search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2026-09-28 2026-09-28 2026-09-28 VU#762428 Authlib library contains a signature‑verification bypass vulnerability
2026-09-25 2026-09-25 2026-09-25 VU#699627 Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
2026-09-24 2026-09-24 2026-09-25 VU#234131 ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
2026-09-24 2026-09-24 2026-09-24 VU#676317 Norwegian Cruise Line door access controller contains an improper authentication vulnerability
2026-09-23 2026-09-23 2026-09-23 VU#273940 Enterprise Access Management EAM does not rotate RSA keys
2026-09-23 2026-09-23 2026-09-23 VU#754548 Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers
2026-09-22 2026-09-22 2026-09-22 VU#738147 Vendor-signed UEFI Shell applications allow Secure Boot bypass
2026-09-17 2026-09-17 2026-09-17 VU#280377 Dokploy is vulnerable to OS command injection
2026-09-16 2026-09-16 2026-09-23 VU#369093 MLflow dspy and statsmodels flavors bypass pickle deserialization control
2026-09-16 2026-09-16 2026-09-16 VU#212479 Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
2026-09-11 2026-09-11 2026-09-11 VU#369611 ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index
2026-09-10 2026-09-10 2026-09-14 VU#687587 AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
2026-09-08 2026-09-08 2026-09-08 VU#718077 UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
2026-09-08 2026-09-08 2026-09-08 VU#859658 Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
2026-09-08 2026-09-08 2026-09-08 VU#943094 ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

Sponsored by CISA.