Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2233148
AlmaLinux
5964
Alpaquita
16148
Alpine
4635
Android
3677
Azure Linux
17766
BellSoft Hardened Containers
764
Bitnami
9476
Chainguard
1043375
CleanStart
5235
CRAN
14
crates.io
2748
Debian
68825
Echo
7749
GHC
3
GIT
108734
GitHub Actions
55
Go
9319
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7048
MinimOS
147720
npm
229081
NuGet
1869
opam
29
openEuler
8900
openSUSE
14526
OSS-Fuzz
4015
Packagist
7100
Pub
11
PyPI
25416
Red Hat
23452
Rocky Linux
4334
Root
19620
RubyGems
5326
SUSE
23401
SwiftURL
60
TuxCare
9810
Ubuntu
65806
VSCode
21
Wolfi
292794
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-49439
github.com/openremote/openremote
OpenRemote read-only asset users can write predicted datapoints
11 Sep
Fix available
Severity - 4.3 (Medium)
CVE-2026-81679
github.com/openremote/openremote
OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API
27 Aug
Fix available
Severity - 8.3 (High)
CVE-2026-67310
github.com/openremote/openremote
openremote before 1.27.0 Cross-Tenant IDOR via setAssetLinks
01 Aug
Fix available
Severity - 5.3 (Medium)
CVE-2026-66013
github.com/openremote/openremote
OpenRemote before 1.26.2 Authentication Bypass via Console Registration
25 Jul
Fix available
Severity - 9.3 (Critical)
CVE-2026-65009
github.com/openremote/openremote
OpenRemote before 1.26.2 Information Disclosure via Syslog REST API
21 Jul
Fix available
Severity - 5.3 (Medium)
CVE-2026-62238
github.com/openremote/openremote
OpenRemote < 1.26.0 SQL Injection via Crosstab Export
17 Jul
Fix available
Severity - 7.2 (High)
GHSA-cgfv-jrfp-2r7v
Maven/io.openremote:openremote-manager
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
06 Jul
Fix available
Severity - 7.2 (High)
GHSA-7v6w-c3f4-9wpq
Maven/io.openremote:openremote-agent
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
06 Jul
Fix available
Severity - 7.6 (High)
GHSA-xqr9-4wvv-gvch
Maven/io.openremote:openremote-manager
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
06 Jul
Fix available
Severity - 7.7 (High)
GHSA-xj53-j257-hxvg
Maven/io.openremote:openremote-manager
OpenRemote read-only asset users can write predicted datapoints
06 Jul
Fix available
Severity - 4.3 (Medium)
CVE-2026-56784
github.com/openremote/openremote
OpenRemote < 1.25.0 IDOR via Bulk Alarm Deletion Endpoint
23 Jun
Fix available
Severity - 8.6 (High)
GHSA-h3m5-97jq-qjrf
Maven/io.openremote:openremote-manager
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
19 Jun
Fix available
Severity - 9.6 (Critical)
CVE-2026-40882
github.com/openremote/openremote
OpenRemote has XXE in Velbus Asset Import
22 Apr
Fix available
Severity - 7.6 (High)
CVE-2026-41166
github.com/openremote/openremote
OpenRemote has Improper Access Control via updateUserRealmRoles function
22 Apr
Fix available
Severity - 7.0 (High)
GHSA-49vv-25qx-mg44
Maven/io.openremote:openremote-manager
OpenRemote has Improper Access Control via updateUserRealmRoles function
22 Apr
Fix available
Severity - 7.0 (High)
GHSA-g24f-mgc3-jwwc
Maven/io.openremote:openremote-manager
OpenRemote has XXE in Velbus Asset Import
15 Apr
Fix available
Severity - 7.6 (High)
Load more...
Vulnerability Database - OSV