Security Advisories

Vulnerability disclosures and security advisories published by Zyenra Security.

CVE IDTitleVendorSeverityType
CVE-2026-38651JWT Verification Bypass in Netmaker Allows Unauthenticated Access to Host EndpointsGravitlCriticalAuth Bypass
CVE-2024-42640Unauthenticated Remote Code Execution via Angular-Base64-Upload Library-CriticalRCE
CVE-2024-57514XSS in TP-Link A20 v3 RouterTP-LinkLowXSS
CVE-2025-51569XSS in LB-Link BL-CPE300M AX300 4G LTE RouterLB-LinkMediumXSS
CVE-2025-57278Improper IP Bound Session Authentication in LB-Link BL-CPE300M AX300 4G LTE RouterLB-LinkHighAuth Bypass
CVE-2025-62719LinkAce Limited Server-Side Request Forgery (SSRF) in Keyword Fetching FunctionalityLinkAceMediumSSRF
CVE-2025-62720LinkAce - Data Exfiltration via Export Functions Allowing Access to All Users' Private LinksLinkAceMediumData Exfiltration
CVE-2025-62721LinkAce Authorization Bypass Allowing Unauthorized Access to All Private Links, Lists, and Tags via RSS Feed EndpointsLinkAceMediumAuth Bypass
CVE-2025-62722LinkAce - Stored XSS Vulnerability in Link Title Field Through Social Media Sharing FunctionalityLinkAceMediumXSS
CVE-2025-66291Unauthorized Access to Interview Attachments via Direct Object ReferenceOrangeHRMMediumIDOR
CVE-2026-25118Insecure Transmission of Shared Link PasswordImmichMediumCredential Disclosure
CVE-2026-27458Stored XSS in Atom Feed via CDATA Escape in List DescriptionLinkAceHighXSS
CVE-2026-29097Server-Side Request Forgery and Denial of Service via RSS Feed DashletSuiteCRMHighSSRF / DoS
CVE-2026-29109Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Filter ProcessingSuiteCRMHighRCE
GHSA-5qpc-x7rv-hvmpServer-Side Request Forgery (SSRF) in Linkwarden Link Creation via fetchTitleAndHeaders FunctionLinkwardenCriticalSSRF
CVE-2026-39349Use of AES-ECB for Sensitive Data Encryption Enables Pattern DisclosureOrangeHRMLowCryptographic Weakness

16 published advisories