Toutes les CVE des six derniers mois, mises à jour chaque jour.
Les vulnérabilités publiées, directement issues de la National Vulnerability Database, avec leur gravité, leur classe CWE et les produits concernés. Cherchez, filtrez et voyez ce qui est arrivé aujourd’hui.
- 294 publiées ces dernières 24 heures
- 2 895 ces 7 derniers jours
- 58 248 ces six derniers mois
Source : NVD (National Vulnerability Database) · Mis à jour le 23 sept. 2026
3 sur 3 affichées
Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. AshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base-32 characters, but the
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical
Trouvez la faille avant un attaquant.
Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.