search
menu
icon-carat-right
cmu-wordmark
×
Home
Notes
Search
Report a Vulnerability
Disclosure Guidance
VINCE
Carnegie Mellon University
Software Engineering Institute
CERT Coordination Center
Home
Notes
Search
Report a Vulnerability
Disclosure Guidance
VINCE
Home
Current:
Notes
CERT/CC Vulnerability Notes Database
Published
Public
Updated
ID
CVSS
Title
2026-08-25
2026-08-25
2026-08-28
VU#308749
Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
2026-09-01
2026-09-01
2026-09-01
VU#456290
Hugging Face Transformers library writes remote code to disk prior to consent check
2026-04-21
2026-04-21
2026-09-02
VU#890999
Radware Alteon has a reflected XSS vulnerability that can execute JavaScript in the host browser
2026-09-03
2026-09-03
2026-09-03
VU#889462
Casdoor authentication server is vulnerable to authorization bypass
2026-09-08
2026-09-08
2026-09-08
VU#943094
ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
2026-09-08
2026-09-08
2026-09-08
VU#859658
Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
2026-09-08
2026-09-08
2026-09-08
VU#718077
UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
2026-06-18
2026-06-18
2026-09-09
VU#457458
Vendor-signed UEFI applications found vulnerable to Secure Boot bypass
2026-08-21
2026-08-21
2026-09-09
VU#756733
Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability
2026-09-10
2026-09-10
2026-09-10
VU#687587
AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
Previous
1
246
247
248
You're on page
249
Next
Sponsored by
CISA.
Download PGP Key
Read CERT/CC Blog
Learn about Vulnerability Analysis