Known Vulnerabilities for Core by @auth
Listed below are 10 of the newest known vulnerabilities associated with "Core" by "@auth".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73419 json | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js s... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-73418 json | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the expo... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-73247 json | Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/run... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-73241 json | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/co... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72912 json | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe p... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-72718 json | goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-71284 json | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the first ex... | Not Provided | 2026-08-05 | 2026-08-10 |
| CVE-2026-71283 json | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile.extr... | Not Provided | 2026-08-05 | 2026-08-10 |
| CVE-2026-71280 json | go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client wit... | Not Provided | 2026-08-05 | 2026-08-10 |
| CVE-2026-71268 json | OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) pr... | Not Provided | 2026-08-05 | 2026-08-10 |