CVE Find est une base de données de vulnérabilités en temps réel, indexant 349 031 failles de sécurité (CVE) issues de MITRE, NVD, CISA KEV, CWE et CAPEC. 1595 nouvelles CVE ont été publiées ces 7 derniers jours.
Données agrégées depuis : MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Publié | Description | Score | Gravité | |
|---|---|---|---|---|---|
CVE-2026-42560 |
2026-05-09 06h16 +00:00 |
auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and... Authorization problems |
9.1 |
Critique |
|
CVE-2026-41705 |
2026-05-09 01h16 +00:00 |
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injec... |
8.6 |
Haute |
|
CVE-2026-44313 |
2026-05-09 00h16 +00:00 |
Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and arc... Server-Side Request Forgery - SSRF |
9.1 |
Critique |
|
CVE-2026-42556 |
2026-05-08 23h16 +00:00 |
Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any auth... Cross-site Scripting |
8.9 |
Haute |
|
CVE-2026-42454 |
2026-05-08 23h16 +00:00 |
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa... OS Command Injection |
9.9 |
Critique |
|
CVE-2026-42354 |
2026-05-08 23h16 +00:00 |
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version ... |
9.1 |
Critique |
|
CVE-2026-42352 |
2026-05-08 23h16 +00:00 |
pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to... Server-Side Request Forgery - SSRF |
8.6 |
Haute |
|
CVE-2026-42302 |
2026-05-08 23h16 +00:00 |
FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-... Authorization problems |
9.8 |
Critique |
|
CVE-2026-42298 |
2026-05-08 23h16 +00:00 |
Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability... Code Injection |
10 |
Critique |
|
CVE-2026-42205 |
2026-05-08 22h16 +00:00 |
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken ... Authorization problems |
8.8 |
Haute |