Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,852
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,141 - 6,160 of 34,996 CVEs
CVE-2026-46439 HIGH - 7.8

compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub
CVE-2026-46405 MEDIUM - 5.3

OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub
CVE-2026-46380 MEDIUM - 6.7

compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub
CVE-2026-45323 CRITICAL - 9.6

MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary javascript in the Home Assistant frontend of anyone viewi...

Vendor: jpettitt
Product: meshcore-card
Published: May 28, 2026
Source: NVD
CVE-2026-45307 MEDIUM - 6.1

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to validate post-login redirect targets applied urljoin(request.host_url, target) before parsing, while the controller passed the raw target to redirect(...

Vendor: murtaza-nasir
Product: speakr
Published: May 28, 2026
Source: NVD

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch. ProjectAuthorizer.__call__ (OSS api/auth/auth_project.py:14-38 and EE ee/api/auth/auth_project.py:14-46) only runs projects.is_autho...

Vendor: openreplay
Product: openreplay
Published: May 28, 2026
Source: NVD
CVE-2026-45296 HIGH - 7.7

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only that the API key itself is valid and that the target projectKey exists. The authorization flow does not veri...

Vendor: openreplay
Product: openreplay
Published: May 28, 2026
Source: NVD
CVE-2026-34126 HIGH - 7.5

TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker within the Bluetooth range...

Vendor: TP-Link Systems Inc., TP Link Systems Inc.
Product: Tapo L535E v1.0, v3.0, Tapo P300 v1.0, Tapo D100C v1.0
Published: May 28, 2026
Source: NVD

OpenBao's Inline Auth Incorrectly Redacted Headers

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub
CVE-2026-46345 HIGH - 8.4

compliance-trestle - jinja has an Arbitrary File Write via Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub

OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub

compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub

Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits โ€” ReDoS

Vendor: composer
Product: symfony/json-path
Published: May 28, 2026
Source: GitHub

Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC โ€” Unauthenticated Webhook Event Injection

Vendor: composer
Product: symfony/mailtrap-mailer
Published: May 28, 2026
Source: GitHub

Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret โ€” Unauthenticated Webhook Event Injection

Vendor: composer
Product: symfony/lox24-notifier
Published: May 28, 2026
Source: GitHub

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.io/otel/schema/v1.1` leaks one file descriptor on each successful `ParseFile` call. `ParseFile` opens the schema file and passes it to `Parse` without clo...

Vendor: go
Product: go.opentelemetry.io/otel/schema/v1.1
Published: May 28, 2026
Source: GitHub
CVE-2026-9098 CRITICAL - 9.1

In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identit...

Published: May 28, 2026
Source: NVD
CVE-2026-9097 CRITICAL - 9.8

Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and parses its claims, but never queries the Token table to verify whether the subject token has been revok...

Published: May 28, 2026
Source: NVD
CVE-2026-9096 HIGH - 7.5

Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are com...

Published: May 28, 2026
Source: NVD
CVE-2026-9095 HIGH - 8.1

Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache, OneTimeUse condition enforcem...

Published: May 28, 2026
Source: NVD