search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2026-08-10 2026-08-10 2026-08-10 VU#614868 Opencart ecommerce platform contains directory traversal vulnerability
2026-08-07 2026-08-07 2026-08-07 VU#987105 The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability
2026-08-06 2026-08-06 2026-08-06 VU#487613 Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations
2026-07-31 2026-07-31 2026-07-31 VU#243636 VPS.org one-click deployment templates contain multiple vulnerabilities
2026-07-30 2026-07-30 2026-07-30 VU#281278 SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure
2026-07-30 2026-07-30 2026-07-30 VU#790363 foreUP golf management platform's web API contains multiple vulnerabilities
2026-07-29 2026-07-29 2026-07-29 VU#293714 Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)
2026-07-29 2026-07-29 2026-08-07 VU#305509 OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure
2026-07-28 2026-07-28 2026-07-28 VU#141367 AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface
2026-07-23 2026-07-23 2026-07-23 VU#492466 Logto Identity Platform has authentication and authorization failures in core protocol handling
2026-07-22 2026-07-22 2026-07-22 VU#847406 Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability
2026-07-22 2026-07-22 2026-08-05 VU#360868 Local Privilege escalation vulnerability in Analog Way Picturall Quad Compact Mark II version 3.5.8
2026-07-21 2026-07-21 2026-07-21 VU#762226 Plane contains multi-tenant authorization bypass vulnerability
2026-07-16 2026-07-16 2026-07-23 VU#885548 Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
2026-07-16 2026-07-16 2026-07-16 VU#326070 SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem

Sponsored by CISA.