prior to 7.1.2-15, 6.9.13-40, 7.1.2-15.
27 Feb 2026VULN230modelcontextprotocol.io : Improper Handling of Case Sensitivity in github.com/modelcontextprotocol/go-sdkSystems running modelcontextprotocol/go-sdk (Go) versions prior to 1.3.1.
27 Feb 2026VULN229Freescout : Predictable Authentication Token Enables Account TakeoverSystems running freescout (Composer) versions prior to 1.8.206.
27 Feb 2026VULN228n8n : Multiple vulnerabilities, some critical fixedSystems running n8n (npm) versions prior to 2.10.1, 2.9.3, 1.123.22.
26 Feb 2026VULN227rustfs : Critical Stored XSS and Missing Post Policy Validation vulnerabilitiesSystems running rustfs (Rust) versions prior to 1.0.0-alpha.83.
26 Feb 2026VULN226Angular : SSRF and Header Injection and Open Redirect in Angular SSRSystems running @angular/ssr (npm) versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, 19.2.21, @nguniversal/common (npm), @nguniversal/express-engine (npm).
26 Feb 2026VULN225Centreon : CVE-2026-2749 - Centreon Open Tickets - CRITICAL SeveritySystems running Centreon Open Tickets versions prior to 25.10.3, 24.10.8, 24.04.7.
26 Feb 2026VULN224Centreon : vulnerabilitySystems running centreon-web versions prior to 25.10.9, 24.10.21, 24.04.25.
26 Feb 2026VULN223 (SPIP : SPIP 4.4.10 corrige trois failles de sécuritéSystems running SPIP versions prior to 4.4.10.
26 Feb 2026VULN222Postgresql : pgvector 0.8.2 fixes a buffer overflow vulnerabilitySystems running pgvector versions prior to 0.8.2.
26 Feb 2026VULN221terraform-provider-linode : Sensitive Information Exposure in Terraform Provider for Linode Debug LogsSystems running terraform-provider-linode versions prior to 3.9.0.
25 Feb 2026VULN220Docker : Docker Desktop 4.62.0 fix out of bounds read vulnerabilitySystems running Docker Desktop versions prior to 4.62.0.
25 Feb 2026VULN219Cisco : Cisco Security Advisories Published on February 25, 2026Systems running Cisco Catalyst, Cisco Nexus 9000 Series Fabric Switches software, Cisco Nexus 3600 and 9500-R Series Switching Platforms, Cisco NX-OS Software, Cisco FXOS and UCS Manager Software, Cisco UCS Manager Software, Cisco Application Policy Infrastructure Controller.
25 Feb 2026VULN218Mozilla : Security Vulnerabilities fixed in Thunderbird 140.8, 148Systems running Thunderbird versions prior to 140.8, 148.
25 Feb 2026VULN217Mozilla : Security Vulnerabilities fixed in Firefox ESR 140.8, ESR 115.33, 148Systems running Firefox versions prior to ESR 140.8, ESR 115.33, 148.
25 Feb 2026VULN216Synology : Synology-SA-26:02 Synology Presto ClientSystems running Synology versions prior to 2.1.3-0672.
25 Feb 2026VULN215GitLab : GitLab Patch Release 18.9.1, 18.8.5, 18.7.5Systems running GitLab versions prior to 18.9.1, 18.8.5, 18.7.5.
25 Feb 2026VULN214Trendmicro : SECURITY BULLETIN Apex One and Apex One (Mac) - February 2026Systems running Apex One version prior to CP Build 14136, Apex One as a Service, Trend Vision One Endpoint - Standard Endpoint Protection versions prior to Security Agent Build 14.0.20315.
25 Feb 2026VULN213Pimcore : SQL injection via unsanitized filter value in Dependency Dao RLIKE clauseSystems running pimcore (Composer) versions prior to 11.5.15 12.3.3.
25 Feb 2026VULN212Google Chrome : Chrome 145.0.7632.116/117 fixes high-severity security vulnerabilitiesSystems running Chrome versions prior to 145.0.7632.116/117.
25 Feb 2026VULN211Solarwinds : Serv-U 15.5.4 release notes fix critical vulnerabilitiesSystems running Serv-U versions prior to 15.5.4.
24 Feb 2026VULN210Sonicwall : SonicOS multiple post-authentication vulnerabilitiesSonicOS.
24 Feb 2026VULN209Valkey : Multiple vulnerabilities fixed in valkey-serverSystems running valkey-server (valkey-io) versions prior to 9.0.3, 8.1.6, 8.0.7, 7.2.12.
24 Feb 2026VULN208MindsDB : Path Traversal in /api/files Leading to Remote Code ExecutionSystems running MindsDB versions prior to 25.9.1.1.
24 Feb 2026VULN207Broadcom : VMware Aria Operations updates address multiple vulnerabilities (CVE-2026-22719, CVE-2026-22720 and CVE-2026-22721)Systems running VMware Cloud Foundation, VMware vSphere Foundation versions prior to 9.0.2.0, VMware Aria Operations versions prior to 8.18.6, VMware Cloud Foundation versions prior to KB92148, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure versions prior to KB428241.
23 Feb 2026VULN206Apache : Apache Airflow Connection Secrets not masked in UI when Connection are added via Airflow cliSystems running Apache Airflow versions prior to 2.11.1.
23 Feb 2026VULN205Microsoft : Vulnérabilité d’élévation de privilèges dans Windows Admin Center New CVE-2026-26119Systems running Windows Admin Center versions prior to 2.6.4.
