Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26401
Total
1955
Critical
7975
High
8228
Medium
CVE ID Severity Score Description Published
CVE-2026-7184 MEDIUM 6.5 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated … Jun 12, 2026
CVE-2026-6961 HIGH 7.6 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared … Jun 12, 2026
CVE-2026-6739 MEDIUM 6.7 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patching protected default system roles, … Jun 12, 2026
CVE-2026-6689 MEDIUM 4.3 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team … Jun 12, 2026
CVE-2026-6046 MEDIUM 5.3 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs … Jun 12, 2026
CVE-2026-53982 MEDIUM 6.5 Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering … Jun 12, 2026
CVE-2026-53981 HIGH 7.6 Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change … Jun 12, 2026
CVE-2026-47224 MEDIUM 4.3 NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap buffer-overflow read exists in the … Jun 12, 2026
CVE-2026-47222 MEDIUM 5.4 NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the … Jun 12, 2026
CVE-2026-3840 HIGH 7.1 A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()` method in `kedro/io/core.py` directly … Jun 12, 2026
CVE-2026-3433 MEDIUM 4.3 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_updated websocket event broadcasts to members of the … Jun 12, 2026
CVE-2026-9641 MEDIUM 5.3 Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used … Jun 12, 2026
CVE-2026-9638 HIGH 7.5 Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for … Jun 12, 2026
CVE-2026-8828 UNKNOWN A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or … Jun 12, 2026
CVE-2026-5792 MEDIUM 6.5 Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing … Jun 12, 2026
CVE-2026-53568 UNKNOWN Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerablity in Frappe Report/List View. This issue … Jun 12, 2026
CVE-2026-50560 UNKNOWN Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling … Jun 12, 2026
CVE-2026-50091 CRITICAL 9.1 Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded … Jun 12, 2026
CVE-2026-50090 CRITICAL 9.3 The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of … Jun 12, 2026
CVE-2026-50089 MEDIUM 6.1 The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of … Jun 12, 2026
CVE-2026-50088 HIGH 8.2 The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with … Jun 12, 2026
CVE-2026-50087 HIGH 8.2 The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has … Jun 12, 2026
CVE-2026-50086 CRITICAL 10.0 The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for … Jun 12, 2026
CVE-2026-50085 HIGH 8.6 The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of … Jun 12, 2026
CVE-2026-50084 CRITICAL 9.6 The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" … Jun 12, 2026