search
menu
icon-carat-right
cmu-wordmark
×
Home
Notes
Search
Report a Vulnerability
Disclosure Guidance
VINCE
Carnegie Mellon University
Software Engineering Institute
CERT Coordination Center
Home
Notes
Search
Report a Vulnerability
Disclosure Guidance
VINCE
Home
Current:
Notes
CERT/CC Vulnerability Notes Database
Published
Public
Updated
ID
CVSS
Title
2026-09-28
2026-09-28
2026-09-28
VU#762428
Authlib library contains a signature‑verification bypass vulnerability
2026-09-25
2026-09-25
2026-09-25
VU#699627
Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
2026-09-24
2026-09-24
2026-09-25
VU#234131
ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
2026-09-24
2026-09-24
2026-09-24
VU#676317
Norwegian Cruise Line door access controller contains an improper authentication vulnerability
2026-09-23
2026-09-23
2026-09-23
VU#273940
Enterprise Access Management EAM does not rotate RSA keys
2026-09-23
2026-09-23
2026-09-23
VU#754548
Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers
2026-09-22
2026-09-22
2026-09-22
VU#738147
Vendor-signed UEFI Shell applications allow Secure Boot bypass
2026-09-17
2026-09-17
2026-09-17
VU#280377
Dokploy is vulnerable to OS command injection
2026-09-16
2026-09-16
2026-09-23
VU#369093
MLflow dspy and statsmodels flavors bypass pickle deserialization control
2026-09-16
2026-09-16
2026-09-16
VU#212479
Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
2026-09-11
2026-09-11
2026-09-11
VU#369611
ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index
2026-09-10
2026-09-10
2026-09-14
VU#687587
AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
2026-09-08
2026-09-08
2026-09-08
VU#718077
UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
2026-09-08
2026-09-08
2026-09-08
VU#859658
Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
2026-09-08
2026-09-08
2026-09-08
VU#943094
ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
Previous
You're on page
1
2
3
4
250
Next
Sponsored by
CISA.
Download PGP Key
Read CERT/CC Blog
Learn about Vulnerability Analysis