CVE Database

46976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-23773
4.3 MEDIUM

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit …

Apr 29, 2026
CVE-2026-7340
4.3 MEDIUM

Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via …

Apr 28, 2026
CVE-2026-7318
5.9 MEDIUM

A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic …

Apr 28, 2026
CVE-2026-7317
5.0 MEDIUM

A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component …

Apr 28, 2026
CVE-2026-7306
5.6 MEDIUM

A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the …

Apr 28, 2026
CVE-2026-7305
6.3 MEDIUM

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component …

Apr 28, 2026
CVE-2026-37750
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the …

Apr 28, 2026
CVE-2026-33467
5.9 MEDIUM

Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents …

Apr 28, 2026
CVE-2026-7293
4.7 MEDIUM

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of the file /admin/ajax.php?action=delete_category. The manipulation of the argument ID …

Apr 28, 2026
CVE-2026-7292
5.6 MEDIUM

A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAgent. The …

Apr 28, 2026
CVE-2026-7291
6.3 MEDIUM

A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of the component URL Fetching. Executing …

Apr 28, 2026
CVE-2026-7290
6.3 MEDIUM

A vulnerability was determined in JeecgBoot up to 3.9.1. Impacted is the function SqlInjectionUtil of the file jeecg-boot/jeecg-boot-base-core/src/main/java/org/jeecg/common/util/SqlInjectionUtil.java of the component loadDict Endpoint. This manipulation …

Apr 28, 2026
CVE-2026-6807
5.5 MEDIUM

A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. …

Apr 28, 2026
CVE-2026-6238
6.5 MEDIUM

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA …

Apr 28, 2026
CVE-2026-42430
6.5 MEDIUM

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allows attackers to bypass strict SSRF checks. Attackers can exploit request-time …

Apr 28, 2026
CVE-2026-42427
5.3 MEDIUM

OpenClaw before 2026.4.8 contains a remote code execution vulnerability caused by missing environment variable denylist entries for HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS. Attackers can inject …

Apr 28, 2026
CVE-2026-42424
5.7 MEDIUM

OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. Attackers can exploit this by crafting …

Apr 28, 2026
CVE-2026-42421
5.4 MEDIUM

OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway token rotation. Attackers can maintain unauthorized access to WebSocket connections …

Apr 28, 2026
CVE-2026-42420
4.3 MEDIUM

OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing decoded-size limits. Attackers can exploit multiple code paths to …

Apr 28, 2026
CVE-2026-41916
5.4 MEDIUM

OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration reload. Newly accepted gateway connections continue using outdated …

Apr 28, 2026
CVE-2026-41915
5.3 MEDIUM

OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host exec operations. Attackers can exploit this by setting GIT_DIR …

Apr 28, 2026
CVE-2026-41911
6.5 MEDIUM

OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace boundaries. Attackers can exploit upload_file …

Apr 28, 2026
CVE-2026-41910
4.3 MEDIUM

OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender can bypass access controls to perform allowlist …

Apr 28, 2026
CVE-2026-41408
4.3 MEDIUM

OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers can …

Apr 28, 2026
CVE-2026-41406
5.4 MEDIUM

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread …

Apr 28, 2026
CVE-2026-41402
4.2 MEDIUM

OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authenticated attackers to replay messages across sibling targets using the …

Apr 28, 2026
CVE-2026-41400
5.3 MEDIUM

OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start validation. Remote attackers can send oversized …

Apr 28, 2026
CVE-2026-41398
4.6 MEDIUM

OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic local-network pages as trusted origins. Attackers can inject …

Apr 28, 2026
CVE-2026-41397
6.8 MEDIUM

OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation during file synchronization operations. Remote attackers can bypass …

Apr 28, 2026
CVE-2026-41393
4.8 MEDIUM

OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted as DNS authorities. Attackers with same-tailnet position and CA-trusted endpoint …

Apr 28, 2026
CVE-2026-41392
6.7 MEDIUM

OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust via shell init-file wrapper invocations. Attackers can exploit shell options …

Apr 28, 2026
CVE-2026-41391
5.3 MEDIUM

OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execution contexts, allowing attackers to redirect Python package-index traffic. Attackers can …

Apr 28, 2026
CVE-2026-41388
6.5 MEDIUM

OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array settings as missing values. Attackers can restart the application to rehydrate revoked …

Apr 28, 2026
CVE-2026-41385
6.5 MEDIUM

OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration …

Apr 28, 2026
CVE-2026-41382
5.4 MEDIUM

OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers to bypass channel and member allowlist restrictions. Attackers can exploit …

Apr 28, 2026
CVE-2026-41381
5.4 MEDIUM

OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attackers to bypass channel-level member access allowlist restrictions. Attackers …

Apr 28, 2026
CVE-2026-41377
4.6 MEDIUM

OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures …

Apr 28, 2026
CVE-2026-41376
5.4 MEDIUM

OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling that fails to properly validate message senders. Attackers can …

Apr 28, 2026
CVE-2026-41375
6.5 MEDIUM

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for …

Apr 28, 2026
CVE-2026-41374
5.3 MEDIUM

OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing …

Apr 28, 2026
CVE-2026-41373
6.1 MEDIUM

OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUILD_RUSTC, and CMAKE_C_COMPILER …

Apr 28, 2026
CVE-2026-24231
6.3 MEDIUM

NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint …

Apr 28, 2026
CVE-2026-24204
6.5 MEDIUM

NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may …

Apr 28, 2026
CVE-2026-38948
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, …

Apr 28, 2026
CVE-2025-60887
5.3 MEDIUM

An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which …

Apr 28, 2026
CVE-2026-7283
4.7 MEDIUM

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function save_expired of the file /ajax.php?action=save_expired. The manipulation …

Apr 28, 2026
CVE-2026-7282
4.7 MEDIUM

A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expired. The manipulation of the …

Apr 28, 2026
CVE-2026-40968
4.2 MEDIUM

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited …

Apr 28, 2026
CVE-2026-6706
6.5 MEDIUM

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted …

Apr 28, 2026
CVE-2026-7309
4.3 MEDIUM

A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` …

Apr 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.