23 Feb 2026VULN204IceWarp : IceWarp Security UpdateSystems running IceWarp Epos versions prior to Update 2 14.2.0.12, Update 1 14.1.0.20, 14.0.0.18, Deep Castle versions prior to 13.0.3.13.
23 Feb 2026VULN203Google : Vulnerabilities fixed in Google Vertex AI and SDK Vertex AISystems running Google Vertex AI Experiments versions prior to 1.133.0, Google google-cloud-aiplatform (SDK Vertex AI pour Python) versions prior to 1.131.0.
20 Feb 2026VULN202Splunk : Multiple Vulnerabilities fixed in Splunk Enterprise for WindowsSystems running Splunk Enterprise for Windows versions prior to 10.2.0, 10.0.3, 9.4.8, 9.3.9, 9.2.12.
20 Feb 2026VULN201Splunk : Third-Party Package Updates in Splunk Enterprise - February 2026Systems running Third Party Packages in Splunk Enterprise versions prior to 10.0.3, 9.4.8, 9.3.9, 9.2.12.
20 Feb 2026VULN200Traefik : Critical TLS ClientAuth Bypass on HTTP/3Systems running Traefik (Go) versions prior to 2.11.37, 3.6.8.
20 Feb 2026VULN199deno : Command Injection via Incomplete shell metacharacter blocklist in `node:child_process`Systems running deno versions prior to 2.6.8.
20 Feb 2026VULN198bigbluebutton : Exposed ClamAV port allowing denial of serviceSystems running clamav (bigbluebutton) versions prior to 3.0.22.
19 Feb 2026VULN197Tenable : Security Center Version 6.8.0 Fixes Multiple VulnerabilitiesSystems running Tenable Security Center versions prior to 6.8.0.
19 Feb 2026VULN196Google Chrome : Chrome 145.0.7632.109/110 fixes high-severity security vulnerabilitiesSystems running Google Chrome versions prior to 145.0.7632.109/110.
19 Feb 2026VULN195jspdf : Client-Side/Server-Side Denial of Service via Malicious GIF DimensionsSystems running jspdf (npm) versions prior to 4.2.0.
19 Feb 2026VULN194Jsonpath : jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path ExpressionsSystems running jsonpath (npm).
19 Feb 2026VULN193brace-expansion : Uncontrolled Resource Consumption in @isaacs/brace-expansionSystems running brace-expansion (npm) versions prior to 5.0.1.
18 Feb 2026VULN192SPIP : Mise à jour de sécurité sortie de SPIP 4.4.9Systems running SPIP versions prior to 4.4.9.
18 Feb 2026VULN191Tenable : Stand-alone Security Patches Available for Tenable Security Center versions 6.5.1, 6.6.0 and 6.7.2Systems running Tenable Security Center versions 6.7.2 and earlier.
18 Feb 2026VULN190Apache : Apache Arrow Potential use-after-free when reading IPC file with pre-bufferingSystems running Apache Arrow versions prior to 23.0.1.
18 Feb 2026VULN189node-tar : Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar ExtractionSystems running node-tar versions prior to 7.5.8.
18 Feb 2026VULN188Apache : Apache Camel Deserialization of Untrusted Data and Cross-Realm Token Acceptance BypassSystems running Apache Camel versions prior to 4.18.0, 4.10.9, 4.14.5.
18 Feb 2026VULN187Apache : Multiple vulnerabilities fixed in Apache TomcatSystems running Apache Tomcat Native versions prior to 2.0.12, 1.3.5, Apache Tomcat versions prior to 11.0.18, 10.1.52, 9.0.115.
18 Feb 2026VULN186Openstack : Nova calls qemu-img without format restrictions for resizeSystems running Nova versions <30.2.2, >=31.0.0 <31.2.1, >=32.0.0 <32.1.1.
18 Feb 2026VULN185vaultwarden : Multiple vulnerabilities fixed in vaultwardenSystems running vaultwarden versions prior to 1.35.3.
18 Feb 2026VULN184Dell : Security Update for RecoverPoint for Virtual Machines Hardcoded Credential VulnerabilitySystems running RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1.
18 Feb 2026VULN183Indico : Server-Side Request Forgery (SSRF) and Cross-Site-Scripting fixedSystems running Indico versions prior to 3.3.10.
18 Feb 2026VULN182Jenkins : Jenkins Security Advisory 2026-02-18Systems running Jenkins (core) versions prior to weekly 2.551, LTS 2.541.2.
17 Feb 2026VULN181Palo Alto : PAN-SA-2026-0002 Chromium Monthly Vulnerability Update (February 2026)Systems running Prisma Browser versions prior to 144.27.7.133.
17 Feb 2026VULN180Rack : Directory Traversal and XSS injection via malicious filename via Rack:DirectorySystems running rack (RubyGems) versions prior to 2.2.22, 3.1.20, 3.2.5.
17 Feb 2026VULN179HAProxy : February 2026 — CVE-2026-26080 and CVE-2026-26081 QUIC denial of service Systems running HAProxy versions prior to 3.0.16, 3.1.14, 3.2.12, 3.3.3.
17 Feb 2026VULN178Mozilla : Security Vulnerabilities fixed in Thunderbird 147.0.2 and 140.7.2Systems running Thunderbird versions prior to 147.0.2, 140.7.2.
