Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,938
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,781 - 1,800 of 34,481 CVEs
CVE-2026-50083 CRITICAL - 9.1

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, C...

Vendor: Aqara
Product: Aquara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50082 MEDIUM - 6.5

The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium)....

Vendor: Aqara
Product: Cloud Developer Portal
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-50020 MEDIUM - 5.3

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all ...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50011 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from t...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50010 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X50...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50009 MEDIUM - 4.8

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and stateless-reset-token generators. The reset token for the serv...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-48748 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked streams, which can cause OOM error. Version 4.2.15.Final patches t...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path. This issue has been patched in version 16.17.4.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-45833 HIGH - 8.8

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/col...

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-45832 HIGH - 8.8

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-45831 HIGH - 8.8

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-45830 HIGH - 8.8

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versions 15.107.2 and 16.17.4.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-44967 MEDIUM - 5.3

OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is a...

Vendor: open-telemetry
Product: opentelemetry-cpp
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an endpoint. This issue has been patched in versions 15.107.2 and 16.17.4.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.

Vendor: AMD
Product: AMD Management Console (AMC), AMD Ryzen™ Master, AMD µProf
Published: Jun 12, 2026
Source: NVD