Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-50086
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. Thi…
Iam\/sso Gateway
Mitigation only
CRITICAL 9.8
CVE-2026-50085
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authent…
Board Service
Mitigation only
HIGH 7.4
CVE-2026-50091
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys,…
Home
No fix yet
MEDIUM 6.1
CVE-2026-50087
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive …
Iam\/sso Gateway
No fix yet
MEDIUM 6.1
CVE-2026-50089
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," wit…
Iam\/sso Gateway
No fix yet
MEDIUM 6.1
CVE-2026-50090
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain mat…
Cloud Oauth Authorization Endpoint
No fix yet
CRITICAL 9.8
CVE-2026-50083
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Creden…
Iam\/sso Gateway
Mitigation only
MEDIUM 6.5
CVE-2026-50084
The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an inst…
Cloud Production Api
No fix yet
MEDIUM 5.3
CVE-2026-50082
The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of…
Cloud Developer Portal
No fix yet
CRITICAL 9.8
CVE-2025-65294
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabli…
Hub M2 Firmware
Mitigation only
HIGH 8.1
CVE-2025-65295
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allo…
Hub M2 Firmware
No fix yet
HIGH 7.5
CVE-2025-65297
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive…
Hub M2 Firmware
Mitigation only
MEDIUM 6.5
CVE-2025-65296
NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable de…
Hub M2 Firmware
No fix yet
HIGH 7.4
CVE-2025-65290
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firm…
Hub M2 Firmware
No fix yet
HIGH 7.4
CVE-2025-65291
Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections fo…
Hub M2 Firmware
No fix yet
HIGH 7.3
CVE-2025-65292
Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to…
Hub M2 Firmware
No fix yet
MEDIUM 6.6
CVE-2025-65293
Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malici…
Camera Hub G3 Firmware
No fix yet