Known Vulnerabilities for Robot-js by Getrobot
Listed below are 1 of the newest known vulnerabilities associated with "Robot-js" by "Getrobot".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-43404 json | In the Linux kernel, the following vulnerability has been resolved: mm: Fix a hmm_range_fault() livelock / starvation proble... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-27509 json | Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization f... | Not Provided | 2026-02-26 | 2026-05-26 |
| CVE-2026-25874 json | LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() i... | Not Provided | 2026-04-23 | 2026-07-14 |
| CVE-2026-23025 json | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: prevent pcp corruption with SMP=n The ke... | Not Provided | 2026-01-31 | 2026-06-02 |
| CVE-2026-10557 json | The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all de... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-8153 json | OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenti... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-7415 json | The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or wr... | Not Provided | 2026-05-07 | 2026-05-07 |
| CVE-2026-7368 json | The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the s... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2025-64307 json | The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user... | Not Provided | 2025-11-15 | 2026-06-25 |
| CVE-2025-39409 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pressaholic WordPress V... | Not Provided | 2025-05-19 | 2026-04-28 |