Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26379
Total
1954
Critical
7969
High
8218
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44797 | HIGH | 8.5 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could … | May 28, 2026 |
| CVE-2026-44796 | MEDIUM | 6.5 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable … | May 28, 2026 |
| CVE-2026-44794 | MEDIUM | 5.4 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a … | May 28, 2026 |
| CVE-2026-43898 | CRITICAL | 10.0 | SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback … | May 28, 2026 |
| CVE-2026-34126 | UNKNOWN | — | TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup … | May 28, 2026 |
| CVE-2026-9098 | UNKNOWN | — | In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to … | May 28, 2026 |
| CVE-2026-9097 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the … | May 28, 2026 |
| CVE-2026-9096 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the … | May 28, 2026 |
| CVE-2026-9095 | HIGH | 8.1 | Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the … | May 28, 2026 |
| CVE-2026-9094 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that … | May 28, 2026 |
| CVE-2026-9093 | UNKNOWN | — | In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go … | May 28, 2026 |
| CVE-2026-9092 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without … | May 28, 2026 |
| CVE-2026-9091 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code … | May 28, 2026 |
| CVE-2026-9090 | UNKNOWN | — | Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts … | May 28, 2026 |
| CVE-2026-8697 | UNKNOWN | — | Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses … | May 28, 2026 |
| CVE-2026-6720 | UNKNOWN | — | When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log … | May 28, 2026 |
| CVE-2026-47676 | MEDIUM | 5.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request … | May 28, 2026 |
| CVE-2026-47675 | MEDIUM | 4.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path … | May 28, 2026 |
| CVE-2026-47674 | MEDIUM | 5.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against … | May 28, 2026 |
| CVE-2026-47673 | MEDIUM | 4.8 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that … | May 28, 2026 |
| CVE-2026-45292 | MEDIUM | 5.3 | opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a … | May 28, 2026 |
| CVE-2026-45261 | UNKNOWN | — | GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler desktop … | May 28, 2026 |
| CVE-2026-45078 | UNKNOWN | — | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead … | May 28, 2026 |
| CVE-2026-45076 | UNKNOWN | — | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that … | May 28, 2026 |
| CVE-2026-44543 | HIGH | 8.7 | Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with … | May 28, 2026 |