17 Feb 2026VULN177Mozilla : Security Vulnerabilities fixed in 147.0.4, ESR 140.7.1, and ESR 115.32.1Systems running Firefox versions prior to 147.0.4, ESR 140.7.1, ESR 115.32.1.
17 Feb 2026VULN176Apache : Apache NiFi Missing Authorization of Restricted Permissions for Component UpdatesSystems running Apache NiFi versions prior to 2.8.0.
16 Feb 2026VULN175lakeFS : lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory accessSystems running lakefs (Go) versions prior to 1.77.0.
16 Feb 2026VULN174Google Chrome : Chrome 145.0.7632.75/76 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 145.0.7632.75/76.
16 Feb 2026VULN173CPAN Security Group : CVE-2025-40905 WWW::OAuth 1.000 and earlier for Perl uses insecure rand() functionSystems running Traefik versions prior to 2.6.1, 3.0.0-beta.3.
16 Feb 2026VULN172Vim : TCP readTimeout bypass via STARTTLS on PostgresSystems running Vim versions prior to 9.1.2148.
16 Feb 2026VULN171Unstructured : Path Traversal via Malicious MSG Attachment Allows Arbitrary File WriteSystems running Unstructured versions prior to 0.18.18.
16 Feb 2026VULN170Hashicorp : Arbitrary code execution in React server-side rendering of untrusted MDX contentSystems running next-mdx-remote versions prior to 6.0.0.
16 Feb 2026VULN169Qnap : Multiple Vulnerabilities in File Station 5Systems running File Station 5 versions prior to 5.5.6.5190.
16 Feb 2026VULN168Qnap : Multiple Vulnerabilities in QTS and QuTS heroSystems running QTS versions prior to 5.2.8.3350 build 20251216, QuTS hero versions prior to 5.2.8.3350 build 20251216, 5.3.2.3354 build 20251225.
13 Feb 2026VULN167Traefik : TCP readTimeout bypass via STARTTLS on PostgresSystems running Traefik versions prior to 2.6.1, 3.0.0-beta.3.
13 Feb 2026VULN166SPIP : Mise à jour de sécurité sortie de SPIP 4.4.8Systems running SPIP versions prior to 4.4.8.
13 Feb 2026VULN165SurrealDB : Denial of Service through scripting function memory edge caseSystems running SurrealDB (Rust) versions prior to 2.6.1, 3.0.0-beta.3.
13 Feb 2026VULN164Fortinet : Multiple vulnerabilities fixed in FortiOSFortiOS versions prior to 7.6.5, 7.4.10.
13 Feb 2026VULN163Fortinet : Missing authorization on CSV user importSystems running FortiAuthenticator versions prior to 6.6.7.
13 Feb 2026VULN162PostgreSQL : PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 Released!Systems running PostgreSQL versions prior to 18.2, 17.8, 16.12, 15.16, 14.21.
13 Feb 2026VULN161Apache : CVE-2025-33042 Apache Avro Java SDK Code injection on Java generated codeSystems running Apache Avro Java SDK versions prior to 1.12.1, 1.11.5.
12 Feb 2026VULN160Pillow : Out-of-bounds write when loading PSD imagesSystems running Pillow versions prior to 12.1.1.
12 Feb 2026VULN159APPLE : APPLE-SA-02-11-2026-7 watchOS 26.3watchOS versions prior to 26.3.
12 Feb 2026VULN158APPLE : APPLE-SA-02-11-2026-6 tvOS 26.3tvOS versions prior to 26.3.
12 Feb 2026VULN157APPLE : iOS 26.3, 18.7.5 and iPadOS 26.3, 18.7.5iOS, iPadOS versions prior to 26.3, 18.7.5.
12 Feb 2026VULN156APPLE : macOS Tahoe 26.3, Sequoia 15.7.4 and Sonoma 14.8.4macOS versions prior to Tahoe 26.3, Sequoia 15.7.4, Sonoma 14.8.4.
12 Feb 2026VULN155BeyondTrust : RCE in Remote Support (RS) and Privileged Remote Access (PRA)Systems running BeyondTrust Remote Support versions prior to Patch BT26-02-RS (v21.3 - 25.3.1), BeyondTrust Privileged Remote Access versions prior to Patch BT26-02-PRA (v22.1 - 24.X).
11 Feb 2026VULN154Ivanti : Security Advisory EPM February 2026 for EPM 2024Systems running Ivanti Endpoint Manager versions prior to 2024 SU5.
11 Feb 2026VULN153GitLab : GitLab Patch Release: 18.8.4, 18.7.4, 18.6.6Systems running GitLab versions prior to 18.8.4, 18.7.4, 18.6.6.
11 Feb 2026VULN152Adobe : Security Updates Available for Adobe Bridge APSB26-21Systems running Adobe Bridge versions prior to 15.1.4 (LTS), 16.0.2.
11 Feb 2026VULN151Adobe : Security Update Available for Adobe InDesign APSB26-17Systems running Adobe InDesign versions prior to ID21.2, ID20.5.2.
11 Feb 2026VULN150(N'existe pas a priori)-
11 Feb 2026VULN149munge : Buffer overflow in message unpacking allows key leakage and credential forgerySystems running munge versions prior to 0.5.18.
11 Feb 2026VULN148Adobe : Security Updates Available for Adobe After Effects APSB26-15Systems running Adobe After Effects versions prior to 25.6.4, 26.0.
11 Feb 2026VULN147Keycloak : Keycloak 26.5.3 fix multiple security vulnerabilitiesSystems running Keycloak versions prior to 26.5.3.
11 Feb 2026VULN146Cryptography : PyCA cryptography 46.0.5 releasedSystems running PyCA cryptography versions prior to 46.0.0.
10 Feb 2026VULN145Fortinet : SQLi in administrative interfaceSystems running FortiClientEMS versions prior to 7.4.5.
10 Feb 2026VULN144SAP : SAP Security Patch Day - February 2026Systems running SAP products.
10 Feb 2026VULN143libpng : Heap buffer overflow in png_set_quantizeSystems running libpng versions prior to 1.6.55.
10 Feb 2026VULN142PowerDNS : PowerDNS Security Advisory 2026-01 Crafted zones can lead to increased resource usage in RecursorSystems running PowerDNS Recursor versions prior to 5.1.10, 5.2.8, 5.3.5.
10 Feb 2026VULN141GNUTLS : gnutls 3.8.12 fix DoS and Stack write buffer overflow vulnerabilitiesSystems running GNUTLS versions prior to 3.8.12.
10 Feb 2026VULN140Apache : CVE-2026-23906 Apache Druid Authentication Bypass via LDAP Anonymous BindSystems running Apache Druid versions prior to 36.0.0.
9 Feb 2026VULN139Broadcom : VMware Tanzu Greenplum 6.32.0Systems running VMware Tanzu Greenplum versions prior to 6.32.0.
9 Feb 2026VULN138Apache : CVE-2026-24343 Apache HertzBeat Uncontrolled Resource Consumption via Crafted XPath ExpressionsSystems running Apache HertzBeat versions prior to 1.8.0.
9 Feb 2026VULN137Apache : Permission Bypass and permission leak vulnerabilities fixed in Apache AirflowSystems running Apache Airflow versions prior to 3.1.7.
9 Feb 2026VULN136Gitlab : GitLab AI Gateway Critical Patch Release: 18.6.2, 18.7.1, and 18.8.1Systems running GitLab AI Gateway versions prior to 18.6.2, 18.7.1, 18.8.1.
9 Feb 2026VULN135Roundcube : Security updates 1.6.13 and 1.5.13 releasedSystems running Roundcube Webmail prior to 1.6.13, 1.5.13.
6 Feb 2026VULN134Broadcom : Isolation Segmentation for VMware Tanzu Platform 10.2.7+LTS-T, 10.3.4Systems running VMware Tanzu Platform versions prior to 10.2.7+LTS-T.
6 Feb 2026VULN133ESET : Local privilege escalation vulnerability in ESET Management Agent for Windows fixedSystems running ESET Management Agent for Windows versions prior to 13.0.1400.0.
6 Feb 2026VULN132web2py : web2py has an Open Redirect VulnerabilitySystems running web2py versions prior to 3.1.7.
6 Feb 2026VULN131pgAdmin : 2026-02-05 - pgAdmin 4 v9.12 ReleasedSystems running pgAdmin 4 versions prior to 9.12.
6 Feb 2026VULN130vim : buffer overflow in helpfile option handling affects Vim < 9.1.2132Systems running Vim versions prior to 9.1.2132.
5 Feb 2026VULN129Broadcom : Foundation Core for VMware Tanzu Platform 3.1.7Systems running Foundation Core for VMware Tanzu Platform versions prior to 3.1.7.
5 Feb 2026VULN128Splunk : Third-Party Package Updates in Splunk SOAR - February 2026Systems running Splunk SOAR versions prior to 7.1.0.
5 Feb 2026VULN127Cisco : Cisco Security Advisories Published on February 04, 2026Systems running Cisco Meeting Management, Cisco TelePresence Collaboration Endpoint Software and RoomOS Software, Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure, Cisco Secure Web Appliance.
5 Feb 2026VULN126Drupal : Login Disable - Less critical - Access bypass - SA-CONTRIB-2026-008Systems running Login Disable for Drupal versions prior to 2.1.3.
5 Feb 2026VULN125NGINX : CVE-2026-1642 SSL upstream injection Vulnerability fixedSystems running NGINX versions prior to 1.29.5+, 1.28.2+.
5 Feb 2026VULN124modelcontextprotocol.io : Sharing server/transport instances can leak cross-client response dataSystems running @modelcontextprotocol/sdk (npm) versions prior to 1.26.0.
5 Feb 2026VULN123openclaw : Local File Inclusion via MEDIA: Path ExtractionSystems running openclaw (npm) versions prior to 2026.1.30.
5 Feb 2026VULN122n8n : Multiple Critical Vulnerabilities fixed in n8nSystems running n8n (npm) versions prior to 2.5.2, 1.123.17.
5 Feb 2026VULN121rancher : Vulnerable to path traversal via parameters.pathPatternSystems running rancher/local-path-provisioner versions prior to 0.0.34.
4 Feb 2026VULN120Tenable : Tenable Identity Exposure Version 3.77.16 Fixes Multiple VulnerabilitiesSystems running Tenable Identity Exposure versions prior to 3.77.16.
4 Feb 2026VULN119Google : Chrome 144.0.7559.132/.133 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 144.0.7559.132/.133.
4 Feb 2026VULN118glpi : Multiple security vulnerabilities fixed in glpiSystems running glpi versions prior to 10.0.23, 11.0.5.
4 Feb 2026VULN117wagtail : Improper permission handling on admin preview endpointsSystems running wagtail versions prior to 6.3.6, 7.0.4, 7.1.3, 7.2.2, 7.3.
