CVE Find est une base de données de vulnérabilités en temps réel, indexant 381 332 failles de sécurité (CVE) issues de MITRE, NVD, CISA KEV, CWE et CAPEC. 4176 nouvelles CVE ont été publiées ces 7 derniers jours.
Données agrégées depuis : MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Publié | Description | Score | Gravité | |
|---|---|---|---|---|---|
CVE-2026-76158 |
2026-08-21 02h02 +00:00 |
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center f... |
9.3 |
Critique |
|
CVE-2026-77651 |
2026-08-21 01h17 +00:00 |
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project ... |
9.8 |
Critique |
|
CVE-2026-77650 |
2026-08-21 01h17 +00:00 |
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a pr... |
9.8 |
Critique |
|
CVE-2026-77649 |
2026-08-21 01h17 +00:00 |
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project... |
9.8 |
Critique |
|
CVE-2026-16520 |
2026-08-20 23h57 +00:00 |
Improper input validation and Exposure of sensitive information through data queries vulnerability i... |
8.7 |
Haute |
|
CVE-2026-77647 |
2026-08-20 23h16 +00:00 |
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited i... Code Injection |
9.8 |
Critique |
|
CVE-2026-72848 |
2026-08-20 22h18 +00:00 |
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente... Server-Side Request Forgery - SSRF |
8.6 |
Haute |
|
CVE-2026-72843 |
2026-08-20 22h18 +00:00 |
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/m... Authorization problems |
9.8 |
Critique |
|
CVE-2026-69851 |
2026-08-20 22h18 +00:00 |
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat... Server-Side Request Forgery - SSRF |
9.9 |
Critique |
|
CVE-2026-69836 |
2026-08-20 22h18 +00:00 |
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c... |
10 |
Critique |