| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-33510 | DOM-Based XSS in Homarr /auth/login Redirect | homarr-labs | homarr | High | 8.8 | 2026-04-06 14:51:39 | Deep Dive |
| CVE-2026-32602 | Homarr has a Race Condition in Invite Token Registration (TOCTOU) | homarr-labs | homarr | Medium | 4.2 | 2026-04-06 14:42:37 | Deep Dive |
| CVE-2026-27796 | Homarr: Unauthenticated Information Disclosure (Integration Metadata Leak) | homarr-labs | homarr | Medium | 5.3 | 2026-03-07 05:54:49 | Deep Dive |
| CVE-2026-27797 | Homarr: Unauthenticated SSRF in rssFeed.ts | homarr-labs | homarr | Medium | 5.3 | 2026-03-07 05:54:32 | Deep Dive |
| CVE-2026-25123 | Homarr affected by Unauthenticated SSRF / Port-Scan Primitive via widget.app.ping | homarr-labs | homarr | Medium | 5.3 | 2026-02-06 21:19:40 | Deep Dive |
| CVE-2025-67493 | Homarr issing input sanitization and possible privilege escalation through ldap search query injection | homarr-labs | homarr | High | 7.5 | 2025-12-17 21:09:44 | Deep Dive |
| CVE-2025-64759 | Homarr is Vulnerable to Stored Cross-Site Scripting (XSS) and Possible Privilege Escalation via Malicious SVG Upload | homarr-labs | homarr | High | 8.1 | 2025-11-19 18:44:09 | Deep Dive |