4 Feb 2026VULN116Claude Code : Multiple security vulnerabilities fixed in ClaudeSystems running Claude Code versions prior to 2.0.74.
4 Feb 2026VULN115Django : Django security releases issued 6.0.2, 5.2.11, and 4.2.28Systems running Django versions prior to 6.0.2, 5.2.11, 4.2.28.
3 Feb 2026VULN114Broadcom : Platform Automation Toolkit 5.4.0Systems running Platform Automation Toolkit versions prior to 5.4.0.
3 Feb 2026VULN113Broadcom : Telemetry for VMware Tanzu Platform 2.4.0Systems running Tanzu Telemetry for VMware Tanzu versions prior to 2.4.0.
3 Feb 2026VULN112Broadcom : Tanzu Kubernetes Grid Integrated Edition (TKGi) VulnerabilitiesSystems running anzu Kubernetes Grid Integrated Edition (TKGi).
3 Feb 2026VULN111Node.js : OpenSSL Security Advisory Assessment, January 2026Systems running Node.js and OpenSSL versions 3.0, 3.5.
3 Feb 2026VULN110Plone : Plone Security Advisory 20260116 - Attempted code insertions into Github pull requestsSystems running plone ecosystem software.
3 Feb 2026VULN109clawdbot : command injection and 1-Click RCE vulnerabilities fixedSystems running clawdbot (npm) versions prior to 2026.1.29.
3 Feb 2026VULN108kubernetes : Multiple issues in ingress-nginxSystems running ingress-nginx versions prior to 1.13.7, 1.14.3.
2 Feb 2026VULN107Grafana : Unauthenticated DoS and Cross-dashboard privilege escalationSystems running Grafana versions prior to 12.3.1+security-01, 12.2.3+security-01, 12.1.5+security-01, 12.0.8+security-01, 11.6.9+security-01.
2 Feb 2026VULN106geopandas : geopandas SQL Injection Vulnerability in to_postgis() Allows Information DisclosureSystems running geopandas (pip) versions prior to 1.1.2.
2 Feb 2026VULN105PsySH : Local Privilege Escalation via CWD .psysh.php auto-loadSystems running PsySH versions prior to 0.12.19, 0.11.23.
2 Feb 2026VULN104Rancher : Rancher CLI skips TLS verification on Rancher CLI login commandSystems running Rancher versions prior to 2.13.2, 2.12.6, 2.11.10, 2.10.11.
2 Feb 2026VULN103Apache : Apache Syncope Console XXE and Reflected XSS vulnerabilitiesSystems running Apache Syncope versions prior to 3.0.16, 4.0.4.
2 Feb 2026VULN102Notepad++ : Notepad++ Hijacked by State-Sponsored HackersSystems running Notepad++ versions prior to 8.9.2.
2 Feb 2026VULN101CISA : Critical Vulnerability in KiloView Encoder SeriesSystems running KiloView Encoder Series.
30 Jan 2026VULN100Withsecure : Multiple security vulnerabilities fixed in Withsecure productsSystems running Withsecure products.
30 Jan 2026VULN099Ivanti : Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 & CVE-2026-1340)Systems running Ivanti Endpoint Manager Mobile versions prior to RPM 12.x.0.x, RPM 12.x.1.x.
30 Jan 2026VULN098Qnap : Vulnerability in legacy QTS with NFS service enabledSystems running qnap QTS versions prior to 5.2.x.
29 Jan 2026VULN097HPE Aruba Networking : HPE Aruba Networking Fabric Composer Multiple VulnerabilitiesSystems running HPE Aruba Networking Fabric Composer versions prior to 7.3.0.
29 Jan 2026VULN096Tenable : Tenable Network Monitor Version 6.5.3 Fixes Multiple VulnerabilitiesSystems running Nessus Network Monitor versions prior to 6.5.3.
29 Jan 2026VULN095Google : Chrome 144.0.7559.109/.110 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 144.0.7559.109/.110.
29 Jan 2026VULN094SolarWinds : Multiple security vulnerabilities fixed in SolarWinds Web Help DeskSystems running SolarWinds Web Help Desk versions prior to 2026.1.
29 Jan 2026VULN093AutoGPT : RCE via Disabled Block ExecutionSystems running AutoGPT Platform versions prio to autogpt-platform-beta-v0.6.44.
28 Jan 2026VULN092Fortinet : Administrative FortiCloud SSO authentication bypassSystems running FortiOS versions prior to 7.6.6, 7.4.11, 7.2.13, 7.0.19, FortiManager versions prior to 7.6.6, 7.4.10, 7.2.13, 7.0.16, FortiAnalyzer versions prior to 7.6.6, 7.4.10, 7.2.12, 7.0.16, FortiProxy versions prior to 7.6.6, 7.4.13, FortiWeb versions prior to 8.0.4, 7.6.7, 7.4.12.
28 Jan 2026VULN091Vllm : Server-Side Request Forgery (SSRF) in `MediaConnector`Systems running vllm (pip) versions prior to 0.14.1.
28 Jan 2026VULN090Symfony : Incorrect argument escaping under MSYS2/Git Bash on Windows can lead to destructive file operationsSystems running symfony/process (Composer), symfony/symfony (Composer) versions prior to 5.4.51, 6.4.33, 7.3.11, 7.4.5, 8.0.5.
