Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,007
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,281 - 2,300 of 34,990 CVEs
CVE-2026-50560 MEDIUM - 5.3

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADE...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50091 CRITICAL - 9.1

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H...

Vendor: Aqara
Product: com.lumiunited.aqarahome
Published: Jun 12, 2026
Source: NVD
CVE-2026-50090 CRITICAL - 9.3

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L...

Vendor: Aqara
Product: Cloud OAuth Authorization Endpoint
Published: Jun 12, 2026
Source: NVD
CVE-2026-50089 MEDIUM - 6.1

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (6.1 Medium), which can be used to set up a phishing attack.

Vendor: Aqara
Product: Aqara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50088 HIGH - 8.2

The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3....

Vendor: Aqara
Product: Aqara Developer Portal, Aqara Developer Test Portal
Published: Jun 12, 2026
Source: NVD
CVE-2026-50087 HIGH - 8.2

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N (8.2 High).

Vendor: Aqara
Product: Aqara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50086 CRITICAL - 10.0

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Al...

Vendor: Aqara
Product: Aqara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50085 HIGH - 8.6

The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/P...

Vendor: Aqara
Product: Board service
Published: Jun 12, 2026
Source: NVD
CVE-2026-50084 CRITICAL - 9.6

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N (9.6 Critical). When combined...

Vendor: Aqara
Product: Cloud Production API
Published: Jun 12, 2026
Source: NVD
CVE-2026-50083 CRITICAL - 9.1

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, C...

Vendor: Aqara
Product: Aquara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50082 MEDIUM - 6.5

The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium)....

Vendor: Aqara
Product: Cloud Developer Portal
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-50020 MEDIUM - 5.3

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all ...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50011 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from t...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50010 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X50...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50009 MEDIUM - 4.8

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and stateless-reset-token generators. The reset token for the serv...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-48748 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked streams, which can cause OOM error. Version 4.2.15.Final patches t...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path. This issue has been patched in version 16.17.4.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-45833 HIGH - 8.8

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/col...

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-45832 HIGH - 8.8

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD