search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2025-11-24 2025-11-18 2026-01-05 VU#761751 Fluent Bit contains five vulnerabilities, including stack buffer overflow, auth bypass, and path traversal
2025-11-24 2025-11-24 2025-11-24 VU#649739 Lack of Sufficient Guardrails Lead to Excessive Agency (LLM08) in Some LLM Applications
2025-11-20 2025-11-20 2025-11-20 VU#268029 Tenda N300 Wi-Fi 4G LTE Router 4G03 Pro impacted by vulnerabilities
2025-11-11 2025-11-11 2025-11-11 VU#553375 Unprotected temporary directories in Wolfram Cloud version 14.2 may result in privilege escalation
2025-11-11 2025-11-11 2025-11-11 VU#579478 Lite XL Arbitrary Code Execution via Project Module and Legacy system.exec Function
2025-11-07 2025-11-07 2025-12-09 VU#263614 Vulnerability in expr-eval JavaScript library can lead to arbitrary code execution
2025-10-28 2025-10-28 2025-10-28 VU#517845 Authenticated SMTP users may spoof other identities due to ambiguous “From” header interpretation
2025-10-17 2025-10-17 2025-10-17 VU#516608 Multiple Password Managers Vulnerable to Clickjacking Attacks
2025-10-17 2025-10-17 2025-10-17 VU#652514 DNS Rebinding and Manipulating CORS Headers Enables Exfiltration of Information
2025-10-13 2025-10-13 2025-10-16 VU#538470 Clevo UEFI firmware embedded BootGuard keys compromising Clevo's implementation of BootGuard
2025-10-10 2025-10-10 2025-10-10 VU#887923 Kiwire Captive Portal contains 3 web vulnerabilities
2025-10-03 2025-10-03 2026-03-02 VU#294418 Vigor routers running DrayOS are vulnerable to RCE via EasyVPN and LAN web administration interface
2025-09-29 2025-09-29 2025-10-23 VU#534320 NPM supply chain compromise exposes challenges to securing the ecosystem from credential theft and self-propagation
2025-09-22 2025-09-22 2025-09-22 VU#780141 Cross-site scripting vulnerability in Lectora course navigation
2025-09-12 2025-09-12 2025-09-12 VU#949137 Langchaingo supports jinja2 and gonja for syntax parsing, allowing for arbitrary file read

Sponsored by CISA.