28 Jan 2026VULN089Suricata : Multiple Vulnerabilities fixed in suricataSystems running Suricata versions prior to 7.0.14, 8.0.3.
28 Jan 2026VULN088node-tar : Multiple vulnerabilities fixed in node-tarSystems running node-tar (npm) versions prior to 7.5.7.
28 Jan 2026VULN087Citrix : XenServer Security Update for CVE-2025-58151 and CVE-2026-23553Systems running XenServer versions 8.4.
28 Jan 2026VULN086GnuPG : GnuPG and Gpg4win Security Advisory (T8044)Systems running GnuPG versions prior to 2.5.17.
28 Jan 2026VULN085OpenSSL : OpenSSL Security Advisory [27th January 2026]Systems running OpenSSL versions prior to 3.6.1, 3.5.5, 3.4.4, 3.3.6, 3.0.19, 1.1.1ze, 1.0.2zn.
28 Jan 2026VULN084Kyverno : Kyverno Cross-Namespace Privilege Escalation and Denial of Service VulnerabilitiesSystems running kyverno (Go) versions prior to 1.16.3, 1.15.3.
28 Jan 2026VULN083vm2 : Sandbox EscapeSystems running vm2 versions prior to 3.10.2.
27 Jan 2026VULN082Microsoft : Vulnérabilit=é de contournement de la fonctionnalité de sécurité dans Microsoft OfficeSystems running Microsoft Office 2016, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019.
27 Jan 2026VULN081React : Denial of Service Vulnerabilities in React Server ComponentsSystems running react-server-dom-parcel (npm), react-server-dom-turbopack (npm), react-server-dom-webpack (npm) versions prior to 19.0.4, 19.1.5, 19.2.4.
27 Jan 2026VULN080next.js : Denial of Service Vulnerabilities fixed in next.jsSystems running next(npm) versions prior to 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5.
27 Jan 2026VULN079pytorch : Loading a malicious PyTorch checkpoint with weights_only=True can result in arbitrary code executionSystems running PyTorch versions prior to 2.10.0.
27 Jan 2026VULN078Xen : Multiple vulnerabilities fixed in XenSystems running Xen.
26 Jan 2026VULN077CPython : email BytesGenerator header injection due to unquoted newlinesSystems running CPython.
26 Jan 2026VULN076protobuf : A potential Denial of Service issue in protobuf-pythonSystems running protobuf (pip) versions prior to 4.25.8, 5.29.5, 6.31.1.
26 Jan 2026VULN075Apache : Apache Continuum Command injection leading to RCESystems running Apache Continuum.
26 Jan 2026VULN074Apache : Apache Karaf Decanter log-socket collector has deserialization vulnerabilitySystems running Apache Karaf versions prior to 2.12.0.
26 Jan 2026VULN073Apache : HDFS native client Out of bounds write in URI parser of native HDFS clientSystems running Apache Hadoop HDFS native client versions prior to 3.4.2.
23 Jan 2026VULN072Broadcom : Web Security Services Agent Security UpdateSystems running Cloud Secure Web Gateway versions prior to 9.8.5.
23 Jan 2026VULN071Python : CVE-2025-12781 base64.b64decode() always accepts \"+/\" characters, despite setting altcharsSystems running CPython.
23 Jan 2026VULN070Symantec : Symantec Endpoint Protection Security UpdateSystems running Symantec Endpoint Protection versions prior to 14.3 RU10 (14.3.12167.10000), 14.3 RU9 (14.3.11237.9000), 14.3 RU8 (14.3.10178.8000).
23 Jan 2026VULN069Apache : Vulnerabilities fixed in Apache SolrSystems running Apache Solr versions prior to 9.10.1.
23 Jan 2026VULN068TYPO3 : Insecure Deserialization in extension \"Mailqueue\" (mailqueue)Systems running TYPO3 extension manager versions prior to 0.5.1, 0.4.3.
23 Jan 2026VULN067surrealdb : Confused Deputy Privilege Escalation through Future Fields and FunctionsSystems running surrealdb (Rust) versions prior to 2.5.0, 3.0.0-beta.3.
23 Jan 2026VULN066GNU InetUtils : GNU InetUtils Security Advisory remote authentication by-pass in telnetdSystems running GNU InetUtils telnetd.
23 Jan 2026VULN065incus : Arbitrary command execution vulnerabilities fixed in incusSystems running incusd (Go) versions prior to 6.21.0, 6.0.6.
22 Jan 2026VULN064vllm : RCE via auto_map dynamic module loading during model initializationSystems running vllm versions prior to 0.14.0.
22 Jan 2026VULN063Argo Workflows : Stored XSS in the artifact directory listingSystems running argo-workflows (Go) versions prior to 3.6.17, 3.7.8.
22 Jan 2026VULN062GLIBC : DoS and stack contents leak vulnerabilitiesSystems running GNU C Library versions 2.30 up to and including 2.42.
22 Jan 2026VULN061Ceph : Incorrect usage of certificate checking via Pybind useSystems running pybind (ceph) versions prior to 20.2.1, 19.2.4, 18.2.9.
21 Jan 2026VULN060CPython : CPython Multiple vulnerabilitiesSystems running CPython.
21 Jan 2026VULN059Bind : CVE-2025-13878 Malformed BRID/HHIT records can cause named to terminate unexpectedlySystems running BIND versions prior to 9.18.44, 9.20.18, 9.21.17.
