Security Advisories

Vulnerability disclosures and security advisories published by Zyenra Security.

CVE IDTitleVendorSeverityType
CVE-2026-38651JWT Verification Bypass in Netmaker Allows Unauthenticated Access to Host EndpointsGravitlCriticalAuth Bypass (CWE-287)
CVE-2024-42640Unauthenticated Remote Code Execution via Angular-Base64-Upload LibraryAdones PitogoCriticalRCE (CWE-434)
CVE-2024-57514XSS in TP-Link A20 v3 RouterTP-LinkLowXSS (CWE-79)
CVE-2025-51569XSS in LB-Link BL-CPE300M AX300 4G LTE RouterLB-LinkMediumXSS (CWE-79)
CVE-2025-57278Improper IP Bound Session Authentication in LB-Link BL-CPE300M AX300 4G LTE RouterLB-LinkHighAuth Bypass (CWE-287)
CVE-2025-62719LinkAce Limited Server-Side Request Forgery (SSRF) in Keyword Fetching FunctionalityLinkAceMediumSSRF (CWE-918)
CVE-2025-62720LinkAce - Data Exfiltration via Export Functions Allowing Access to All Users' Private LinksLinkAceMediumData Exfiltration (CWE-862)
CVE-2025-62721LinkAce Authorization Bypass Allowing Unauthorized Access to All Private Links, Lists, and Tags via RSS Feed EndpointsLinkAceMediumAuth Bypass (CWE-862)
CVE-2025-62722LinkAce - Stored XSS Vulnerability in Link Title Field Through Social Media Sharing FunctionalityLinkAceMediumXSS (CWE-79)
CVE-2025-66291Unauthorized Access to Interview Attachments via Direct Object ReferenceOrangeHRMMediumIDOR (CWE-639)
CVE-2026-25118Insecure Transmission of Shared Link PasswordImmichMediumCredential Disclosure (CWE-598)
CVE-2026-27458Stored XSS in Atom Feed via CDATA Escape in List DescriptionLinkAceHighXSS (CWE-80)
CVE-2026-29097Server-Side Request Forgery and Denial of Service via RSS Feed DashletSuiteCRMHighSSRF / DoS (CWE-918)
CVE-2026-29109Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Filter ProcessingSuiteCRMHighRCE (CWE-502)
CVE-2026-44313Server-Side Request Forgery (SSRF) in Linkwarden Link Creation via fetchTitleAndHeaders FunctionLinkwardenCriticalSSRF (CWE-918)
CVE-2026-44522Arbitrary File Write via Path Traversal in Asset Names Leading to Remote Code ExecutionNote MarkHighArbitrary File Write / RCE (CWE-22)
CVE-2026-39349Use of AES-ECB for Sensitive Data Encryption Enables Pattern DisclosureOrangeHRMLowCryptographic Weakness (CWE-327)
CVE-2026-45342IDOR in Update Policies Allows Any Authenticated User to Overwrite Other Users' Links, Lists, Tags, and NotesLinkAceHighIDOR (CWE-639)
CVE-2026-45343Stored XSS via Unsanitized SSO User's Name Rendered in Admin Audit Log Allows Session HijackingLinkAceHighXSS (CWE-79)

19 published advisories