Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,811
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,841 - 7,860 of 36,689 CVEs
CVE-2026-34126 HIGH - 7.5

TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker within the Bluetooth range...

Vendor: TP-Link Systems Inc., TP Link Systems Inc.
Product: Tapo L535E v1.0, v3.0, Tapo P300 v1.0, Tapo D100C v1.0
Published: May 28, 2026
Source: NVD

OpenBao's Inline Auth Incorrectly Redacted Headers

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub
CVE-2026-46345 HIGH - 8.4

compliance-trestle - jinja has an Arbitrary File Write via Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub

OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub

compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub

Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS

Vendor: composer
Product: symfony/json-path
Published: May 28, 2026
Source: GitHub

Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection

Vendor: composer
Product: symfony/mailtrap-mailer
Published: May 28, 2026
Source: GitHub

Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection

Vendor: composer
Product: symfony/lox24-notifier
Published: May 28, 2026
Source: GitHub

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.io/otel/schema/v1.1` leaks one file descriptor on each successful `ParseFile` call. `ParseFile` opens the schema file and passes it to `Parse` without clo...

Vendor: go
Product: go.opentelemetry.io/otel/schema/v1.1
Published: May 28, 2026
Source: GitHub
CVE-2026-9098 CRITICAL - 9.1

In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identit...

Published: May 28, 2026
Source: NVD
CVE-2026-9097 CRITICAL - 9.8

Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and parses its claims, but never queries the Token table to verify whether the subject token has been revok...

Published: May 28, 2026
Source: NVD
CVE-2026-9096 HIGH - 7.5

Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are com...

Published: May 28, 2026
Source: NVD
CVE-2026-9095 HIGH - 8.1

Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache, OneTimeUse condition enforcem...

Published: May 28, 2026
Source: NVD
CVE-2026-9094 CRITICAL - 9.8

Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. Thi...

Published: May 28, 2026
Source: NVD
CVE-2026-9093 CRITICAL - 9.8

In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudie...

Published: May 28, 2026
Source: NVD
CVE-2026-9092 CRITICAL - 9.1

Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the email_verified claim from upstream providers; the idp.UserInfo struct does not even inc...

Published: May 28, 2026
Source: NVD
CVE-2026-9091 MEDIUM - 5.3

Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn directly without invoking checkMfaEnable. Any user authenticating via this path i...

Published: May 28, 2026
Source: NVD
CVE-2026-9090 CRITICAL - 9.1

Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-co...

Published: May 28, 2026
Source: NVD
CVE-2026-8697 HIGH - 8.8

Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. Successful exploitati...

Vendor: tp-link
Product: archer_c64_firmware
Published: May 28, 2026
Source: NVD

When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the cluster — inline kubeconfig (with bearer token), Ku...

Published: May 28, 2026
Source: NVD