search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2026-01-20 2026-01-20 2026-01-20 VU#244846 Server-Side Template Injection (SSTI) vulnerability exist in Genshi
2026-01-20 2026-01-20 2026-01-20 VU#924114 dr_flac contains an integer overflow vulnerability that allows for DoS when provided a crafted file
2026-01-16 2026-01-16 2026-03-16 VU#383552 The Librarian does not secure its interface, allowing for access to internal system data
2026-01-16 2026-01-16 2026-01-16 VU#650657 Livewire Filemanager contains an insecure .php component that allows for unauthenticated RCE in Laravel Products
2026-01-15 2026-01-15 2026-01-15 VU#472136 Information Leak and DoS Vulnerabilities in Redmi Buds 3 Pro through 6 Pro
2026-01-09 2026-01-09 2026-01-09 VU#361400 BeeS Software Solutions BeeS Examination Tool (BET) portal contains SQL injection vulnerability
2026-01-06 2026-01-06 2026-01-06 VU#295169 TOTOLINK EX200 firmware-upload error handling can activate an unauthenticated root telnet service
2026-01-06 2026-01-06 2026-01-06 VU#420440 Vulnerable Python version used in Forcepoint One DLP Client
2025-12-17 2025-12-17 2025-12-22 VU#382314 Vulnerability in UEFI firmware modules prevents IOMMU initialization on some UEFI-based motherboards
2025-12-16 2025-12-16 2025-12-16 VU#651499 Siemens Gridscale X Prepay username enumeration and account lock bypass vulnerability
2025-12-09 2025-12-09 2025-12-09 VU#821724 TOTOLINK's X5000R's (AX1800 router) lacks authentication for telnet
2025-12-09 2025-12-09 2025-12-09 VU#404544 Vulnerabilities identified in PCIe Integrity and Data Encryption (IDE) protocol specification
2025-12-05 2025-12-05 2025-12-09 VU#441887 Duc contains a stack buffer overflow vulnerability in the buffer_get function, allowing for out-of-bounds memory read
2025-12-01 2025-12-01 2025-12-01 VU#633103 Insufficient Session Cookie Invalidation in nopCommerce ASP.NET Core eCommerce Platform
2025-11-25 2025-11-25 2025-11-25 VU#521113 Forge JavaScript library impacted by a vulnerability in signature verification.

Sponsored by CISA.