Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28433
Total
2190
Critical
8535
High
8856
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45296 | HIGH | 7.7 | OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only … | May 28, 2026 |
| CVE-2026-45058 | UNKNOWN | — | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users … | May 28, 2026 |
| CVE-2026-45021 | UNKNOWN | — | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and … | May 28, 2026 |
| CVE-2026-44798 | HIGH | 7.1 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record … | May 28, 2026 |
| CVE-2026-44797 | HIGH | 8.5 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could … | May 28, 2026 |
| CVE-2026-44796 | MEDIUM | 6.5 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable … | May 28, 2026 |
| CVE-2026-44794 | MEDIUM | 5.4 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a … | May 28, 2026 |
| CVE-2026-43898 | CRITICAL | 10.0 | SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback … | May 28, 2026 |
| CVE-2026-34126 | UNKNOWN | — | TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup … | May 28, 2026 |
| CVE-2026-9098 | UNKNOWN | — | In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to … | May 28, 2026 |
| CVE-2026-9097 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the … | May 28, 2026 |
| CVE-2026-9096 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the … | May 28, 2026 |
| CVE-2026-9095 | HIGH | 8.1 | Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the … | May 28, 2026 |
| CVE-2026-9094 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that … | May 28, 2026 |
| CVE-2026-9093 | UNKNOWN | — | In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go … | May 28, 2026 |
| CVE-2026-9092 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without … | May 28, 2026 |
| CVE-2026-9091 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code … | May 28, 2026 |
| CVE-2026-9090 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts … | May 28, 2026 |
| CVE-2026-8697 | UNKNOWN | — | Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses … | May 28, 2026 |
| CVE-2026-6720 | UNKNOWN | — | When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log … | May 28, 2026 |
| CVE-2026-47676 | MEDIUM | 5.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request … | May 28, 2026 |
| CVE-2026-47675 | MEDIUM | 4.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path … | May 28, 2026 |
| CVE-2026-47674 | MEDIUM | 5.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against … | May 28, 2026 |
| CVE-2026-47673 | MEDIUM | 4.8 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that … | May 28, 2026 |
| CVE-2026-45292 | MEDIUM | 5.3 | opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a … | May 28, 2026 |