Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,981
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,761 - 1,780 of 34,478 CVEs
CVE-2026-47222 MEDIUM - 5.4

NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) vbmeta image parser in NanaZip (via the upstream 7-Zip AvbHandler). An unsigned integer underflow in a...

Vendor: M2Team
Product: NanaZip
Published: Jun 12, 2026
Source: NVD
CVE-2026-3840 HIGH - 7.1

A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()` method in `kedro/io/core.py` directly interpolates user-supplied version strings into filesystem paths without sanitization. This enables an attacker...

Vendor: linuxfoundation
Product: kedro
Published: Jun 12, 2026
Source: NVD
CVE-2026-3433 MEDIUM - 4.3

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_updated websocket event broadcasts to members of the affected team or channel which allows an authenticated attacker with guest-level access to observe permission scheme...

Published: Jun 12, 2026
Source: NVD
CVE-2026-9641 MEDIUM - 5.3

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterat...

Published: Jun 12, 2026
Source: NVD
CVE-2026-9638 HIGH - 7.5

Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

Published: Jun 12, 2026
Source: NVD

A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

Published: Jun 12, 2026
Source: NVD
CVE-2026-5792 MEDIUM - 6.5

Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing Cloud (RMC): through 12052026.

Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerablity in Frappe Report/List View. This issue has been patched in versions 15.107.2 and 16.17.4.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-50560 MEDIUM - 5.3

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADE...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50091 CRITICAL - 9.1

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H...

Vendor: Aqara
Product: com.lumiunited.aqarahome
Published: Jun 12, 2026
Source: NVD
CVE-2026-50090 CRITICAL - 9.3

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L...

Vendor: Aqara
Product: Cloud OAuth Authorization Endpoint
Published: Jun 12, 2026
Source: NVD
CVE-2026-50089 MEDIUM - 6.1

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (6.1 Medium), which can be used to set up a phishing attack.

Vendor: Aqara
Product: Aqara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50088 HIGH - 8.2

The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3....

Vendor: Aqara
Product: Aqara Developer Portal, Aqara Developer Test Portal
Published: Jun 12, 2026
Source: NVD
CVE-2026-50087 HIGH - 8.2

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N (8.2 High).

Vendor: Aqara
Product: Aqara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50086 CRITICAL - 10.0

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Al...

Vendor: Aqara
Product: Aqara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50085 HIGH - 8.6

The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/P...

Vendor: Aqara
Product: Board service
Published: Jun 12, 2026
Source: NVD
CVE-2026-50084 CRITICAL - 9.6

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N (9.6 Critical). When combined...

Vendor: Aqara
Product: Cloud Production API
Published: Jun 12, 2026
Source: NVD
CVE-2026-50083 CRITICAL - 9.1

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, C...

Vendor: Aqara
Product: Aquara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50082 MEDIUM - 6.5

The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium)....

Vendor: Aqara
Product: Cloud Developer Portal
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD