Known Vulnerabilities for Led Strip by Govee
Listed below are 2 of the newest known vulnerabilities associated with "Led Strip" by "Govee".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65900 json | DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65694 json | Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticat... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-65603 json | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-63886 json | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base6... | Not Provided | 2026-07-19 | 2026-07-20 |
| CVE-2026-63799 json | In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET ... | Not Provided | 2026-07-19 | 2026-07-20 |
| CVE-2026-62233 json | grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, all... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-60032 json | The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/write... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-59875 json | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path ... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-56298 json | Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive ... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-56218 json | Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information ... | Not Provided | 2026-06-20 | 2026-06-23 |