This page aggregates publicly disclosed CVE and security risk information related to jetkvm, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-32295 | JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials. | 9119a7d8-5eab-497f-8521-727c672e3725 | 9.3 | 0.49% | 2026-03-17 | 2026-04-10 |
| CVE-2026-32294 | JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification. | 9119a7d8-5eab-497f-8521-727c672e3725 | 7.0 | 0.13% | 2026-03-17 | 2026-04-10 |