Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242897
AlmaLinux
5975
Alpaquita
16181
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
771
Bitnami
9501
Chainguard
1048720
CleanStart
5479
CRAN
14
crates.io
2768
Debian
68994
Echo
7867
GHC
3
GIT
109123
GitHub Actions
55
Go
9332
Hackage
33
Hex
367
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148690
npm
229272
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4354
Root
19660
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9977
Ubuntu
66090
VSCode
21
Wolfi
293843
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-49439
github.com/openremote/openremote
OpenRemote read-only asset users can write predicted datapoints
11 Sep
Fix available
Severity - 4.3 (Medium)
CVE-2026-81679
github.com/openremote/openremote
OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API
27 Aug
Fix available
Severity - 8.3 (High)
CVE-2026-67310
github.com/openremote/openremote
openremote before 1.27.0 Cross-Tenant IDOR via setAssetLinks
01 Aug
Fix available
Severity - 5.3 (Medium)
CVE-2026-66013
github.com/openremote/openremote
OpenRemote before 1.26.2 Authentication Bypass via Console Registration
25 Jul
Fix available
Severity - 9.3 (Critical)
CVE-2026-65009
github.com/openremote/openremote
OpenRemote before 1.26.2 Information Disclosure via Syslog REST API
21 Jul
Fix available
Severity - 5.3 (Medium)
CVE-2026-62238
github.com/openremote/openremote
OpenRemote < 1.26.0 SQL Injection via Crosstab Export
17 Jul
Fix available
Severity - 7.2 (High)
GHSA-cgfv-jrfp-2r7v
Maven/io.openremote:openremote-manager
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
06 Jul
Fix available
Severity - 7.2 (High)
GHSA-7v6w-c3f4-9wpq
Maven/io.openremote:openremote-agent
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
06 Jul
Fix available
Severity - 7.6 (High)
GHSA-xqr9-4wvv-gvch
Maven/io.openremote:openremote-manager
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
06 Jul
Fix available
Severity - 7.7 (High)
GHSA-xj53-j257-hxvg
Maven/io.openremote:openremote-manager
OpenRemote read-only asset users can write predicted datapoints
06 Jul
Fix available
Severity - 4.3 (Medium)
CVE-2026-56784
github.com/openremote/openremote
OpenRemote < 1.25.0 IDOR via Bulk Alarm Deletion Endpoint
23 Jun
Fix available
Severity - 8.6 (High)
GHSA-h3m5-97jq-qjrf
Maven/io.openremote:openremote-manager
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
19 Jun
Fix available
Severity - 9.6 (Critical)
CVE-2026-40882
github.com/openremote/openremote
OpenRemote has XXE in Velbus Asset Import
22 Apr
Fix available
Severity - 7.6 (High)
CVE-2026-41166
github.com/openremote/openremote
OpenRemote has Improper Access Control via updateUserRealmRoles function
22 Apr
Fix available
Severity - 7.0 (High)
GHSA-49vv-25qx-mg44
Maven/io.openremote:openremote-manager
OpenRemote has Improper Access Control via updateUserRealmRoles function
22 Apr
Fix available
Severity - 7.0 (High)
GHSA-g24f-mgc3-jwwc
Maven/io.openremote:openremote-manager
OpenRemote has XXE in Velbus Asset Import
15 Apr
Fix available
Severity - 7.6 (High)
Load more...
Vulnerability Database - OSV