CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-100629
5.5 MEDIUM

Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The handler verifies that the newly assigned role's priority rank does …

Sep 26, 2026
CVE-2026-100628
4.3 MEDIUM

capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply …

Sep 26, 2026
CVE-2026-100626
4.3 MEDIUM

capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that accepts attacker-controlled icon storage paths. Authenticated users can supply …

Sep 26, 2026
CVE-2026-100624
5.4 MEDIUM

Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy endpoint. When a native build request is created, …

Sep 26, 2026
CVE-2026-100621
4.3 MEDIUM

Capgo (capgo.app) contains an incomplete access-control/content-lock enforcement issue affecting all versions; no patch is available at the time of publication. The `enforce_encrypted_bundle_trigger` / `check_encrypted_bundle_on_insert` content …

Sep 26, 2026
CVE-2026-100616
5.5 MEDIUM

capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security UPDATE policy on the public.orgs table …

Sep 26, 2026
CVE-2026-100613
5.3 MEDIUM

capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time …

Sep 26, 2026
CVE-2026-100611
6.5 MEDIUM

Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user …

Sep 26, 2026
CVE-2026-100609
6.8 MEDIUM

Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with …

Sep 26, 2026
CVE-2026-100604
5.4 MEDIUM

ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle …

Sep 26, 2026
CVE-2026-100603
5.4 MEDIUM

ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic …

Sep 26, 2026
CVE-2026-100602
6.5 MEDIUM

ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill …

Sep 26, 2026
CVE-2026-100601
5.3 MEDIUM

ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks …

Sep 26, 2026
CVE-2026-100600
5.3 MEDIUM

ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single …

Sep 26, 2026
CVE-2026-100313
4.3 MEDIUM

A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. Executing a manipulation of the …

Sep 26, 2026
CVE-2026-100312
6.3 MEDIUM

A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a …

Sep 26, 2026
CVE-2026-96533
5.8 MEDIUM

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, …

Sep 26, 2026
CVE-2026-96531
6.8 MEDIUM

The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users …

Sep 26, 2026
CVE-2026-92411
6.8 MEDIUM

The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it …

Sep 26, 2026
CVE-2026-89237
6.8 MEDIUM

The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers …

Sep 26, 2026
CVE-2026-84097
6.5 MEDIUM

The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using …

Sep 26, 2026
CVE-2026-19708
5.9 MEDIUM

The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under …

Sep 26, 2026
CVE-2026-11871
5.3 MEDIUM

The Team Members WordPress plugin before 9.3 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member …

Sep 26, 2026
CVE-2026-15273
6.4 MEDIUM

The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escaping. …

Sep 26, 2026
CVE-2026-100595
6.5 MEDIUM

OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles. …

Sep 26, 2026
CVE-2026-100594
6.5 MEDIUM

OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers …

Sep 26, 2026
CVE-2026-100593
5.4 MEDIUM

OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel …

Sep 26, 2026
CVE-2026-100592
6.3 MEDIUM

OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized …

Sep 26, 2026
CVE-2026-100591
6.3 MEDIUM

OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender …

Sep 26, 2026
CVE-2026-100590
4.3 MEDIUM

OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with …

Sep 26, 2026
CVE-2026-100584
6.7 MEDIUM

OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could …

Sep 26, 2026
CVE-2026-100583
4.3 MEDIUM

OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel …

Sep 26, 2026
CVE-2026-100582
6.5 MEDIUM

OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, …

Sep 26, 2026
CVE-2026-100581
5.5 MEDIUM

OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted …

Sep 26, 2026
CVE-2026-100577
6.3 MEDIUM

OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can …

Sep 26, 2026
CVE-2026-100576
5.4 MEDIUM

OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations. …

Sep 26, 2026
CVE-2026-100574
5.9 MEDIUM

OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, …

Sep 26, 2026
CVE-2026-100572
5.3 MEDIUM

OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy …

Sep 26, 2026
CVE-2026-100571
5.3 MEDIUM

OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients only …

Sep 26, 2026
CVE-2026-100569
5.5 MEDIUM

OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so an …

Sep 26, 2026
CVE-2026-100566
6.5 MEDIUM

OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits DM allowFrom values when groupAllowFrom is not explicitly configured. …

Sep 26, 2026
CVE-2026-100564
5.4 MEDIUM

OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within attendance CSV exports. Attackers can inject formula-like cells that execute …

Sep 26, 2026
CVE-2026-100563
5.4 MEDIUM

OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interpret as formulas when the Control UI exports session data to …

Sep 26, 2026
CVE-2026-100562
5.4 MEDIUM

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. …

Sep 26, 2026
CVE-2026-100556
6.3 MEDIUM

OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted …

Sep 26, 2026
CVE-2026-100554
4.2 MEDIUM

OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation …

Sep 26, 2026
CVE-2026-100553
4.3 MEDIUM

OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin …

Sep 26, 2026
CVE-2026-100550
5.4 MEDIUM

OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported …

Sep 26, 2026
CVE-2026-100549
5.4 MEDIUM

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear …

Sep 26, 2026
CVE-2026-100548
5.3 MEDIUM

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured …

Sep 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.