Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-53568

Frappe: Stored XSS in Frappe Report/List View via ‘set_link_title_field_value’_CVE-2026-53568

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerablity in Frappe Report/List ...

frappe frappe < 15.107.2 CVE
MEDIUM 6.9 CVE-2026-50560

Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature_CVE-2026-50560

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty H...

netty netty >= 4.2.0.Final, < 4.2.15.Final CVE
CRITICAL 9.1 CVE-2026-50091

Aqara Home Android SDK hardcoded keys_CVE-2026-50091

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic key...

Aqara com.lumiunited.aqarahome 6.0.0 CVE
CRITICAL 9.3 CVE-2026-50090

Aqara OAuth redirect_uri validation bypass_CVE-2026-50090

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain m...

Aqara Cloud OAuth Authorization Endpoint 2026-04-20 CVE
MEDIUM 6.1 CVE-2026-50089

Aqara IAM/SSO Gateway open redirect_CVE-2026-50089

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," w...

Aqara Aqara IAM/SSO Gateway 2026-04-20 CVE
HIGH 8.2 CVE-2026-50088

Aqara Developer Portal cross-origin resource sharing_CVE-2026-50088

The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin ...

Aqara Aqara Developer Portal 2026-04-20 CVE
HIGH 8.2 CVE-2026-50087

Aqara IAM/SSO Gateway cross-origin resource sharing_CVE-2026-50087

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissiv...

Aqara Aqara IAM/SSO Gateway 2026-04-20 CVE
CRITICAL 10 CVE-2026-50086

Aqara unauthenticated AES oracle_CVE-2026-50086

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. T...

Aqara Aqara IAM/SSO Gateway 2026-04-20 CVE
HIGH 8.6 CVE-2026-50085

Aqara Board IoT insecure debug API_CVE-2026-50085

The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authe...

Aqara Board service 2026-04-20 CVE
CRITICAL 9.6 CVE-2026-50084

Aqara API cross-account access_CVE-2026-50084

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an in...

Aqara Cloud Production API 2026-04-20 CVE