CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-100547
5.5 MEDIUM

OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over …

Sep 26, 2026
CVE-2026-100546
6.4 MEDIUM

OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts …

Sep 26, 2026
CVE-2026-100545
5.3 MEDIUM

OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that …

Sep 26, 2026
CVE-2026-100540
6.8 MEDIUM

OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account …

Sep 26, 2026
CVE-2026-100538
6.5 MEDIUM

OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has …

Sep 26, 2026
CVE-2026-100536
6.5 MEDIUM

OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. …

Sep 26, 2026
CVE-2026-100533
5.3 MEDIUM

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters …

Sep 26, 2026
CVE-2026-100531
6.5 MEDIUM

The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove …

Sep 26, 2026
CVE-2026-100529
6.4 MEDIUM

OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. Attackers …

Sep 26, 2026
CVE-2026-100528
5.4 MEDIUM

OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible …

Sep 26, 2026
CVE-2026-100527
5.3 MEDIUM

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can …

Sep 26, 2026
CVE-2026-100526
5.3 MEDIUM

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a …

Sep 26, 2026
CVE-2026-100525
4.3 MEDIUM

The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing …

Sep 26, 2026
CVE-2026-100524
5.4 MEDIUM

Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers …

Sep 26, 2026
CVE-2026-100523
6.1 MEDIUM

Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with …

Sep 26, 2026
CVE-2026-100522
6.1 MEDIUM

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. …

Sep 26, 2026
CVE-2026-100521
6.1 MEDIUM

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft …

Sep 26, 2026
CVE-2026-100505
4.4 MEDIUM

Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer …

Sep 26, 2026
CVE-2026-92842
5.9 MEDIUM

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the …

Sep 25, 2026
CVE-2026-91768
6.5 MEDIUM

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a …

Sep 25, 2026
CVE-2026-63432
6.5 MEDIUM

Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a user-controlled body at …

Sep 25, 2026
CVE-2026-63431
6.5 MEDIUM

Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_single_deduction before loading records …

Sep 25, 2026
CVE-2026-100502
5.0 MEDIUM

Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary …

Sep 25, 2026
CVE-2026-100501
6.5 MEDIUM

Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the …

Sep 25, 2026
CVE-2026-100418
5.3 MEDIUM

Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can …

Sep 25, 2026
CVE-2026-91769
4.3 MEDIUM

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires …

Sep 25, 2026
CVE-2026-91767
6.5 MEDIUM

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer …

Sep 25, 2026
CVE-2026-91766
5.9 MEDIUM

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a …

Sep 25, 2026
CVE-2026-6103
4.3 MEDIUM

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and …

Sep 25, 2026
CVE-2026-100388
5.4 MEDIUM

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. …

Sep 25, 2026
CVE-2025-14181
6.5 MEDIUM

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not …

Sep 25, 2026
CVE-2026-93682
5.8 MEDIUM

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte …

Sep 25, 2026
CVE-2026-100373
4.1 MEDIUM

OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users …

Sep 25, 2026
CVE-2026-97895
6.3 MEDIUM

A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing …

Sep 25, 2026
CVE-2026-100306
5.3 MEDIUM

TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can …

Sep 25, 2026
CVE-2026-100305
4.3 MEDIUM

TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a form's key …

Sep 25, 2026
CVE-2026-100304
5.3 MEDIUM

TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access …

Sep 25, 2026
CVE-2026-100303
5.4 MEDIUM

TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or …

Sep 25, 2026
CVE-2026-100192
6.5 MEDIUM

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and …

Sep 25, 2026
CVE-2026-97886
6.3 MEDIUM

A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file managevideos2.php. Such manipulation …

Sep 25, 2026
CVE-2026-97884
6.3 MEDIUM

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestudent.php of the component Student Update Functionality. …

Sep 25, 2026
CVE-2026-93366
5.4 MEDIUM

Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to …

Sep 25, 2026
CVE-2026-97879
5.3 MEDIUM

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the …

Sep 25, 2026
CVE-2026-93365
6.5 MEDIUM

Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of …

Sep 25, 2026
CVE-2026-93364
4.3 MEDIUM

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators …

Sep 25, 2026
CVE-2026-93363
4.3 MEDIUM

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route …

Sep 25, 2026
CVE-2026-18320
6.1 MEDIUM

Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule. This configuration …

Sep 25, 2026
CVE-2026-18312
6.1 MEDIUM

Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL …

Sep 25, 2026
CVE-2026-18311
6.1 MEDIUM

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as …

Sep 25, 2026
CVE-2026-100237
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects …

Sep 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.