CVE Vulnerability Database

Search and browse 395,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-50089MEDIUM6.1The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire...
CVE-2026-50088MEDIUM4.7The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara...
CVE-2026-50087MEDIUM6.1The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an inst...
CVE-2026-50086CRITICAL9.8The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing ke...
CVE-2026-50085CRITICAL9.8The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's ...
CVE-2026-50084MEDIUM6.5The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to...
CVE-2026-50083CRITICAL9.8The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-...
CVE-2026-50082MEDIUM5.3The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the att...
CVE-2026-50026MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in...
CVE-2026-50020MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50011HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50010HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50009MEDIUM4.8Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,...
CVE-2026-48748HIGH7.5Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Fina...
CVE-2026-48059HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-48043HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to ...
CVE-2026-48006HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-47691CRITICAL10Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-47190MEDIUM4.4IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM c...
CVE-2026-47182MEDIUM5.3Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private fi...
CVE-2026-46690MEDIUM5.8unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-v...
CVE-2026-45833HIGH8.8A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke...
CVE-2026-45832HIGH8.8All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorizatio...
CVE-2026-45831HIGH8.8The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project eva...
CVE-2026-45830HIGH8.8A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us...