21 Jan 2026VULN058Oracle : January 2026 Critical Patch Update ReleasedSystems running Oracle products.
21 Jan 2026VULN057GitLab : GitLab Patch Release 18.8.2, 18.7.2, 18.6.4Systems running GitLab versions prior to 18.8.2, 18.7.2, 18.6.4.
21 Jan 2026VULN056Cisco : Cisco Security Advisories Published on January 21, 2026Cisco Unified Communications Products, Cisco Intersight Virtual Appliance, Cisco IEC6400 Wireless Backhaul Edge Compute Software, Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise.
20 Jan 2026VULN055urllib3 : Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)Systems running urllib3 versions prior to 2.6.3.
20 Jan 2026VULN054Wireshark : Wireshark file parser and dissector crashesSystems running Wireshark versions prior to 4.6.3, 4.4.13.
20 Jan 2026VULN053Traefik : ACME TLS-ALPN fast path lacks timeouts and close on handshake stallSystems running traefik versions prior to 2.11.35, 3.6.7.
19 Jan 2026VULN052Svelte : XSS with textarea bind:valueSystems running svelte (npm) versions prior to 3.59.2.
19 Jan 2026VULN051Mattermost : Multiple security vulnerabilities fixed in MattermostSystems running Mattermost.
19 Jan 2026VULN050Deno : fix for `node:crypto` vulnerability and Incomplete fix for command-injection prevention on WindowsSystems running Deno versions prior to 2.6.0.
19 Jan 2026VULN049GLIBC : Integer overflow in memalign leads to heap corruptionSystems running GNU C Library versions 2.30 up to and including 2.42.
16 Jan 2026VULN048Centreon : CVE-2025-43865, CVE-2025-43864 - Centreon 25.10 IT & Business EditionsSystems running Centreon 25.10 IT & Business Editions.
16 Jan 2026VULN047GLPI : Unauthorized access to documents and Unauthenticated SQL injection fixedSystems running glpi versions prior to 10.0.21, 11.0.3.
16 Jan 2026VULN046Pimcore : Multiple vulnerabilities fixed in PimcoreSystems running pimcore (Composer) versions prior to 12.3.1 11.5.14.
16 Jan 2026VULN045Go : Go 1.25.6 and Go 1.24.12 include 6 security fixesSystems running Go versions prior to 1.25.6, 1.24.12.
16 Jan 2026VULN044Apache : Apache Airflow sensitive data exposure vulnerabilities fixedSystems running Apache Airflow versions prior to 3.1.6.
16 Jan 2026VULN043Apache : CVE-2025-60021 Apache bRPC Remote command injection vulnerability in heap builtin serviceSystems running Apache bRPC versions prior to 1.15.0.
15 Jan 2026VULN042Adobe : Security update available for Adobe Dreamweaver APSB26-01Systems running Adobe Dreamweaver versions prior to 21.7.
15 Jan 2026VULN041Cisco : Cisco Security Advisories Published on January 15, 2026Systems running Cisco Secure Email Gateway And Cisco Secure Email and Web Manager, Cisco Identity Services Engine, Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure.
15 Jan 2026VULN040Adobe : Security Updates Available for Adobe Illustrator APSB26-03Systems running Adobe Illustrator versions prior to 2025 29.8.4, 2026 30.1.
15 Jan 2026VULN039Adobe : Security updates available for Adobe ColdFusion APSB26-12Systems running Adobe ColdFusion versions prior to 2025 Update 6, 2023 Update 18.
15 Jan 2026VULN038Mozilla : Security Vulnerabilities fixed in Thunderbird 147, 140.7Systems running Thunderbird versions prior to 147, 140.7.
15 Jan 2026VULN037Mozilla : Security Vulnerabilities fixed in Firefox 147, ESR 115.32, ESR 140.7Systems running Firefox versions prior to 147, ESR 115.32, ESR 140.7.
15 Jan 2026VULN036Google: Chrome 144.0.7559.59/60 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 144.0.7559.59/60.
14 Jan 2026VULN035Misp : Stored/Reflected XSS via Unsanitized Parameters in URL Generation and JavaScript ContextSystems running misp versions prior to 2.5.31.
14 Jan 2026VULN034Spring : CVE-2026-22718 Command injection on user machine using VSCode extension for Spring CLISystems running Spring CLI VSCode Extension.
14 Jan 2026VULN033Fortinet : Heap-based buffer overflow in cw_acd daemonSystems running FortiOS versions prior to 7.6.4, 7.4.9, 7.2.12, 7.0.18, 6.4.17, FortiSASE versions prior to 25.2.c, FortiSwitchManager versions prior to 7.2.7, 7.0.6.
14 Jan 2026VULN032Fortinet : Unauthenticated remote command injection in FortiSIEMSystems running FortiSIEM versions prior to 7.4.1, 7.3.5, 7.2.7, 7.1.9.
14 Jan 2026VULN031Fortinet : Unauthenticated access to local configurationSystems running FortiFone versions prior to 7.0.2, 3.0.24.
14 Jan 2026VULN030TYPO3 : Broken Access Control and Insecure Deserialization Vulnerabilities fixed in TYPO3Systems running TYPO3 CMS versions prior to 10.4.55 ELTS, 11.5.49 ELTS, 12.4.41 LTS, 13.4.23 LTS, 14.0.2.
14 Jan 2026VULN029AdonisJS : Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORMSystems running @adonisjs/lucid versions prior to 21.8.2, 22.0.0-next.6.
