CVE Tools

Core

119 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Core, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Core CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Core CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-031
2025-043
2025-050
2025-060
2025-070
2025-080
2025-091
2025-103
2025-110
2025-120
2026-011
2026-024
2026-0317
2026-045
2026-0514
2026-064
2026-074
2026-089
2026-098

Severity

How the 119 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1614%
  • High4741%
  • Medium4943%
  • Low22%

Latest CVEs

The 15 most recently published vulnerabilities affecting Core.

  1. CVE-2026-63000REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates6.4
  2. CVE-2026-62998REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration4.3
  3. CVE-2026-63002REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames4.8
  4. CVE-2026-63001REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`4.8
  5. CVE-2026-91129Home Assistant: mDNS Server-Side Request Forgery5.4
  6. CVE-2026-91130Home Assistant: XSS in Statistics Graph Card—
  7. CVE-2026-53581ntp: write path traversal9.0
  8. CVE-2026-85093Cheshire Cat AI Memory Collection Endpoint Information Disclosure6.5
  9. CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)9.1
  10. CVE-2026-73420NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass—
  11. CVE-2026-73419NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them6.8
  12. CVE-2026-73418NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers7.5
  13. CVE-2026-66061Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution7.1
  14. CVE-2026-66060Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers7.1
  15. CVE-2026-59717Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing4.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store