search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2026-09-10 2026-09-10 2026-09-10 VU#687587 AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
2026-09-08 2026-09-08 2026-09-08 VU#718077 UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
2026-09-08 2026-09-08 2026-09-08 VU#859658 Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
2026-09-08 2026-09-08 2026-09-08 VU#943094 ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
2026-09-03 2026-09-03 2026-09-03 VU#889462 Casdoor authentication server is vulnerable to authorization bypass
2026-09-01 2026-09-01 2026-09-01 VU#456290 Hugging Face Transformers library writes remote code to disk prior to consent check
2026-08-25 2026-08-25 2026-08-28 VU#308749 Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
2026-08-24 2026-08-24 2026-08-24 VU#728712 Konami's Metal Gear Online 3 contains a heap-based buffer overflow
2026-08-21 2026-08-21 2026-09-09 VU#756733 Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability
2026-08-19 2026-08-19 2026-08-19 VU#874418 RDK-B WebUI contains multiple vulnerabilities
2026-08-11 2026-08-11 2026-08-12 VU#431093 TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks
2026-08-10 2026-08-10 2026-08-24 VU#614868 OpenCart ecommerce platform contains directory traversal vulnerability
2026-08-07 2026-08-07 2026-08-07 VU#987105 The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability
2026-08-06 2026-08-06 2026-08-18 VU#487613 Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations
2026-07-31 2026-07-31 2026-07-31 VU#243636 VPS.org one-click deployment templates contain multiple vulnerabilities

Sponsored by CISA.