14 Jan 2026VULN028opencode : Malicious website can execute commands on the local system through XSS in the OpenCode web UISystems running opencode versions prior to 1.1.10.
14 Jan 2026VULN027Apache : Apache Camel security advisory CVE-2025-66169Systems running Apache Camel versions prior to 4.10.8, 4.14.3, 4.17.0.
14 Jan 2026VULN026Node.js : Tuesday, January 13, 2026 Security ReleasesSystems running Node.js versions prior to 20.20.0, 22.22.0, 24.13.0, 25.3.0.
13 Jan 2026VULN025VMware : Vulnerabilities fixed in VMware Tanzu GemFire 10.1.6 and 10.2.1Systems running VMware Tanzu Data Intelligence, VMware Tanzu Data Services Pack, VMware Tanzu Data Suite, VMware Tanzu Gemfire.
13 Jan 2026VULN024SAP : SAP Security Patch Day - January 2026Systems running SAP products.
13 Jan 2026VULN023react-router : Multiple vulnerabilities fixed in react-router ecosystemSystems running @react-router/node (npm) versions prior to 7.9.4, react-router (npm) versions prior to 7.12.0, @remix-run/react (npm) versions prior to 2.17.1, @remix-run/router (npm) versions prior to 1.23.2, @remix-run/deno (npm), @remix-run/node (npm), @remix-run/server-runtime (npm) versions prior to 2.17.3.
13 Jan 2026VULN022Libpng : Heap buffer over-read vulnerabilities fixed in libpngSystems running Libpng versions prior to 1.6.54.
12 Jan 2026VULN021Angular : XSS Vulnerability via Unsanitized SVG Script AttributesSystems running @angular/compiler (npm), @angular/core (npm) versions prior to 21.1.0-rc.0, 21.0.7, 20.3.16, 19.2.18.
12 Jan 2026VULN020Apache : CVE-2025-68493 Apache Struts XXE vulnerability in outdated XWork componentSystems running Apache Struts versions prior to 25.10.2, 24.10.3, 24.04.3.
12 Jan 2026VULN019Centreon : Centreon Open Tickets - Vulnerabilities, one High Severity Systems running Centreon Open Tickets versions prior to 25.10.0, 24.10.5, 24.04.5, 23.10.4.
12 Jan 2026VULN018Joomla! : Core - XSS vectors in Joomla! CMSSystems running Joomla! CMS versions prior to 5.4.2, 6.0.2.
9 Jan 2026VULN017Centreon : Centreon AWIE - Critical Severity VulnerabilitiesSystems running Centreon AWIE versions prior to 25.10.2, 24.10.3, 24.04.3.
9 Jan 2026VULN016Apache : Multiple Vulnerabilities fixed in Apache NimBLE 1.9.0Systems Apache NimBLE versions prior to 1.9.0.
9 Jan 2026VULN015Tenable : Nessus Agent Versions 11.0.3 and 10.9.3 Fix One VulnerabilitySystems running Nessus Agent versions prior to 11.0.3, 10.9.3.
9 Jan 2026VULN014Trend Micro : Trend Micro Apex Central (on-premise) January 2026 Multiple VulnerabilitiesSystems Apex Central (on-premise) versions prior to Critical Patch Build 7190.
9 Jan 2026VULN013Cisco : Cisco Security Advisories Published on January 07, 2026Systems running Cisco Products running Snort, Cisco Identity Services Engine.
9 Jan 2026VULN012RustFS : Multiple Vulnerabilities Resolved in RustFS, one CriticalSystems running RustFS versions prior to alpha.79.
8 Jan 2026VULN011Veeam : Vulnerabilities Resolved in Veeam Backup & Replication, one CriticalSystems running Veeam Backup & Replication versions prior to 13.0.1.1071.
8 Jan 2026VULN010Vega : Vega Cross-Site Scripting (XSS) vulnerabilitiesSystems running vega-selections (npm) versions prior to 6.1.2, 5.6.3, vega-functions (npm) versions prior to 6.1.1.
8 Jan 2026VULN009Google : Chrome 143.0.7499.192/.193 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 143.0.7499.192/.193.
8 Jan 2026VULN008GitLab : GitLab Patch Release 18.7.1, 18.6.3, 18.5.5Systems running GitLab versions prior to 18.7.1, 18.6.3, 18.5.5.
7 Jan 2026VULN007Opencti : GraphQL IDOR allows authenticated user to delete workspace content of other usersSystems running OpenCTI versions prior to 6.8.1.
7 Jan 2026VULN006Apache : CVE-2025-68280 Apache SIS XML External Entity (XXE) vulnerabilitySystems running Apache SIS versions prior to 1.6.
7 Jan 2026VULN005AIOHTTP : Multiple Security Vulnerabilities fixed in AIOHTTPSystems running AIOHTTP versions prior to 3.13.3.
7 Jan 2026VULN004curl : Multiple vulnerabilities fixed in curl 8.18.0Systems running curl versions prior to 8.18.0.
7 Jan 2026VULN003GNU Wget : Critical file overwrite issue with metalink in GNU Wget2 CVE-2025-69194Systems running GNU Wget2 versions prior to 2.2.1.
7 Jan 2026VULN002Langflow : Missing Authentication on Critical API EndpointsSystems running Langflow versions prior to 1.7.1.
7 Jan 2026VULN001n8n : Critical RCE via Arbitrary File WriteSystems running n8n versions prior to 1.121.3.