Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26401
Total
1955
Critical
7975
High
8228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-50083 | CRITICAL | 9.1 | The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an … | Jun 12, 2026 |
| CVE-2026-50082 | MEDIUM | 6.5 | The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing … | Jun 12, 2026 |
| CVE-2026-50026 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to … | Jun 12, 2026 |
| CVE-2026-50020 | MEDIUM | 5.3 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` … | Jun 12, 2026 |
| CVE-2026-50011 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity … | Jun 12, 2026 |
| CVE-2026-50010 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any … | Jun 12, 2026 |
| CVE-2026-50009 | MEDIUM | 4.8 | Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on … | Jun 12, 2026 |
| CVE-2026-48748 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 … | Jun 12, 2026 |
| CVE-2026-48059 | UNKNOWN | — | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec … | Jun 12, 2026 |
| CVE-2026-48043 | MEDIUM | 5.3 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates … | Jun 12, 2026 |
| CVE-2026-48006 | UNKNOWN | — | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled … | Jun 12, 2026 |
| CVE-2026-47691 | HIGH | 8.7 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick … | Jun 12, 2026 |
| CVE-2026-47190 | MEDIUM | 4.4 | IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD … | Jun 12, 2026 |
| CVE-2026-47182 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path. This issue … | Jun 12, 2026 |
| CVE-2026-46690 | MEDIUM | 5.8 | unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race. At … | Jun 12, 2026 |
| CVE-2026-45833 | UNKNOWN | — | A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server … | Jun 12, 2026 |
| CVE-2026-45832 | UNKNOWN | — | All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls … | Jun 12, 2026 |
| CVE-2026-45831 | UNKNOWN | — | The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks … | Jun 12, 2026 |
| CVE-2026-45830 | UNKNOWN | — | A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or … | Jun 12, 2026 |
| CVE-2026-44976 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has … | Jun 12, 2026 |
| CVE-2026-44975 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. … | Jun 12, 2026 |
| CVE-2026-44967 | MEDIUM | 5.3 | OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector … | Jun 12, 2026 |
| CVE-2026-44208 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to … | Jun 12, 2026 |
| CVE-2026-44207 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration … | Jun 12, 2026 |
| CVE-2026-44206 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an endpoint. This issue has … | Jun 12, 2026 |